Vulnerability Management & Response Engineer

Starr Insurance Companies$90K — $120K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of hands-on experience in enterprise Vulnerability Management programs including governance and remediation outcomes.
  • Proficiency with Tenable for scan configuration, credentialed scanning, and troubleshooting.
  • Understanding of vulnerability scoring systems (CVSS) and risk-based remediation prioritization.
  • Experience with patching strategies and tools like SCCM or Intune.
  • Strong documentation skills with an emphasis on process improvement.
  • Proven ability to liaise effectively between technical and non-technical teams.

Responsibilities

  • Manage daily operations of the Tenable platform, including scan setups and troubleshooting.
  • Oversee vulnerability remediation tasks, coordinating across infrastructure and application teams.
  • Implement and enforce SLA-based remediation processes, including reporting on SLA compliance.
  • Integrate Tenable findings with other systems for automation of tracking and validation.
  • Conduct reconciliations between Tenable outputs and asset inventories to ensure data accuracy.
  • Maintain comprehensive records of exceptions and risk acceptances with proper documentation.
  • Produce detailed metrics and reports on VM program performance and risk trends.

Benefits

  • Cross-functional collaboration opportunities with diverse teams.
  • Involvement in cutting-edge vulnerability management automation and governance.
  • Continuous improvement of VM processes with a focus on risk mitigation.
  • Opportunity to work with enterprise-level scanning tools and cloud environments.
Full Job Description
Position Summary

We are seeking a highly skilled Vulnerability Management & Response Engineer to help operate and continuously improve our enterprise Vulnerability Management (VM) program. This role is responsible for owning core VM processes end-to-end-identification, assessment, prioritization, exception handling, remediation tracking, and validation-across on-premises and cloud environments using Tenable. The position drives risk-informed decisions and facilitates remediations with the asset owners.

This role will partner cross-functionally with Infrastructure, Development, Risk, and Compliance teams to maintain continuous scanning coverage, meet remediation SLAs, and mature the VM program through automation, reporting, and governance. The ideal candidate has proven experience running a Vulnerability Management program at enterprise scale, with hands-on Tenable administration and a track record of driving remediation outcomes with asset owners.

Key Responsibilities
  • Own day-to-day operations of the Tenable platform (e.g., scan configuration, scheduling, coverage monitoring, credentials management, and results troubleshooting).
  • Lead triage, assignment, and validation of vulnerability remediation tasks across infrastructure and application stakeholders.
  • Define, maintain, and enforce SLA-based remediation, including escalation and executive reporting for SLA drift.
  • Integrate Tenable findings and remediation workflows with SCCM, Intune, SOAR, SIEM, and ticketing systems to enable automated assignment, tracking, and validation.
  • Conduct quarterly reconciliation of Tenable scanner output with CMDB and asset inventories to validate coverage, ownership, and data quality.
  • Maintain an auditable exception register with documented risk acceptance, compensating controls, approvals, and expiration controls.
  • Produce VM program metrics and reporting (weekly, monthly, quarterly, and annually), including risk trends, SLA performance, and remediation outcomes.
  • Run a recurring VM governance cadence (e.g., quarterly working sessions) to review SLA drift, backlog health, scanner coverage, and tool-to-tool integrations.
  • Support internal audit and regulatory review of the Vulnerability Management program by providing evidence, metrics, and control narratives.


Required Qualifications
  • 5+ years of hands-on experience running an enterprise Vulnerability Management program (process, governance, metrics, and remediation outcomes), not just point-in-time scanning.
  • Hands-on experience with Tenable, including scan configuration, credentialed scanning, reporting, and troubleshooting.
  • Deep understanding of vulnerability scoring systems (CVSS), threat intelligence correlation, and risk-based prioritization to drive remediation sequencing.
  • Experience leading or contributing to patching strategies using SCCM, Intune, or similar tools.
  • Strong documentation and process improvement skills.
  • Proven ability to collaborate across technical and non-technical teams.


Preferred Qualifications
  • Experience integrating VM tools with SOAR, SIEM, or ticketing platforms like Remedyforce or ServiceNow.
  • Knowledge of container security, cloud-native security controls (Azure, AWS, GCP), and API-based vulnerability exposure.
  • Exposure to CMDB reconciliation and asset discovery in dynamic environments.
  • Experience presenting technical risk summaries to executive or audit stakeholders.

About Starr Insurance Companies

Starr Insurance Companies Careers

There has never been a better time to join the global team of Starr Insurance Companies—the leading provider of insurance and investment solutions worldwide.

Work You’ll Do

Join Starr Insurance Companies' top-tier team to assist some of the most prestigious clients in navigating their risk management and insurance strategies. Transform the approach to global insurance solutions with the brightest minds at Starr Insurance Companies. This is where innovation meets industry expertise in a dynamic environment. Lead from a unique position in the marketplace, at the crossroads of deep industry knowledge and extensive insurance innovation. Engage with a worldwide network of professionals dedicated to redefining the future of insurance and risk management. Collaborate with a diverse and inclusive team, fostering a culture of professional growth and diversity training.

Introducing the Starr Insurance Companies Professional Growth Path

The team is committed to building a leading career development framework to help individuals master their professional journey within the insurance industry.

Do Innovative Work

Be part of a team that is at the forefront of industry innovation—delivering targeted solutions through a depth of expertise that is unmatched in the insurance sector.

Drive Innovation and Leadership

Develop and implement groundbreaking solutions on trusted platforms, enhancing Starr Insurance Companies' position as a leader in the insurance industry.

Be Part of a Great Team

Join a team that values diversity and leadership, working on a wide range of initiatives that harness the capabilities of Starr Insurance Companies' global presence.

Future-proof Your Career

Advance your career with limitless opportunities supported by unmatched training, development, and certification programs.

Explore

Discover how Starr Insurance Companies is leading the way in predictive analytics to revolutionize risk assessment and management solutions.

The Starr Insurance Companies Edge

With a commitment to innovation and leadership, Starr Insurance Companies helps clients tackle the challenges of today’s dynamic market. Clients globally turn to Starr Insurance Companies for strategic insights and solutions that drive growth and success in the insurance industry.

Stay Connected

Join the Team

Search open positions that match your skills and interests. Starr Insurance Companies seeks passionate, curious, and solution-driven team players. SEARCH STARR INSURANCE COMPANIES JOBS

Keep Up to Date

Stay informed with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the professionals who work at Starr Insurance Companies.

READ CAREERS BLOG

Job Alert Emails

Customize your subscription to receive job alerts, the latest news, and insider tips tailored to your preferences. Explore the exciting and rewarding career opportunities that await at Starr Insurance Companies.
Learn more about Starr Insurance Companies

Similar Jobs

More Jobs at Starr Insurance Companies

More Information Technology Jobs

Find similar Vulnerability Management & Response Engineer jobs: