- Страна
- США
Откликайтесь
на вакансии с ИИ

Vulnerability Management Engineer (Qualys) - Mid-Atlantic region (Remote)
Отличная вакансия для узкого специалиста по Qualys с очень сильным социальным пакетом (90-100% оплаты страховки компанией) и удаленным форматом. GuidePoint — уважаемый игрок на рынке кибербезопасности США.
Сложность вакансии
Роль требует глубокой экспертизы именно в инструментарии Qualys (минимум 3 года) и навыков разработки кастомных проверок соответствия. Высокая планка обусловлена необходимостью работать с облачными архитектурами и сложными корпоративными сетями.
Анализ зарплаты
Указанные требования соответствуют уровню Senior/Lead Vulnerability Engineer в США. Рыночные зарплаты для таких ролей в сфере кибербезопасности обычно начинаются от $130,000 и могут достигать $180,000 в зависимости от бонусов.
Сопроводительное письмо
I am writing to express my strong interest in the Vulnerability Management Engineer position at GuidePoint Security. With over five years of experience in information security and a deep specialization in Qualys VMDR, I have successfully designed and implemented enterprise-scale scanning infrastructures across hybrid and multi-cloud environments. My expertise in developing custom compliance and audit files, combined with a strong background in scripting with Python and PowerShell, aligns perfectly with the technical requirements of your delivery practice.
Throughout my career, I have focused on not just identifying vulnerabilities, but providing actionable risk analysis and strategic guidance to stakeholders. I am particularly drawn to GuidePoint's holistic approach to security and its reputation as a trusted advisor to Fortune 500 companies. I am eager to bring my technical proficiency in Qualys and my experience with Infrastructure as Code to help your clients optimize their vulnerability management lifecycles and minimize organizational risk.
Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в guidepointsecurity уже сейчас
Присоединяйтесь к команде экспертов GuidePoint Security и станьте доверенным советником для крупнейших компаний США!
Описание вакансии
GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.
GuidePoint Security is seeking an experienced Vulnerability Management Engineer to join our delivery practice in the Mid-Atlantic.
Summary
As a Vulnerability Management Engineer (Qualys), you will be part of a team of highly skilled engineers providing delivery services for customers in several verticals, including retail, finance, healthcare, and more. Your primary responsibilities revolve around partnering with our customers to advise, develop, implement, and optimize all components of the vulnerability management lifecycle.
Role and Responsibilities:
Execute and manage vulnerability scanning of internal, external, and cloud assets
- Plan, design, and implement enterprise vulnerability scanning infrastructure in a hybrid or multi-cloud architecture
- Deploy vulnerability management infrastructure such as scanners, sensors, and agent configurations
- Perform vulnerability scanning with the Qualys VMDR
- Analyze vulnerabilities and clearly communicate impact and risk to the organization
- Advise customers on Vulnerability Management best practices
- Development of custom compliance and audit files for Qualys compliance scanning
- Provide guidance and collaborate with peers on the Vulnerability Management practice team
- Establish credibility as a trusted advisor to our customers
Experience, Education, and Technical Requirements.
- 5+ years of information security experience
- 3+ years of vulnerability engineering experience with Qualys REQUIRED
- 3+ years of performing compliance scanning with Qualys (CIS, NIST, DISA)
- Experience developing custom compliance and audit checks with Qualys VMDR REQUIRED
- Must have experience with Qualys.io or Qualys Security Center
- Experience with scripting tasks using native tools such as BASH, PowerShell, Python, or other native scripting languages
- Experience with Regex for data parsing
- Experience with cloud service providers such as Amazon AWS, Microsoft Azure, or Google Cloud Platform.
- Experience with compliance frameworks such as Cis, NIST, DISA Required
- Experience developing Infrastructure as Code, such as Terraform, or Cloud Formation is a plus
- Experience with Kubernetes, containers, Ci/CD or serverless is a plus
- An understanding of operating systems such as Windows Server, Windows 10/7, Mac OSX, RHEL, and Ubuntu Linux and the ability to perform advanced functions at the CLI
- Ability to manage time independently while handling multiple projects concurrently
- Strong written and verbal communication skills
- A strong desire to learn new technologies and contribute to a fast-growing company
We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application.
Why GuidePoint?GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1,200 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 6,200 customers.
Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity.
This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation.
Some added perks….
- Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
- Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
- Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
- 12 corporate holidays and a Flexible Time Off (FTO) program
- Healthy mobile phone and home internet allowance
- Eligibility for retirement plan after 2 months at open enrollment
- Pet Benefit Option
Создайте идеальное резюме с помощью ИИ-агента

Навыки
- Qualys
- Vulnerability Management
- Python
- PowerShell
- Bash
- AWS
- Azure
- Google Cloud Platform
- Terraform
- Kubernetes
- NIST
- CIS
- Regex
Возможные вопросы на собеседовании
Вакансия требует обязательного опыта работы с Qualys VMDR и настройки инфраструктуры сканирования.
Опишите ваш опыт проектирования и развертывания архитектуры сканирования Qualys в гибридной облачной среде (AWS/Azure). С какими основными трудностями вы сталкивались?
В описании указано требование по разработке кастомных файлов аудита.
Расскажите о процессе создания кастомного файла соответствия (compliance/audit file) в Qualys для специфического стандарта безопасности, которого нет в стандартной библиотеке.
Инженер должен уметь не только находить уязвимости, но и оценивать их влияние на бизнес.
Как вы приоритизируете уязвимости для клиента, если отчет сканирования содержит тысячи критических находок? Какие метрики вы используете для оценки риска?
Упоминается использование Python, Bash и Regex для парсинга данных.
Приведите пример задачи по автоматизации процесса управления уязвимостями, которую вы решили с помощью скриптов и API Qualys.
Позиция подразумевает роль консультанта (Trusted Advisor).
Как вы справляетесь с ситуацией, когда ИТ-команда клиента отказывается устранять критическую уязвимость из-за риска нарушения работы бизнес-процессов?
Похожие вакансии
Security Engineer
Principal Network Security Engineer
Conseiller.ère en architecture de sécurité
Security Engineer, Cloud Security
Security Engineer, Application Security
Security Engineer
1000+ офферов получено
Устали искать работу? Мы найдём её за вас
Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!
- Страна
- США