Senior Vulnerability Management Engineer – Tenable Nessus
We are seeking a Senior Vulnerability Management Engineer with strong hands-on experience with Tenable Nessus and enterprise vulnerability management programs. The successful candidate will be responsible for designing, configuring, integrating, optimizing, deploying, and supporting vulnerability scanning capabilities across complex enterprise environments.
Key Responsibilities
- Design, configure, deploy, integrate, maintain, and upgrade Tenable Nessus vulnerability management solutions.
- Manage and optimize vulnerability scanning infrastructure, scan policies, scanners, agents, and related components.
- Conduct advanced vulnerability analysis using CVSS scoring and risk-based prioritization.
- Perform root-cause analysis and provide actionable remediation recommendations across network, endpoint, and cloud environments.
- Support the complete vulnerability management lifecycle, including scanning, analysis, remediation, validation, and reporting.
- Investigate and resolve complex and non-standard cybersecurity vulnerabilities and system issues.
- Improve scanning strategies, detection coverage, scan fidelity, and reduce false positives.
- Integrate Nessus with security and infrastructure technologies using APIs, vendor integrations, and custom scripting.
- Collaborate with Security Operations, Infrastructure, Application, and other technical teams to coordinate and drive vulnerability remediation.
- Develop and maintain technical architecture, implementation, configuration, testing, operational, and support documentation.
- Provide technical recommendations related to Nessus capabilities, modules, configuration options, upgrades, architecture, and enhancements.
- Identify opportunities to automate vulnerability-management tasks, workflows, and data replication.
- Provide technical guidance and mentoring to junior analysts and engineers.
- Maintain awareness of emerging vulnerabilities, threats, attack techniques, cybersecurity standards, and industry best practices.
Required Qualifications
- 6+ years of combined training and progressive hands-on experience in cybersecurity and vulnerability management.
- Significant hands-on experience with Tenable Nessus in an enterprise vulnerability management environment.
- Experience deploying, configuring, maintaining, and optimizing vulnerability scanning infrastructure.
- Experience developing and tuning vulnerability scan policies.
- Strong experience with CVSS, vulnerability analysis, risk-based prioritization, and remediation.
- Experience performing root-cause analysis and providing remediation guidance.
- Experience supporting vulnerability management across network, endpoint, and cloud environments.
- Strong understanding of the full vulnerability management lifecycle.
- Experience analyzing complex cybersecurity issues and designing or improving vulnerability management solutions.
- Experience working with security frameworks and standards such as NIST, DoD, or FedRAMP.
- Experience collaborating with Security Operations, Infrastructure, and Application teams.
- Strong technical documentation, communication, and problem-solving skills.
- Experience providing technical mentoring and guidance to junior team members.
Technical Environment
Experience with some or all of the following is highly relevant:
- Tenable Nessus
- Nessus Security Center
- Nessus Manager
- Nessus Active Scanner
- Nessus Agents – Windows/Linux
- Nessus Network Monitor / Passive Vulnerability Sensor
- SIEM technologies
- SCCM
- Elasticsearch / Logstash / Kibana (ELK)
- Rapid7 / Nexpose
- Asset, application, and configuration management tools
- Security APIs and custom scripting
- Endpoint security technologies
What We're Looking For
This role is best suited for a hands-on vulnerability management professional, not a general cybersecurity analyst. Candidates should be able to demonstrate substantial experience directly working with Tenable Nessus, enterprise vulnerability scanning, vulnerability analysis, remediation, and optimization.