Job Summary
The Cloud Vulnerability Management Engineer will manage the end-to-end vulnerability management lifecycle across hybrid-cloud, Microsoft Azure, and AWS environments. The role will focus on vulnerability assessment, risk-based prioritization, remediation, validation, and reporting across cloud infrastructure, operating systems, containers, Java applications, open-source components, and Apache Spark-based data platforms. The engineer will partner with Application Development, Cloud Engineering, DevOps, SRE, Infrastructure, and Cybersecurity teams to integrate security controls into CI/CD and DevSecOps processes and improve enterprise vulnerability management and cloud security posture.
Key Responsibilities
• Manage the end-to-end vulnerability management lifecycle for enterprise applications and infrastructure across hybrid-cloud, Azure, and AWS environments.
• Analyze vulnerability scan results affecting cloud infrastructure, operating systems, containers, application dependencies, open-source libraries, and cloud-hosted data platforms.
• Assess and prioritize vulnerabilities based on CVE/CVSS severity, exploitability, application criticality, external exposure, and business risk.
• Work with Application Development, Cloud Engineering, DevOps, SRE, Infrastructure, and Cybersecurity teams to define and execute remediation plans.
• Identify and remediate vulnerabilities across AWS and Azure services, Linux/Windows servers, Kubernetes, Docker images, Java applications, and open-source components.
• Support vulnerability management for Apache Spark-based applications and data-processing platforms, including Spark runtimes, Java/JVM dependencies, libraries, packages, and cloud infrastructure.
• Troubleshoot vulnerability root causes and recommend remediation through patching, dependency upgrades, configuration changes, infrastructure changes, or compensating controls.
• Validate remediation through rescanning, technical verification, and security evidence collection.
• Track Critical and High vulnerabilities against established remediation SLAs and escalate overdue vulnerabilities, blockers, and risks.
• Identify recurring vulnerability patterns and recommend systemic solutions and preventive controls.
• Integrate vulnerability and security scanning into CI/CD and DevSecOps pipelines.
• Support cloud security posture assessments and remediation of configuration weaknesses across Azure, AWS, and hybrid-cloud environments.
• Develop scripts and automation to improve vulnerability identification, remediation tracking, validation, reporting, and compliance evidence collection.
• Create dashboards and reports covering open vulnerabilities, remediation aging, SLA compliance, risk acceptance, remediation trends, and vulnerability reduction.
• Participate in vulnerability governance and operational review meetings and communicate technical risks, remediation status, dependencies, and blockers to engineering and management stakeholders.
Required Qualifications
• 7+ years of experience in IT engineering, Cloud Engineering, DevOps/SRE, Cybersecurity, Application Security, or Vulnerability Management within enterprise environments.
• 4+ years of hands-on experience in Vulnerability Management, Application Security, or Cloud Security, including vulnerability analysis, prioritization, remediation, and validation.
• 4+ years of experience working with public cloud technologies, with strong hands-on knowledge of AWS and/or Microsoft Azure.
• 2+ years of experience supporting hybrid-cloud or multi-cloud environments, preferably involving application migration or transformation between Azure and AWS.
• 3+ years of experience using enterprise vulnerability/security platforms such as Qualys, Tenable, Rapid7, Wiz, Prisma Cloud, Microsoft Defender for Cloud, AWS Inspector, or comparable tools.
• 3+ years of experience analyzing and remediating CVE/CVSS-based vulnerabilities, including operating-system vulnerabilities, application dependencies, open-source libraries, containers, and cloud infrastructure.
• 2+ years of experience supporting security or vulnerability management for Apache Spark, Databricks, EMR, Hadoop, or similar large-scale data-processing platforms.
• 2+ years of experience working with Java/JVM applications and open-source dependency vulnerability remediation, including upgrading vulnerable libraries and packages.
• 2+ years of experience working with containers and container orchestration technologies such as Docker and Kubernetes, including container/image vulnerability management.
• 2+ years of experience with CI/CD and DevSecOps technologies such as GitLab CI, GitHub Actions, Jenkins, Azure DevOps, or comparable platforms.
• 2+ years of experience integrating or working with SAST, DAST, Software Composition Analysis (SCA), container scanning, secrets scanning, and Infrastructure-as-Code scanning.
• 2+ years of experience with scripting or automation using Python, Bash, PowerShell, or equivalent technologies.
• Strong understanding of AWS and Azure security concepts, including IAM/access controls, cloud configuration, network security, logging/monitoring, and cloud security posture management.
• Strong knowledge of vulnerability management concepts including CVE, CVSS, risk-based prioritization, patch management, vulnerability SLAs, remediation validation, security exceptions, and risk acceptance.
• Strong analytical, troubleshooting, and communication skills with the ability to translate security findings into actionable technical remediation.
• Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or equivalent work experience.
Preferred Qualifications
• Experience working in Banking, Financial Services, or other highly regulated enterprise environments.
• Experience securing enterprise data platforms utilizing Apache Spark, Databricks, AWS EMR, Kafka, Hadoop, or related technologies.
• Experience with cloud security services including AWS Security Hub, Inspector, GuardDuty, CloudTrail, Config, Microsoft Defender for Cloud, Azure Policy, and Entra ID.
• Experience with Infrastructure as Code technologies such as Terraform and AWS CloudFormation.
• Knowledge of security standards and frameworks including NIST, CIS Benchmarks, OWASP, and cloud security best practices.
• Experience implementing automated vulnerability-remediation and security-validation workflows.
• Experience applying AI/LLM-based capabilities to vulnerability analysis, remediation recommendations, or security automation.
• Familiarity with SRE, observability, production support, and incident-management practices.
• Relevant certifications such as AWS Certified Security - Specialty, Microsoft Azure Security Engineer, CISSP, CCSP, Security+, or equivalent cloud/security certifications.