Senior Vulnerability Management Engineer

Celonis Celonis · Data AI · Raleigh, NC +1 · Information Security

Celonis is seeking a Senior Vulnerability Management Engineer to protect its cloud-native and on-premise infrastructure by identifying, assessing, and prioritizing security vulnerabilities. The role involves executing vulnerability scans, triaging findings from various security tools, providing actionable intelligence to remediation teams, developing asset inventories, creating executive-level metrics, and participating in Red Team exercises. Requires a Bachelor's or Master's degree in Computer Science or Cybersecurity, minimum 5 years of experience in vulnerability management, strong understanding of networking and cloud architectures, and proficiency with vulnerability scanning, CSPM, and SAST tools, as well as scripting skills in Python or Bash.

What you'd actually do

  1. Execute comprehensive vulnerability scans across various technological domains including network, cloud, and applications.
  2. Interpret and triage findings from network scanners, Cloud Security Posture Management (CSPM), Software Composition Analysis (SCA), and Static Application Security Testing (SAST).
  3. Provide actionable intelligence and prioritization metrics to remediation teams.
  4. Develop and maintain an asset inventory for dynamic scanning requirements.
  5. Create executive-level vulnerability metrics and dashboards.

Skills

Required

  • Bachelor's or Master's degree in Computer Science, Cybersecurity, or related field
  • Minimum of 5 years in a dedicated vulnerability management role
  • Deep understanding of networking protocols and cloud architectures
  • Hands-on experience with premium vulnerability scanning tools such as Qualys, Nessus, or similar
  • Strong proficiency in CSPM tools like Prisma, Dome9, or similar
  • Expertise in interpreting SAST results from tools like Checkmarx or Veracode
  • Excellent scripting skills in Python or Bash for custom vulnerability identification

Nice to have

  • Certified Information Systems Security Professional (CISSP) or Certified Ethical Hacker (CEH) certification

What the JD emphasized

  • Minimum of 5 years in a dedicated vulnerability management role.