Overview
Security Engineer focused on vulnerability management, turning high-volume security findings into validated, risk-prioritised remediation work that gets fixed.
What you'll do
- Triage and validate vulnerabilities from security tooling to separate real, exploitable, relevant findings from noise.
- Support risk-based prioritisation using severity, exploitability, asset criticality, and business context.
- Automate remediation workflows in Seemplicity, including routing, ticketing, deduplication, and escalation logic.
- Verify fixes via re-scanning or manual checks before closing tickets.
- Drive reporting and dashboards on vulnerability posture, remediation progress, SLA adherence, and trends.
- Maintain the remediation pipeline by monitoring ageing findings and identifying stalled items and systemic blockers.
- Run strategies to nudge fix behaviours to reduce time-to-remediate and recurring issues.
What you'll need
- Hands-on vulnerability management experience or a similar analytical security role.
- Familiarity with vulnerability/exposure tooling such as Wiz, Semgrep, CrowdStrike Exposure Management, or EASM platforms.
- Understanding of vulnerability scoring/prioritisation concepts including CVSS, EPSS, CISA KEV exploitability, and asset context.
- Ability to handle risk acceptance/exception management with proper documentation, approvals, and tracking.
- Experience or strong appetite for workflow automation/orchestration via Seemplicity, scripting, or integrations.
- Confidence building reports and dashboards from complex data into clear narratives.
- Strong communication skills for explaining findings and translating remediation progress into metrics.
Details
- Flexible workplace model supports both in-person and remote work.
- Remote work supported, with regular in-person gatherings encouraged.
Read the full description and apply on the company’s own careers page.