Skip to content

Open nowPosted 32 days ago

Tenable Vulnerability Management Engineer

Workable (global search)109,826 open roles

Where
Philadelphia, PA, United States
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowTenable Vulnerability Management EngineerWorkable (global search) · Philadelphia, PA, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 2 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 32 days ago

Workable (global search) median: 2 days open

The posting

Symmetrio is recruiting a Remote Tenable Vulnerability Management Engineer Consultant for our customer, a large government organization in Philadelphia, PA. This role is intended for an experienced, hands-on Tenable practitioner who can elevate and mature a large enterprise vulnerability management program.

The successful candidate will bring recent, deep experience across the Tenable platform and will be expected to optimize how Tenable is configured, operated, automated, and used to drive risk-based vulnerability identification, prioritization, remediation, and executive reporting. This individual should be excited to expand the program beyond traditional infrastructure scanning by leveraging Tenable Vulnerability Management, Tenable Web App Scanning, APIs, automation, and other applicable Tenable capabilities. The candidate will also help advance the use of AI-enabled tools and techniques to analyze vulnerability data, identify patterns and exposures, improve prioritization, accelerate investigation, and support remediation decisions across a complex enterprise environment.

Strong PowerShell and/or Python scripting skills are essential to automate repetitive activities, integrate data sources, enrich findings, and improve the efficiency and scale of the vulnerability management lifecycle. The ideal candidate is not simply a scanner operator; they are a vulnerability management engineer and program builder who can identify opportunities to improve coverage, data quality, risk prioritization, automation, metrics, and overall program maturity.

This is a remote position, with occasional visits to the Philadelphia office as needed for team meetings, strategic planning, and stakeholder discussions. The position offers a salary range of $115,000–$130,000, along with competitive health benefits, PTO, and a 401(k) plan.

Responsibilities

  • Conduct vulnerability assessments using Tenable to identify potential security vulnerabilities within our systems, networks, and applications.
  • Collaborate with cross-functional teams to analyze and prioritize vulnerabilities based on risk levels and potential impact.
  • Develop and implement vulnerability management processes, procedures, and best practices to ensure timely identification, remediation, and reporting of vulnerabilities.
  • Monitor and track the remediation of identified vulnerabilities, ensuring that they are addressed within defined timelines.
  • Stay updated with the latest security vulnerabilities, threats, and industry best practices to continuously improve the vulnerability management program.
  • Perform regular vulnerability scanning and penetration testing to proactively identify and address potential security weaknesses.
  • Work closely with IT teams to provide guidance and support in remediating vulnerabilities, including suggesting configuration changes, patches, and other remediation actions.
  • Provide technical expertise and guidance to internal stakeholders on vulnerability management issues and best practices.
  • Collaborate with the Incident Response team to investigate and respond to security incidents related to vulnerabilities.

Requirements

  • Bachelor's degree in Computer Science, Information Security, or a related field, preferred but not required with acceptable experience. 3-5 years of recent, hands-on experience administering and engineering Tenable solutions in a large enterprise environment is acceptable in replacement of education. Relevant certifications (e.g., CISSP, CEH, GIAC), including Tenable or other vendor certifications, are highly desirable.
  • Demonstrated recent experience with the Tenable platform, with strong hands-on expertise in Tenable Vulnerability Management (Tenable.io) and Nessus, including scanner deployment and management, scan configuration, asset discovery, tagging, credentialed scanning, plugin management, troubleshooting, dashboards, reporting, and platform optimization.
  • Experience using Tenable Web App Scanning to identify and assess vulnerabilities in web applications and APIs; experience with additional Tenable services and capabilities is strongly preferred.
  • Proven experience designing, operating, and maturing an enterprise vulnerability management program, including vulnerability discovery, validation, risk-based prioritization, remediation tracking, exception management, metrics, reporting, and continuous improvement.
  • Advanced scripting and automation skills, particularly PowerShell; Python or similar scripting experience is highly desirable. Must be able to create and maintain scripts that automate Tenable administration, data collection, enrichment, reporting, integrations, remediation workflows, and other vulnerability management activities.
  • Experience working with Tenable APIs and integrating Tenable vulnerability and asset data with enterprise technologies such as ticketing systems, SIEM/SOAR platforms, CMDBs, asset inventories, dashboards, or other security tools.
  • Demonstrated ability and interest in leveraging AI tools to assist with vulnerability analysis, data correlation, pattern identification, prioritization, remediation research, scripting, reporting, and other vulnerability management use cases while applying appropriate validation and security controls to AI-generated outputs.
  • Strong understanding of vulnerability intelligence and risk-based prioritization, including CVE, CVSS, CISA Known Exploited Vulnerabilities (KEV), exploitability, threat intelligence, asset criticality, exposure, compensating controls, and business impact.
  • Solid understanding of common vulnerabilities, attack vectors, mitigation techniques, network and application security concepts, and the ability to distinguish actionable risk from scanner noise or false positives.
  • Experience with network scanning, authenticated/credentialed scanning, web application scanning, vulnerability validation, and penetration testing or vulnerability exploitation techniques.
  • Knowledge of industry standards and frameworks such as CVSS, CVE, OWASP, NIST, and vulnerability management best practices.
  • Strong analytical, troubleshooting, communication, and problem-solving skills, with the ability to translate technical vulnerability data into clear remediation guidance and risk information for infrastructure teams, application owners, leadership, and other stakeholders.
  • Demonstrated ability to independently identify gaps in vulnerability coverage, tooling, processes, automation, reporting, and governance and recommend and implement improvements that measurably increase vulnerability management program maturity.

Benefits

  • Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan (401k)
  • Paid Time Off (Vacation, Sick & Public Holidays)
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.