Cloud Security Vulnerability Management Engineer
Estuate Inc.
- Job
- 28939
- Posted
- Location
- Remote
- Work type
- Contract
- Tax terms
- W2, C2C, 1099
- Experience
- Experience open
- Openings
- 1 opening
Opens your email app with a message to the employer, its subject naming this job. Attach your resume and send it from your own email.
Skills
- AWS
- Azure
- ServiceNow
- SIEM
About the job
Job description:
Role: Cloud Security VM Engineer
REMOTE
Role Summary Cloud Security Engineer responsible for triaging and analyzing vulnerabilities across multi-cloud environments (AWS, Google Cloud Platform, Azure) using CNAPP platforms, providing actionable remediation guidance to stakeholders across infrastructure and application security domains.
Key Responsibilities
- Triage, prioritize, and track cloud vulnerabilities surfaced through CNAPP tooling (e.g., Upwind, Wiz, Prisma Cloud), correlating findings across infrastructure and application layers
- Analyze cloud misconfigurations, CVEs, and runtime risks across AWS, Google Cloud Platform, and Azure.
- Translate vulnerability/security issue findings into clear, stakeholder-ready remediation guidance and verify proper fixes are implemented and validated post-remediation before closure
- Record and report operational metrics including MTTR and MTTD to measure program effectiveness and drive continuous improvement in remediation velocity
- Partner with VM, App Sec, and cloud engineering teams to drive remediation workflows and track closure SLAs
- Support cloud security governance by maintaining visibility into asset exposure, attack surface, and risk posture across multi-tenant environments
- Contribute to security runbooks, risk scoring frameworks, and remediation playbooks aligned to business risk
Required Qualifications
- 4+ years in cloud security with hands-on experience in AWS, Google Cloud Platform, and Azure
- Proficiency with CNAPP platforms for vulnerability triage and cloud posture management
- Strong foundation in infrastructure security (IaC, networking, compute) and application security (SAST/DAST, container security, secrets management)
- Experience communicating technical risk to non-technical stakeholders with clear remediation priorities
- Familiarity with vulnerability management tools such as Tenable, Qualys, or equivalent
Preferred Qualifications
- Experience with CNAPP platforms like Upwind, Wiz or Orca Security
- Experience with integrating CNAPP findings into SIEM/SOAR or ticketing platforms (e.g., ServiceNow VRM)
- Cloud certifications: AWS Security Specialty, Google Cloud Platform Professional Security Engineer, or AZ-500