Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior ConMon Engineer image - Rise Careers
Job details

Senior ConMon Engineer

About Coalfire


Coalfire is on a mission to make the world a safer place by solving our clients’ hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Denver, Colorado with offices across the U.S. and U.K., and we support clients around the world.


But that’s not who we are – that’s just what we do.

 

We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.


Position Summary

We’re looking for a Senior Continuous Management Engineer to lead and enhance vulnerability management processes, driving compliance and security in cloud-based environments. If you’re driven by a desire to innovate, excel at operational excellence, and thrive in a collaborative environment, come be part of a team committed to making the world a safer place. 


What You'll Do
  • Provide senior-level oversight for enterprise vulnerability management tools (for example, Tenable, Nessus, Burp, Qualys, Rapid7, Wiz, Prisma, Microsoft Defender), ensuring they remain updated and fully operational
  • Lead the execution of regular and on-demand scans across a variety of environments (operating systems, databases, web applications, containers), then collaborate with technical teams (for example, SRE and client administrators) to prioritize and remediate vulnerabilities
  • Serve as a key point of contact for monthly reporting on open vulnerabilities, vendor dependencies, and operational requirements, delivering clear data-driven updates to clients
  • Offer strategic, risk-based recommendations to improve vulnerability posture, aligning remediation with organizational and compliance objectives
  • Work closely with cross-functional teams to refine and integrate vulnerability management processes in cloud environments (AWS, Azure, GCP)
  • Enhance internal standards, processes, and documentation for vulnerability management, including training materials, standard operating procedures, and best practices
  • Lead or support security assessment and authorization initiatives to ensure adherence to compliance frameworks such as FedRAMP, HITRUST, and PCI


What You'll Bring
  • 5–7 years of professional experience in vulnerability management, compliance monitoring, or related security operations roles
  • Extensive background in managing vulnerabilities across operating systems, databases, networks, containers, web applications, and APIs
  • Experience supporting vulnerability management in at least two of the following cloud providers: AWS, Azure, GCP, with a proven track record of integrating tools into cloud workflows
  • Involvement with at least one compliance framework (for example, FedRAMP, HITRUST, PCI), contributing to security assessments and risk-based reporting
  • Demonstrated success producing periodic vulnerability status reports, ensuring timely remediation efforts and accountability across multiple stakeholders
  • Advanced administrative understanding of AWS, Azure, or GCP
  • Strong expertise in vulnerability scanning technologies and methods, including scoring systems (CVSS, CMSS)
  • Excellent communication, organizational, and documentation skills, with the ability to convey technical findings and remediation plans to both internal teams and clients
  • Demonstrated ability to coordinate and influence technical teams, fostering collaboration for effective vulnerability mitigation
  • Proficiency in scripting (for example, Python, PowerShell) for automating tasks and scaling vulnerability management solutions
  • Familiarity with defining and enforcing baseline configuration standards (for example, CIS Benchmarks) and presenting compliance findings
  • Professional/Expert level certifications in Azure or AWS or GCP
  • Security-focused cloud certifications for Azure or AWS or GCP


Bonus Points
  • Security+
  • CISSP
  • Terraform


$86,000 - $148,000 a year
The salary range listed is a reasonable estimate of the compensation range for this role based on national salary averages. The actual salary offer to the successful candidate will be based on job-related education, geographic location, training, licensure and certifications and other factors. You may also be eligible to participate in annual incentive, commission, and/or recognition programs.

Why You’ll Want to Join Us


At Coalfire, you’ll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where you’ll work most effectively – whether you’re at home or an office.


Regardless of location, you’ll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You’ll have opportunities to join employee resource groups, participate in in-person and virtual events, and more. And you’ll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options.


At Coalfire, equal opportunity and pay equity is integral to the way we do business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Coalfire is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation to participate in the job application or interview process, our Human Resources team at HumanResourcesMB@coalfire.com.

Coalfire Glassdoor Company Review
3.8 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Coalfire DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Coalfire
Coalfire CEO photo
Tom McAndrew
Approve of CEO

Average salary estimate

$117000 / YEARLY (est.)
min
max
$86000K
$148000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior ConMon Engineer, Coalfire

At Coalfire, we’re on a mission to make the world a safer place by tackling the toughest cybersecurity challenges our clients face. We’re searching for a Senior Continuous Management Engineer who is excited about leading and enhancing our vulnerability management processes within cloud environments. If you have a knack for operational excellence and a passion for collaboration, this role is perfect for you! You’ll provide senior oversight for critical vulnerability management tools, ensuring they remain operational and up-to-date. Regularly executing scans and collaborating with technical teams is key to prioritizing and remediating vulnerabilities. You’ll act as a vital point of contact for delivering data-driven reports to clients while offering strategic recommendations to bolster their vulnerability posture. With your extensive knowledge of cloud providers like AWS, Azure, and GCP, you’ll refine our vulnerability management processes in these environments. Your hands-on experience in compliance frameworks will further enhance our initiatives, enabling us to maintain adherence to standards such as FedRAMP and PCI. At Coalfire, you’ll thrive in a supportive environment designed for personal and professional growth. Together, we can create a safer digital world, making an impactful difference with every project we undertake.

Frequently Asked Questions (FAQs) for Senior ConMon Engineer Role at Coalfire
What responsibilities does a Senior Continuous Management Engineer at Coalfire have?

As a Senior Continuous Management Engineer at Coalfire, you will oversee enterprise vulnerability management tools, lead vulnerability scans across different environments, and work closely with cross-functional teams to integrate and enhance management processes. You'll also provide strategic, risk-based recommendations for vulnerability remediation and ensure compliance with frameworks such as FedRAMP and PCI.

Join Rise to see the full answer
What qualifications are required for the Senior Continuous Management Engineer position at Coalfire?

Candidates for the Senior Continuous Management Engineer role at Coalfire should have 5 to 7 years of experience in vulnerability management or related fields, expertise in managing vulnerabilities across various platforms, and familiarity with at least two major cloud providers such as AWS, Azure, or GCP. Professional and expert-level certifications in these cloud providers and understanding compliance frameworks are also essential.

Join Rise to see the full answer
How does Coalfire support their Senior Continuous Management Engineers?

Coalfire offers a collaborative and flexible work environment for Senior Continuous Management Engineers. We prioritize personal and professional growth by providing opportunities for training, certification reimbursements, and wellbeing support. Additionally, our culture fosters connection through employee resource groups and community-focused events.

Join Rise to see the full answer
What tools and technologies should a Senior Continuous Management Engineer at Coalfire be familiar with?

A Senior Continuous Management Engineer at Coalfire should be well-versed in vulnerability management tools such as Tenable, Nessus, Burp, and Qualys. Familiarity with cloud-based environments and tools for AWS, Azure, and GCP is crucial, as is proficiency with scripting languages like Python and PowerShell for automation purposes.

Join Rise to see the full answer
What is the salary range for a Senior Continuous Management Engineer at Coalfire?

The salary range for a Senior Continuous Management Engineer at Coalfire is between $86,000 and $148,000 per year. The actual salary will depend on factors like education, geographic location, and job-related experience. Additionally, candidates may be eligible for annual incentives and benefits.

Join Rise to see the full answer
Common Interview Questions for Senior ConMon Engineer
Can you explain your experience with vulnerability management tools?

In your response, highlight specific tools you've used, like Tenable or Qualys, and describe how you've utilized these tools for effective vulnerability scanning and remediation. Discuss the processes you followed and any improvements you made as a result.

Join Rise to see the full answer
How do you prioritize vulnerabilities in your security assessments?

When answering, discuss the frameworks or methodologies you employ, such as CVSS scoring or risk-based assessments, to prioritize vulnerabilities based on potential impact and likelihood. Provide examples from past experiences where you've made difficult prioritization decisions.

Join Rise to see the full answer
Describe a challenging vulnerability you encountered and how you remediated it?

Use the STAR method (Situation, Task, Action, Result) to explain a specific instance. Focus on the complexity of the vulnerability, your analytical process, and the outcome of the actions you implemented to resolve it.

Join Rise to see the full answer
What strategies do you use to keep up with the latest cybersecurity trends?

Share how you stay informed through industry publications, webinars, or online courses. Mention any cybersecurity communities or forums you participate in and how this helps you implement new knowledge in your role as a Senior Continuous Management Engineer.

Join Rise to see the full answer
How do you communicate technical findings to non-technical stakeholders?

Provide insight into your communication strategies, such as simplifying complex terms and using visuals or reports. Mention past experiences where you successfully conveyed risks or recommendations to stakeholders for actionable outcomes.

Join Rise to see the full answer
What is your experience with compliance frameworks like FedRAMP or PCI?

Discuss specific compliance frameworks you've worked with and outline your role in helping organizations adhere to those standards. Provide details about assessments you've participated in and how you approached meeting compliance requirements.

Join Rise to see the full answer
Can you describe a time you led a cross-functional team to enhance vulnerability processes?

Think of a specific project where you took the lead. Explain your role, the team members involved, how you facilitated cooperation, and the positive results achieved for vulnerability management.

Join Rise to see the full answer
What programming or scripting languages do you utilize for automating security processes?

Mention any relevant languages such as Python or PowerShell. Provide examples of scripts you’ve written to automate tasks, improve efficiency, and the impact this had on the vulnerability management process.

Join Rise to see the full answer
How do you handle a high volume of vulnerabilities within tight deadlines?

Describe your time management skills and prioritization techniques. Give examples of how you organized your workflow to tackle high-priority vulnerabilities first while ensuring thorough assessment and remediation.

Join Rise to see the full answer
What unique qualities can you bring to the Senior Continuous Management Engineer role at Coalfire?

Reflect on your key competencies, such as problem-solving abilities, leadership skills, and your passion for cybersecurity. Share specific strengths that align with Coalfire’s mission and values, demonstrating why you're a great fit for the team.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User

Join Coalfire as a Senior Manager to lead project management in cybersecurity consulting with a focus on client engagement and team development.

Photo of the Rise User
Posted 7 days ago

Join Anduril Industries as a Mission Success Specialist to oversee and enhance the performance of advanced defense technologies.

Photo of the Rise User

Join Peraton as a Lead Associate Configuration Manager and support essential high-performance computing initiatives vital to national security.

Photo of the Rise User
Posted 11 days ago

Join Trail of Bits as a Senior Security Engineer to enhance application security through thorough assessments and innovative tool development.

Photo of the Rise User
Posted 8 days ago

Join Tempus as an Enterprise Systems Administrator to advance healthcare through technology and precision medicine.

rogersbh Hybrid Corporate Center, Oconomowoc, WI
Posted 13 days ago
Photo of the Rise User

Join Bristol Myers Squibb as an Associate Director to lead laboratory systems initiatives that will enhance operational efficiencies and improve patient outcomes.

Coalfire is a cybersecurity and compliance services company that secures the future of businesses by solving complex cybersecurity challenges and is trusted by leading organizations across various sectors.

124 jobs
MATCH
Calculating your matching score...
BADGES
Badge ChangemakerBadge Diversity ChampionBadge Flexible CultureBadge Future Maker
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 12, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!