Career Area:
Technology, Digital and Data
Job Description:
The Qualys Platform Lead owns the administration, operation, governance, and continuous improvement of Caterpillar’s enterprise Qualys platform. This role provides technical leadership for vulnerability scanning, scanner appliances, Cloud Agents, platform configuration, asset data quality, reporting, integrations, and roadmap delivery across a global environment.
The role serves as the primary Qualys subject matter expert and works closely with Cybersecurity, Infrastructure, Cloud, Application, ServiceNow, Governance and Compliance, and leadership teams to support effective vulnerability identification, prioritization, routing, and remediation coordination.
What You Will Do:
Platform Ownership & Administration
Manage platform configurations, scan profiles, scanner appliances, schedules, authentication records, asset tags, user access, and permissions, subscription usage, and operational health.
Ensure high availability, accuracy, and scalability of vulnerability scanning across enterprise-wide infrastructure and coordinate rescanning and validation activities as needed.
Maintain integrations between Qualys, ServiceNow, CMDB, cloud platforms, reporting systems, and approved security technologies.
Oversee host discovery, authenticated infrastructure scanning, scanner appliance operations, and Cloud Agent deployments.
Analyze vulnerability data to identify trends, coverage gaps, systemic issues, and areas requiring attention.
Support risk-based prioritization using Qualys Detection Scores, ETM and TruRisk capabilities, threat intelligence, exploitability, and asset context. Lead prioritization efforts using Caterpillar’s risk criteria and Qualys capabilities (e.g., TruRisk, Threat Protection, Patch Management modules if applicable).
Leverage AI-assisted security analytics and risk-scoring capabilities to improve vulnerability prioritization and remediation decision-making.
Evaluate and validate AI-generated insights from Qualys TruRisk, threat intelligence platforms, and security analytics tools to reduce false positives and focus remediation efforts on exploitable risks.
Utilize predictive analytics to identify emerging vulnerability trends, attack paths, and areas of heightened exposure.
Evaluate AI use cases and emerging technologies to improve operational efficiency, asset discovery, threat exposure analysis, and remediation effectiveness.
Governance, Reporting & Metrics
Work closely with Governance and Compliance teams to support audits, controls, and regulatory requirements.
Create, update, and maintain operational documentation, standards, and processes for vulnerability lifecycle management.
Assess and mitigate risks associated with AI-generated recommendations and automated remediation activities.
Cross-Functional Collaboration
Partner with Infrastructure, Cloud, Application, and DevOps teams to drive remediation plans and support secure system configurations.
Serve as a trusted advisor to IT partners, educating them on vulnerability risks, remediation techniques, and Qualys usage best practices.
Provide escalation support and root cause analysis for scan failures, agent issues, or false positives.
Continuous Improvement
Evaluate and implement new Qualys modules, features, or scanning techniques aligned with Caterpillar’s security roadmap. ETM/TruRisk, CSAM (Asset Management), QPM (Patch Management) and QPA (Policy Control/Audit, EASM (Attack Surface Management).
Drive automation opportunities for asset onboarding, reporting, ticketing, and scanning workflows.
Identify process gaps and propose enhancements to strengthen vulnerability management maturity across the organization.
What You Have:
Vulnerability management and security operations expertise
Hands-on experience with Qualys or similar vulnerability management platforms
Vulnerability scanning, authenticated scans, Cloud Agents, and asset management
Knowledge of Windows, Linux, TCP/IP networking, AWS, and Azure
Experience analyzing vulnerability data, CVSS scores, and threat intelligence
Strong problem-solving, communication, and stakeholder management skills
Familiarity with AI, machine learning, and predictive risk modeling
Experience using Microsoft Copilot, Security Copilot, or similar AI tools for security operations and reporting
Ability to collaborate across security, infrastructure, and application teams
Top Candidates Will Also Have:
Qualys Certifications (e.g., Qualys Vulnerability Management, Policy Compliance, Web Application Scanning, VMDR, CSAM, ETM, Cloud Agent, or EASM).
Experience with ITIL processes, ticketing platforms (ServiceNow, Remedy), and CI/CD pipelines as well as integrating Qualys with ServiceNow, CMDB, reporting, ticketing, cloud, or security platforms.
Experience with scripting for automation (Python, PowerShell).
Experience operating in large-scale, complex enterprise environments like Caterpillar.
Strong communication skills with ability to translate technical findings into actionable direction for non-technical teams.
Additional Info:
Summary Pay Range:
$128,470.00 - $208,770.00
Compensation and benefits offered may vary depending on multiple individualized factors, job level, market location, job-related knowledge, skills, individual performance and experience. Please note that salary is only one component of total compensation at Caterpillar.
Benefits:
Subject to plan eligibility, terms, and guidelines. This is a summary list of benefits.
Medical, dental, and vision benefits*
Paid time off plan (Vacation, Holidays, Volunteer, etc.)*
401(k) savings plans*
Health Savings Account (HSA)*
Flexible Spending Accounts (FSAs)*
Health Lifestyle Programs*
Employee Assistance Program*
Voluntary Benefits and Employee Discounts*
Career Development*
Incentive bonus*
Disability benefits
Life Insurance
Parental leave
Adoption benefits
Tuition Reimbursement
* These benefits also apply to part-time employees
This position requires working onsite five days a week.
Relocation is available for this position.
Posting Dates:
August 10, 2026 - August 19, 2026