Avatar for Foresite MSSP
Foresite MSSP
Actively Hiring
Cybersecurity and compliance services provider

Vulnerability Management Engineer

Posted: 1 week ago• Recruiter recently active
Job Location
Remote Work Policy

In office

Visa Sponsorship

Not Available

RelocationAllowed
Skills
SSH
SOAR
SIEM
servicenow
Smb
Tenable Security Center
Role-Based Access Control (RBAC)
Custom Dashboards
Nessus Scanners
Custom Reporting
Google SecOps (Chronicle)
Tenable Vulnerability Management
Tenable APIs
Tenable Nessus Agents
Credentialed Scans
Tenable OT Security
Tenable Distributed Scanning Components
Cloud Scanner Pools
Uncredentialed Vulnerability Scans
Security Center Repository Configuration
Security Center Scan Zone Design
Security Center Analytic Query Construction
Tenable OT Security Specialized Scanning Profiles
Industrial Control Systems (ICS) Scanning
Custom Asset Filters
Saved Scan Templates
Vulnerability Priority Rating (VPR)
Cyber Exposure Score (CES)

About the job

Foresite is seeking an enterprise-level Vulnerability Management Engineer dedicated to the administration, engineering, and day-to-day operations of our Tenable product infrastructure. In this technical role, you will be responsible for building, optimizing, and maintaining our multi-tenant shared instances and standalone client consoles across Tenable Vulnerability Management and Tenable Security Center, along with Tenable OT Security for industrial clients and all other Tenable Modules.

The ideal candidate possesses deep technical knowledge of Tenable distributed scanning components, has hands-on experience running advanced credentialed scans, and holds a proven track record of converting raw threat data into highly organized, actionable remediation roadmaps for clients.

What you'll do:

  • Maintain scanner infrastructure & configuration hygiene: Monitor the health, availability, and version currency of distributed scanning infrastructure across complex multi-tenant environments — including on-premise Nessus scanners, cloud scanner pools, and Tenable Nessus Agents. Identify offline scanners, stale agent check-ins, plugin update failures, and linked-scanner issues, then coordinate resolution with client teams.
  • Enforce access control & RBAC: Configure and maintain strict Role-Based Access Control (RBAC) definitions, custom asset groups, and scanning permissions to enforce least privilege and limit administrative blast radius.
  • Support telemetry integrations: Maintain data ingestion pipelines from Tenable APIs over to enterprise analytical hubs, explicitly optimizing vulnerability telemetry streams for SIEM/SOAR engines like Google SecOps (Chronicle) and ITSM platforms like ServiceNow.
  • Optimize scan & assessment operations: Design, schedule, and execute deep credentialed and uncredentialed vulnerability scans across hybrid infrastructures, optimizing parameters to guarantee extensive visibility without causing network degradation.
  • Administer Security Center: Operate and maintain on-premise Tenable Security Center deployments for clients requiring self-hosted vulnerability management, including repository configuration, scan zone design, and analytic query construction.
  • Execute Operational Technology (OT) scanning: Execute specialized scanning profiles using Tenable OT Security to protect industrial control systems (ICS) where applicable for manufacturing and critical infrastructure clients.
  • Build custom reporting & dashboards: Build and maintain custom dashboards, asset filters, and saved scan templates tailored to client business units and regulatory needs.
  • Prioritize organizational risk: Utilize Tenable's Vulnerability Priority Rating (VPR) and Cyber Exposure Score (CES) to filter out operational noise and highlight immediately exploitable threats.
  • Generate actionable remediation roadmaps: Translate complex vulnerability data sets into clear, prioritized technical remediation checklists for client infrastructure teams, conducting recurring technical reviews to track system posture.

Who you are:

  • Experience: 4+ years in cybersecurity operations, system administration, or vulnerability management, with at least 2 years of dedicated, hands-on Tenable administration at scale (10,000+ assets).
  • Advanced troubleshooting capabilities: Proven ability to troubleshoot complex credentialed scanning failures over SMB and SSH.
  • Multi-tenant domain knowledge: Demonstrated ability to manage concurrent delivery across multiple client tenants without cross-contaminating client data, credentials, or findings.
  • Required Certifications: Must hold at least one active mandatory technical certification:

  • Tenable One Vulnerability Management Specialist

  • Tenable Security Center Specialist

  • Tenable One OT Exposure Specialist

Nice to have:

  • Multiple Tenable Certifications: Holding more than one of the required Tenable Specialist certifications listed above.
  • Adjacent Platform & Industry Certifications: Google SecOps / Chronicle Certified Professional, CompTIA Security+ / Network+ / Linux+, or CEH (Certified Ethical Hacker).
  • Helpful Experience with Additional Tenable Modules: Exposure to adjacent modules including Tenable Web App Scanning, Identity Exposure, Cloud Security, Attack Surface Management, Patch Management, Tenable One platform capabilities (Exposure View, Attack Path Analysis), AI Exposure, Enclave Security, PCI ASV, or Nessus Expert.
  • Licensing Familiarity: Understanding of Tenable's licensing model across modules — how asset counts, resource ratios, and add-on components affect client entitlements in an MSSP environment.

Why Join Foresite?

We are a mission-driven partner helping organizations navigate an increasingly complex threat landscape. Founded by security practitioners, we’ve grown into a global leader in SecOps and MDR by staying true to our core value: radical transparency. When you join Foresite, you are part of a "humans-first" culture where your expertise is valued, and your well-being is a priority. We leverage our Google Cloud Premier SecOps Partnership to stay at the cutting edge, but we know that our greatest asset is our people.

What we offer:

  • Comprehensive Health & Wellness: Robust medical insurance options to keep you and your family healthy.
  • Employer-Covered Insurance: We fully provide employer-paid Dental coverage, as well as Short-Term (STD) and Long-Term Disability (LTD).
  • Recharge & Refuel: We believe in a true work-life balance. You’ll start with 3 weeks of paid vacation, plus additional sick leave and paid company holidays to ensure you have time to recharge.
  • Growth & Mentorship: Access to world-class training and mentorship. We support your career trajectory, whether you’re looking to deepen your technical skills or move into leadership.
  • Impactful Work: Help protect global clients using the latest AI-enhanced security tools and GCP native technologies.

About the company

Foresite MSSP company logo

Foresite MSSP

Actively Hiring
Cybersecurity and compliance services provider51-200 Employees
Learn more about Foresite MSSP image

Funding

AMOUNT RAISED
$3M
FUNDED OVER
1 round
Round
S
$3000000
Seed - Jan 2019

Similar Jobs

Paklogics company logo
Paklogics
Paklogics delivers custom web, mobile, SaaS, and AI solutions with global staffing expertise