Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Threat Vulnerability Management Engineer image - Rise Careers
Job details

Senior Threat Vulnerability Management Engineer

About CommvaultCommvault (NASDAQ: CVLT) is the gold standard in cyber resilience. The company empowers customers to uncover, take action, and rapidly recover from cyberattacks – keeping data safe and businesses resilient. The company’s unique AI-powered platform combines best-in-class data protection, exceptional data security, advanced data intelligence, and lightning-fast recovery across any workload or cloud at the lowest TCO. For over 25 years, more than 100,000 organizations and a vast partner ecosystem have relied on Commvault to reduce risks, improve governance, and do more with data.JOB DESCRIPTION:What you’ll do…• Work with both on-prem and public cloud assets and assess the technology stack from the operating system through to the code and application stack.• Make major contributions to shaping both the technical and process aspects of the TVM lifecycle.• Configure and operate TVM scanning platforms; analyze and triage scan results; and work with internal partners and stakeholders to drive remediation of detected vulnerabilities.• Collect and oversee Application Security test processes executed by distributed development teams.• Define, organize, and execute penetration test efforts to assess targeted Commvault services, and information assets.• Establish & operate KPI/KRI metrics, and data trends analysis in support of management decisions.• Develop and drive cybersecurity initiatives related to threat & vulnerability management with adherent to ‘continuous monitoring’ and ‘continuous improvement’ thought process.Responsibilities include but are not limited to the following:• Day-to-Day Operation of Infrastructure Scan/Analyze/Triage/Remediate Process• Configure and operate TVM scanning platform.• Analyze & Triage scan results.• Prepare Scan metrics and reporting.• Work with internal stakeholders to remediate detected vulnerabilities.• Plan and execute focused TVM campaigns as needed.• Good knowledge on integration of scanning tools with other tools using connectors and any centralized vulnerability management tools (such as Keena, Vulcan) is preferable.• Penetration Test Planning, Coordination & Execution• May be required to directly conduct penetration tests against selected Commvault services and information assets.• May be required to plan, direct, and coordinate 3rd party penetration test teams.• Application Security Testing Management & Coordination• Monitor SAST, DAST, and Penetration tests executed by DevSecOps personnel on distributed development teams.• Act as SME to development teams if they require assistance interpreting and remediating results.• Collate, Merge, and Analyze AppSec/Secure SDLC scan results for trends and management reporting.• Reporting & Data Analysis• Establish and maintain KPI’s and KRI’s for the TVM Program and its Components.• Analyze collected scan data for latent patterns around technical vulnerabilities, or process deficiencies.• Threat Picture & Industry Knowledge• Cyber Threat Intelligence (CTI) knowledge.• Maintain current awareness of security trends, emerging threats, and recent zero-day exploits.• Apply such knowledge to Commvault’s Vulnerability picture, alerting management to specific escalated risks directly applicable to Commvault.Who you are...Education• BA/BS Degree or equivalent work experience.• Security Certifications—CISSP, OSCP, other penetration test certifications.• Cloud Certifications—Azure preferred.Experience• 10+ years in information security area.• 5+ years in a technical role with hands-on technology, either on the IT side, or in Security.• Direct experience with Active Directory, Windows, and Linux.• Experience with one of the major public cloud providers.• Solid knowledge of Network protocols and workings.• Direct hands-on penetration test experience.Soft Skills• Leadership—the ability to “lead up” by influencing senior members of the team.• Self-Starting & Self-Directing—ability and drive to see what needs to be done, and craft a solution.• Communications--Ability to work with all levels of stakeholders, from low level apprentices to senior management.• Communications--Ability to communicate complex situations to audiences at the appropriate level of detail.• Project Management & Coordination of cross functional/cross-departmental teams.Process & Workflow Design• Ability to author SOPs and processes.Data Handling & Analysis Skills• Ability to merge data from different sources for cross-source analysis.• Ability to query standard relational databases (SQL).• Ability to produce summary data analysis to drive KPI’s, KRI’s, trend analysis and to support management decisions.Technical Skills• Ability to configure scans and scan automation on one or more industry standard scanning platforms— (Tenable, Nessus, Qualys, etc).• Penetration test skills (Kali Linux, Burp Suite, etc).• Utility Scripting or light programming—as needed to automate and integrate toolsets.You’ll love working here because:• Continuous professional development, product training and career pathing• An inclusive company culture, opportunity to join our Community Guilds• Generous Global Benefits• Employee Stock Purchase PlanReady to #makeyourmark at Commvault? Apply now!#LI-JS1#LI-RemoteThank you for your interest in Commvault. Total compensation for this role is market competitive, and within the below base salary range:$68,000 - $195,500We’re proud to offer competitive benefits that care for you and your family through our 401K plan, health benefits (including medical, dental, and vision available for families and domestic partners), and pet insurance for your furry family members. You can also find the details of our U.S. benefits by visiting benefits.commvault.com.Commvault is an equal opportunity workplace and is an affirmative action employer. We are always committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status and we will not discriminate against on the basis of such characteristics or any other status protected by the laws or regulations in the locations where we work.Commvault’s goal is to make interviewing inclusive and accessible to all candidates and employees. If you have a disability or special need that requires accommodation to participate in the interview process or apply for a position at Commvault, please email accommodations@commvault.com For any inquiries not related to an accommodation please reach out to wwrecruitingteam@commvault.com.For our Candidates to prioritize your security:Commvault has been made aware of email and/or text correspondence scams that falsely state that the senders are from the Commvault HR team and/or a member of our leadership team. The scammers even conduct false interviews via email or text and then request personal information (name, address, birthdate, social security number, etc.) when returning the signed offer letter. Please note that Commvault does not conduct interviews by email or text, and we will never ask you to submit a W4 via email or prior to your first day of employment.If you think you have been targeted in this recruiting scam, please reach out to us at wwrecruitingteam@commvault.com. You can also find more tips about job scams and how to avoid them on the FTC’s website.

Average salary estimate

Estimate provided by employer
$70000 / ANNUAL (est.)
min
max
$60K
$80K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Threat Vulnerability Management Engineer, Commvault

As a Senior Threat Vulnerability Management Engineer at Commvault in Massachusetts, you will play a crucial role in fortifying our cyber resilience strategy. Your day will be filled with exciting challenges as you assess both on-premise and cloud-based assets, all while diving deep into the technology stack from the operating systems right through to the intricate application layers. You will be instrumental in shaping our threat and vulnerability management lifecycle, from configuring and operating scanning platforms to analyzing results and working closely with internal teams to remediate vulnerabilities swiftly. Your expertise in penetration testing will be put to the test as you facilitate comprehensive security assessments across our services. Furthermore, you will be responsible for establishing critical KPIs and KRIs while also engaging in continuous monitoring and improvement initiatives that keep our cybersecurity measures sharp and responsive. With a keen eye for trends and a rich background in security, you’ll bring invaluable insights into the ever-evolving threat landscape, advising management on pertinent risks to our operations. At Commvault, you won't just work – you'll be part of a dynamic team that values innovation, professional development, and a culture of inclusivity. Whether you're setting up scans, staging penetration tests, or collaborating with developers to optimize security results, your contributions will directly enhance our safeguarding strategies against cyber threats. If you are self-motivated, passionate about cybersecurity, and ready to take on these responsibilities, we can't wait to meet you!

Frequently Asked Questions (FAQs) for Senior Threat Vulnerability Management Engineer Role at Commvault
What are the responsibilities of a Senior Threat Vulnerability Management Engineer at Commvault?

As a Senior Threat Vulnerability Management Engineer at Commvault, your responsibilities will include assessing both on-prem and public cloud assets, operating vulnerability scanning platforms, analyzing results, driving remediation efforts, and conducting penetration tests. Additionally, you will manage Application Security test processes, establish KPIs, and engage in continuous cybersecurity improvements to support management decisions.

Join Rise to see the full answer
What qualifications do I need to become a Senior Threat Vulnerability Management Engineer at Commvault?

To qualify for the Senior Threat Vulnerability Management Engineer position at Commvault, you should have at least a BA/BS degree or equivalent experience, alongside industry-recognized security certifications such as CISSP or OSCP. You'll also need over 10 years in information security, including 5 years in a hands-on technical role, with direct experience in penetration testing and knowledge of cloud services.

Join Rise to see the full answer
What kind of experience is required for the Senior Threat Vulnerability Management Engineer position at Commvault?

In order to succeed as a Senior Threat Vulnerability Management Engineer at Commvault, you should have a strong background with over 10 years in the information security domain, at least 5 years in a technical role involving hands-on technology, as well as direct knowledge of Active Directory, Windows, Linux, and major public cloud platforms.

Join Rise to see the full answer
How does Commvault support the professional development of a Senior Threat Vulnerability Management Engineer?

Commvault is committed to your continuous professional development, offering product training and clear career paths within the organization. You will have opportunities to engage in community guilds, build leadership skills, and participate in various initiatives geared towards enhancing your growth as a Senior Threat Vulnerability Management Engineer.

Join Rise to see the full answer
What type of skills are important for a Senior Threat Vulnerability Management Engineer at Commvault?

Essential skills for a Senior Threat Vulnerability Management Engineer at Commvault include a strong technical foundation in cybersecurity, expertise in configuring and automating vulnerability scans, penetration testing skills, and the ability to analyze complex data sets for trends. Soft skills like leadership, effective communication, and project management are also critical for successful collaboration with team members and stakeholders.

Join Rise to see the full answer
Common Interview Questions for Senior Threat Vulnerability Management Engineer
Can you explain your experience with vulnerability scanning tools?

When answering this, highlight specific tools you have used, such as Tenable, Qualys, or Nessus. Discuss your expertise in configuring scans, automating processes, interpreting results, and collaborating with teams to mitigate vulnerabilities.

Join Rise to see the full answer
Describe your approach to penetration testing.

Articulate your methodology, including your planning phase, tools you prefer (like Burp Suite or Kali Linux), and how you report and remediate findings post-assessment. Providing a specific example would also add weight to your response.

Join Rise to see the full answer
What challenges have you faced when managing application security testing?

Discuss a specific challenge, like aligning security testing with development teams, and explain how you addressed it through effective communication, training, or adapting processes to ensure successful outcomes.

Join Rise to see the full answer
How do you stay updated on the latest cybersecurity threats?

Explain your proactive approach to learning, whether through industry publications, forums, webinars, or attending conferences. Mention specific resources such as Threat Intelligence platforms or security-related news websites.

Join Rise to see the full answer
Can you give an example of a successful remediation project you've led?

Provide a detailed example showcasing your role, the vulnerabilities identified, the collaboration with stakeholders, actions taken, and the results achieved imcluding improvements in security posture.

Join Rise to see the full answer
What strategies would you use to communicate risks to different stakeholders?

Emphasize the importance of tailoring your communication style based on your audience. For example, you might simplify technical jargon for non-technical stakeholders while providing detailed data analysis for senior management.

Join Rise to see the full answer
What do you consider are key elements to any effective cybersecurity program?

Identify critical components such as risk assessment processes, continuous monitoring, incident response plans, and employee training, and elaborate on how these elements work together to create a robust cybersecurity posture.

Join Rise to see the full answer
How do you prioritize vulnerabilities for remediation?

Discuss methods you would use to evaluate the risk and impact of vulnerabilities, such as CVSS scoring, business context, and potential exploitability, and how you would communicate these priorities to your team.

Join Rise to see the full answer
What is your experience with cloud security?

Provide an overview of your experiences with cloud environments (such as Azure), specific security practices you've implemented, and tools used alongside your understanding of shared responsibility models.

Join Rise to see the full answer
How do you assess the effectiveness of a threat vulnerability management program?

Mention metrics you consider essential, such as KPIs and KRIs, and discuss how you analyze trends over time to make informed improvements in the program.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 12 days ago
Photo of the Rise User
Posted 2 days ago
Photo of the Rise User
Core One Hybrid Sterling, Virginia
Posted 5 days ago
Photo of the Rise User
Posted 11 days ago
Photo of the Rise User
Bosch Group Remote EN109, Zona Industrial de Ovar, Lugar da Pardala, Ovar, Portugal
Posted 7 days ago

Commvault is a worldwide leader in delivering data readiness. We’re committed to ensuring you can protect, manage, move, recover, and use your data. Always. Our software automates mind-numbing IT tasks and makes your data work harder for you — so ...

29 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
December 18, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!