ULTA Salon, Cosmetics & Fragrance, Inc

Engineer - Vulnerability Management

Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, CIS, or equivalent experience (5+ years in cybersecurity)
  • Preferred Certifications - CISSP or equivalent
  • 3-5 years professional experience in a relevant field
  • Excellent analysis/troubleshooting skills
  • Strong communication skills with non-technical stakeholders
  • Ability to prioritize tasks in high-pressure environments
  • Retail industry experience preferred

Responsibilities

  • Design and optimize vulnerability scans across various environments
  • Prioritize vulnerabilities using risk-based context and threat intelligence
  • Drive remediation efforts in collaboration with multiple teams
  • Maintain an accurate and updated asset inventory across diverse systems
  • Publish actionable dashboards and reports on vulnerabilities and compliance
  • Work with development teams to integrate security practices into CI/CD pipelines
  • Build automation for asset management and reporting processes

Benefits

  • Paid time off
  • Health, dental, vision, life, and disability benefits
  • Opportunities for additional compensation through a bonus plan
  • Support for training and conferences with minimal travel required
  • Flexible work environment with hybrid options
Full Job Description
THE IMPACT YOU CAN HAVE:

The Engineer - Vulnerability Management is responsible for working with the VM Manager to design, implement, and maintain a robust vulnerability management program across hybrid environments, including on-premises, cloud, containers, and SaaS platforms. This role focuses on technical execution-deploying and tuning scanning tools (Tenable Security Center/Falcon Exposure Management), then using continuous, data driven communication to remediation teams via ServiceNow VR so that they are empowered to address the riskiest vulnerabilities within their environments. The engineer will leverage risk-based prioritization, threat intelligence, and business context to reduce exposure and improve resilience.

This position requires deep technical expertise in vulnerability scanning technologies, scripting and automation, and security practices across the traditional and cloud-native spectrum. The engineer will collaborate closely with infrastructure, cloud, application, and security teams to drive remediation according to organizational SLAs, and continuously improve program maturity through metrics, automation, and emerging technologies.

YOU'LL ACCOMPLISH THESE GOALS BY:
  • Vulnerability Identification & Scanning
    • Design, schedule, and optimize authenticated/credentialed scans for on-prem, cloud, and remote endpoints; ensure minimal disruption and scan hygiene
    • Validate scanner configuration and coverage (e.g., Qualys/Tenable/Rapid7/Falcon Exposure Management) and continuously tune for false-positive reduction
  • Risk-Based Prioritization
    • Prioritize findings using context: exploit likelihood (EPSS), Known Exploited Vulnerabilities (CISA KEV), network exposure, business impact, compensating controls, and asset criticality
    • Correlate with threat intel and active detections (EDR/XDR/SIEM), elevating actively exploited vulnerabilities to emergency treatment
    • Define severity thresholds and SLAs per asset class; manage exceptions with time-bound risk acceptance and compensating controls.
  • Remediation & Ticketing
    • Drive remediation by regularly partnering with Infra/Platform, Cloud, and App teams to empower them to make informed decisions when weighing the priority of patches and configuration changes versus compensating controls and operational realities
    • Integrate with ticketing systems (ServiceNow VR) to ensure that proper assignment logic is in place, and that automated validation scans determine the status of fix actions.
    • Assist the Security Operations team as they execute zero-day/rapid-response playbooks (e.g. scans/queries, exploitability assessments, validations, enrich post-mortems)
  • Asset & Exposure Discovery
    • Contribute to and help maintain an accurate, continuously updated asset inventory across a primary scope of endpoints, servers, and network devices, as well as containers, mobile, OT/IoT, and cloud resources (IaaS, PaaS, SaaS)
    • Integrate data from CMDB, cloud provider APIs, EDR/XDR, MDM, and attack surface management to reduce blind spots
    • Assist CMDB owner with categorization of assets for business criticality, data sensitivity, internet-exposure, and ownership to enable risk-based prioritization
  • Validation & Continuous Improvement
    • Perform targeted rescans and exploit-simulation where safe to confirm remediation
    • Tune detection rules to reduce noise; establish a feedback loop with platform owners for recurring findings
    • Run root cause analyses for chronic issues (missing patch baselines, unsupported OS, inadequate maintenance windows)
  • Governance, Metrics & Reporting
    • Publish actionable dashboards and reports: weighted risk trends, criticality & exposure trends, SLA adherence, risky asset highlighting, KEV coverage, etc
    • Align with risk and audit frameworks (NIST CSF/800-53, CIS Controls, ISO 27001, SOC 2) and support audit evidence requests
    • Maintain policy/standards for scanning coverage, remediation SLAs, and risk acceptances.
  • Cloud, Containers, and DevSecOps Integration
    • Work with teams utilizing existing scanning in their CI/CD pipelines and enforce policy gates for images, IaC, and dependencies
    • Partner with cloud engineering to communicate misconfigurations (CSPM/CNAPP) and high-risk services (public S3, exposed admin ports, overly permissive IAM)
    • Champion SBOM generation and consumption; track vulnerable components (e.g., Log4j) across apps, images, and functions
  • Collaboration & Stakeholder Management
    • Act as the primary point of contact with Infra/Platform, Cloud, AppSec, Networking, and Business Owners for remediation prioritization
    • Communicate risk in business terms; escalate blockers; provide clear, concise guidance
  • Automation & Tooling
    • Build automation for asset enrichment, ticket creation, SLA tracking, and report generation (APIs, scripts, workflows)
    • Evaluate and pilot emerging capabilities (exposure management, ASM, CNAPP) and drive vendor/tool rationalization

ADDITIONAL RESPONSIBILITIES:
  • Work across groups to identify opportunities for improvement within the environment, both technical and operational, along with plans to capture those benefits.
  • Responsible for ensuring adherence to existing processes both operationally, and in support of PCI and/or SOX audit requirements.
  • Collaborate with other members of the Engineering organization to create and maintain standards and operating procedures, and provide information as appropriate to manager, project manager, and various departments within the Company.
ESSENTIALS FOR SUCCESS:
  • Bachelor's degree in Computer Science, CIS, or equivalent experience (5+ years in cybersecurity)
  • Preferred Certifications - CISSP or equivalent
  • 3-5 years professional experience in a relevant field
  • Excellent analysis/troubleshooting skills, able to solve problems efficiently
  • Excellent communication skills; feels comfortable working with non-technical business partners
  • Skilled and comfortable with tackling complex challenges, either in leading the troubleshooting effort or advising/leading others
  • Work with production support and project consultants in an onshore / offshore model
  • Able to prioritize and execute tasks in a high-pressure environment
  • Solid knowledge of industry best practices and technical systems
  • Knowledgeable as to IT security concepts, compliance, principles, and tools
  • Ability to work in team in diverse/ multiple stakeholder environments
  • Ability to follow-up, follow through and deliver timely results
  • Proven track record of delivering high quality solutions on time and on schedule
  • Flexibility of providing support during odd hours, weekends, and peak seasons
  • Off-Hours support including 24x7 on-call required
  • Minimal travel required (training/conferences)
  • Retail industry experience preferred
#LI-ML1

#LI-HYBRID

The pay range for this position is $90,800.00 - $120,000.00 / Year with the opportunity for eligible associates to earn additional compensation pursuant to the Company's bonus plan. Exact pay will be based on factors including, but not limited to relevant education, qualifications, certifications, experience, level, shift, geographic location, and business and organizational needs. Full-time positions are eligible for paid time off, health, dental, vision, life and disability benefits. Part-time positions are eligible for dental, vision, life, and disability benefits. For additional information concerning our benefits, visit our Benefits and Career Development page: https://learn.bswift.com/ulta

About ULTA Salon, Cosmetics & Fragrance, Inc

ULTA Beauty is the beauty retailer in the United States and the premier beauty destination for cosmetics, fragrance, skin, hair care products and salon services. Since opening its first store 25 years ago, ULTA Beauty has grown to become the top national retailer providing All Things Beauty, All in One Place™. The Company offers more than 20,000 products from over 500 well-established and emerging beauty brands across all categories and price points, including ULTA Beauty's own private label. ULTA Beauty also offers a full-service salon in every store featuring hair, skin and brow services. ULTA Beauty is recognized for its commitment to personalized service, fun and inviting stores and its industry-leading Ultamate Rewards loyalty program.

ULTA Salon, Cosmetics & Fragrance, Inc. Careers

Join the vibrant team at ULTA Salon, Cosmetics & Fragrance, Inc., a leader in the beauty industry, where innovation meets diversity and professional growth. As a company renowned for its inclusive culture and commitment to employee development, there has never been a better time to explore job opportunities with us. Work You’ll Do At ULTA, we empower our team to bring beauty to life, providing unparalleled opportunities for career advancement and professional enrichment. Whether you are looking for a position in our retail stores, at our corporate headquarters, or within our distribution network, ULTA offers a dynamic work environment where your skills will be honed and your achievements recognized. Join our team and contribute to an industry-leading company known for its commitment to innovation, leadership, and diversity. ULTA is not just about beauty products; it's about elevating the beauty in everyone. Our team’s diversity is our strength, and we continuously strive to foster an inclusive environment through comprehensive diversity training programs. Internship and Employment Opportunities Start your career journey with an internship at ULTA, where you can gain hands-on experience in a thriving retail environment. Our internships provide a robust foundation in the beauty industry, offering insights into various aspects of business operations, from marketing to supply chain management. For those seeking full-time roles, ULTA is hiring across a range of departments. We look for passionate, creative, and solution-driven team players. Explore open positions that match your skills and interests on our Careers page. Benefits and Culture At ULTA, we believe in rewarding our employees for their hard work and commitment. Our benefits package is designed to support the well-being and financial security of our team members and their families. Benefits include health coverage, retirement plans, employee discounts, and more. Our company culture champions personal and professional growth, encouraging every team member to reach their full potential. Through leadership training and continuous learning opportunities, we prepare our employees to lead and innovate in the beauty industry. Networking and Professional Development Stay connected and advance your career through ULTA’s networking events, where you can meet industry leaders and like-minded professionals. Enhance your resume and interview skills through our career development workshops and receive personalized advice from our experienced hiring managers. Future-Proof Your Career With ULTA, the trajectory of your career is boundless. Embrace the opportunity to grow with a company that is as committed to your professional journey as it is to leadership in the beauty industry. Explore Discover how ULTA is transforming the beauty landscape and leading the way in retail innovation. Read more about our latest projects and the impact they have on our customers and industry. Join Our Team Search for job opportunities that align with your career aspirations. We are excited to see how your vision and expertise can contribute to our ongoing success. Stay Up to Date Keep ahead with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here. Job Alert Emails Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. See what exciting and rewarding opportunities await at ULTA Salon, Cosmetics & Fragrance, Inc. Join us and be part of a company where innovation, leadership, and beauty move forward together.
Learn more about ULTA Salon, Cosmetics & Fragrance, Inc
Size
16,500 employees
Market Cap
$23.6 billion
Industry
Net Income
$175.8 million
Founded
1990
5 Year Trend
+12.2%
Revenue
$6.1 billion
NASDAQ

Similar Jobs

More Jobs at ULTA Salon, Cosmetics & Fragrance, Inc

More Information Technology Jobs

Find similar Engineer - Vulnerability Management jobs: