
Vulnerability Management Engineer // Endpoint Patching
Job Overview
Employment Type
Full-time
Compensation
Salary
Range $106,100.00 - $165,300.00
Work Schedule
Standard Hours
Benefits
competitive salary
Medical insurance
Dental Insurance
Vision Insurance
401(k) with Company Match
Paid Time Off
Remote work environment
Professional development opportunities
Certification support
Collaborative team culture
Job Description
A well-established wealth management firm is seeking a Vulnerability Management Engineer to join its cybersecurity team. The firm specializes in providing comprehensive financial services tailored to high-net-worth individuals and institutions. With a strong commitment to safeguarding client assets and information, this organization operates in a highly regulated and complex financial environment. It is recognized for its stability, innovation, and dedication to fostering an inclusive workplace where diversity and respect form the foundation of its corporate culture. Employees at this firm benefit from a remote-first work environment that values flexibility while maintaining high standards of security and operational excellence.
In the role of Vulnerability Management Engineer, you will be responsible for owning the end-to-end vulnerability management program within a Windows-dominant enterprise environment. This position emphasizes hands-on endpoint patching and system hardening, highlighting the importance of execution and tangible results, as the role requires you to not only identify vulnerabilities but actively close them. You will lead remediation efforts, drive patch compliance, and collaborate closely with infrastructure and IT operations teams to reduce the organization's attack surface.
The role demands an individual who thrives in technical, execution-focused settings and takes pride in effectively closing vulnerabilities rather than simply tracking them. Close interaction with IT, cloud, and business stakeholders is essential to ensure timely remediation of vulnerabilities while preserving the stability and security of critical financial systems. An ideal candidate should bring in-depth Windows patch management experience, coupled with strong vulnerability prioritization and risk-based decision-making skills. The role also includes responsibilities around analyzing vulnerability assessment results, translating those findings into actionable recommendations, and supporting security operations activities such as incident response and threat intelligence correlation.
This position offers a unique opportunity to work in a dynamic, high-stakes environment where cybersecurity is fundamental to the firm’s success. You will contribute to developing and refining policies and procedures for patch management and endpoint configuration standards. Additionally, you will be involved in continuous process improvement initiatives, supporting exception management processes, and providing clear communication to both technical teams and organizational leadership. If you are passionate about cybersecurity within the financial services sector and seek to make a meaningful impact through proactive vulnerability management and system hardening, this role will provide the perfect environment to grow your career and work alongside a collaborative, mission-driven team.
In the role of Vulnerability Management Engineer, you will be responsible for owning the end-to-end vulnerability management program within a Windows-dominant enterprise environment. This position emphasizes hands-on endpoint patching and system hardening, highlighting the importance of execution and tangible results, as the role requires you to not only identify vulnerabilities but actively close them. You will lead remediation efforts, drive patch compliance, and collaborate closely with infrastructure and IT operations teams to reduce the organization's attack surface.
The role demands an individual who thrives in technical, execution-focused settings and takes pride in effectively closing vulnerabilities rather than simply tracking them. Close interaction with IT, cloud, and business stakeholders is essential to ensure timely remediation of vulnerabilities while preserving the stability and security of critical financial systems. An ideal candidate should bring in-depth Windows patch management experience, coupled with strong vulnerability prioritization and risk-based decision-making skills. The role also includes responsibilities around analyzing vulnerability assessment results, translating those findings into actionable recommendations, and supporting security operations activities such as incident response and threat intelligence correlation.
This position offers a unique opportunity to work in a dynamic, high-stakes environment where cybersecurity is fundamental to the firm’s success. You will contribute to developing and refining policies and procedures for patch management and endpoint configuration standards. Additionally, you will be involved in continuous process improvement initiatives, supporting exception management processes, and providing clear communication to both technical teams and organizational leadership. If you are passionate about cybersecurity within the financial services sector and seek to make a meaningful impact through proactive vulnerability management and system hardening, this role will provide the perfect environment to grow your career and work alongside a collaborative, mission-driven team.
Job Requirements
- 3+ years of experience in vulnerability management, endpoint security, or a related IT/information security role
- bachelor's degree in computer science, information systems, cybersecurity, or a related discipline or equivalent experience
- hands-on experience with patch management platforms in a Windows environment such as WSUS, SCCM/MECM, Intune, or equivalent
- proficiency with vulnerability scanning tools such as Tenable Nessus, Qualys, or Rapid7 InsightVM
- strong understanding of Windows OS hardening standards and CIS Benchmarks
- ability to prioritize and communicate risk-based remediation recommendations to both technical teams and leadership
- experience coordinating remediation activities across infrastructure, desktop engineering, and application teams
- strong written and verbal communication skills across technical and non-technical audiences
- self-directed and organized, with the ability to manage competing priorities in a fast-paced environment
- strong analytical and problem-solving skills with a continuous improvement mindset
Job Qualifications
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or related discipline or equivalent experience
- 3+ years of experience in vulnerability management, endpoint security, or related IT/information security roles
- hands-on experience with patch management platforms in a Windows environment such as WSUS, SCCM/MECM, Intune, or equivalents
- proficiency with vulnerability scanning tools like Tenable Nessus, Qualys, or Rapid7 InsightVM
- strong understanding of Windows OS hardening standards and CIS Benchmarks
- ability to prioritize and communicate risk-based remediation recommendations to technical teams and leadership
- experience coordinating remediation activities across infrastructure, desktop engineering, and application teams
- strong written and verbal communication skills for technical and non-technical audiences
- self-directed and organized with ability to manage competing priorities in fast-paced environments
- strong analytical and problem-solving skills with a continuous improvement mindset
- familiarity with STIG compliance and Group Policy for Windows endpoint configuration
- exposure to Active Directory security hardening and privileged account hygiene
- experience with ticketing and workflow platforms such as ServiceNow or Jira
- knowledge of cloud vulnerability management in Azure or M365 environments
- understanding of CVSS scoring, exploit intelligence feeds, and risk-based patch prioritization
- relevant certifications such as CompTIA Security+, CySA+, GCWN, or similar
Job Duties
- Owning the full vulnerability management lifecycle from scan and discovery through prioritization, remediation coordination, and validation
- executing and coordinating endpoint patching across the Windows fleet including workstations and servers using enterprise patch management tooling
- applying and maintaining system hardening configurations in line with CIS Benchmarks, STIGs, and internal security baselines
- analyzing scan results and translating findings into clear, actionable remediation guidance tailored to asset criticality and business risk
- partnering with IT operations, desktop engineering, and server teams to plan and execute patch deployments with minimal disruption
- tracking and reporting on patch compliance, SLA adherence, and remediation progress for leadership and audit audiences
- identifying hardening gaps across the Windows environment and driving improvement projects to close them
- supporting exception management processes including risk acceptance documentation and compensating control review
- contributing to policy and procedure development around patch management and endpoint configuration standards
- participating in security operations activities such as vulnerability-related incident response and threat intelligence correlation
Job Criteria
Experience
Mid Level (3-7 years)
Job Location
Your Profile Is Visible To Hiring Managers Across OysterLink.
We'll match you with best jobs
Get job offers faster


Search For More Opportunities:
How Candidates Get Hired Faster
Apply to 2–3 similar roles
Complete profile & get best matches
Check new opportunities daily

