Security Engineer, Vulnerability & Attack Surface Management

AspenView Technology Partners, Inc.

$90K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4-6+ years in cybersecurity, focusing on vulnerability management, attack surface management, or security operations.
  • Security+ or GEVA certification preferred; vendor certifications (e.g., Tenable, Qualys) or AI/ML coursework are advantageous.
  • Strong analytical skills to interpret AI-generated vulnerability insights into actionable risk narratives.
  • Proven ability to foster collaboration across IT, cloud, and application teams for efficient remediation efforts.
  • Experience with AI-driven technologies in vulnerability assessment and management.

Responsibilities

  • Design and manage AI-augmented vulnerability scanning across diverse environments.
  • Deploy and tailor AI-driven models for prioritizing vulnerabilities based on multiple risk factors.
  • Correlate real-time vulnerability data with current threat intelligence to update prioritization.
  • Establish automated remediation processes, including AI-generated ITSM ticket creation.
  • Monitor SLA compliance and detect potential breaches proactively through automation.
  • Create AI-generated reports and dashboards to effectively communicate security risks.
  • Maintain accurate asset inventories and integrate with CMDB while managing external exposure risks.

Benefits

  • Flexible work arrangements to support work-life balance.
  • Opportunities for professional development and certifications.
  • Engagement with cutting-edge AI technologies in cybersecurity.
  • Collaborative work environment across diverse teams and technologies.
  • Access to advanced tools and resources for vulnerability management.
Full Job Description
The Security Engineer, Vulnerability & Attack Surface Management operates across the full vulnerability lifecycle. You will act as the technical engine of the VM program, transforming it from a reactive process into a proactive, intelligence-driven capability. By embedding AI across scanning, triage, and remediation, you will ensure high-risk vulnerabilities are addressed before exploitation across IT, cloud, and OT-adjacent environments.

What you will do:

AI-Driven Scanning & Prioritization

  • Design and operate AI-augmented vulnerability scanning pipelines across IT, cloud, and hybrid environments.
  • Deploy and tune AI-driven prioritization models combining CVSS, EPSS, CISA KEV, threat intelligence, and asset criticality.
  • Correlate vulnerability data with live threat intelligence and active exploit activity to keep prioritization models current and accurate.

Automated Remediation & Workflows

  • Build and maintain automated remediation workflows, including AI-generated ticket creation and resolution tracking through ITSM platforms.
  • Monitor SLA compliance across workflows using automated alerting and predictive SLA breach detection.
  • Produce AI-generated operational dashboards and executive reporting to translate raw vulnerability data into clear risk narratives.

Attack Surface & Asset Management

  • Maintain asset inventory accuracy and CMDB integrations, using AI-assisted asset discovery to identify shadow IT and coverage gaps.
  • Contribute to attack surface management using AI-powered exposure analysis to map external trends and model risk reduction scenarios.
  • Support exception documentation and compensating control tracking through structured, audit-ready workflows.

Tools & Technologies:

  • Scanning Platforms: Tenable Nessus, Qualys VMDR, Rapid7 InsightVM, or Microsoft Defender Vulnerability Management.
  • Risk Scoring: CVSS v3/v4, EPSS, CISA KEV, and asset-criticality-based prioritization frameworks.
  • ASM Platforms: Cortex Xpanse, Microsoft Defender EASM, or Axonius.
  • Scripting & ITSM: ServiceNow, Jira, Python, and PowerShell.

What you bring:

  • Experience: 4-6+ years in cybersecurity with a primary focus on vulnerability management, attack surface management, or security operations.
  • Certification: Security+ or GEVA preferred; vendor certifications (Tenable, Qualys) or AI/ML security coursework are a strong plus.
  • Communication: Strong analytical skills with the ability to translate AI-generated vulnerability insights into risk narratives for technical teams and executive stakeholders.
  • Collaboration: Effective at driving remediation velocity across IT, cloud, and application teams using data to influence prioritization.

Similar Jobs

More Jobs at AspenView Technology Partners, Inc.

More Information Technology Jobs

Find similar Security Engineer, Vulnerability & Attack Surface Management jobs: