Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Senior Vulnerability Management Engineer image - Rise Careers
Job details

Senior Vulnerability Management Engineer

Company Description

Sandisk understands how people and businesses consume data and we relentlessly innovate to deliver solutions that enable today’s needs and tomorrow’s next big ideas. With a rich history of groundbreaking innovations in Flash and advanced memory technologies, our solutions have become the beating heart of the digital world we’re living in and that we have the power to shape.

 

Sandisk meets people and businesses at the intersection of their aspirations and the moment, enabling them to keep moving and pushing possibility forward. We do this through the balance of our powerhouse manufacturing capabilities and our industry-leading portfolio of products that are recognized globally for innovation, performance and quality.

 

Sandisk has two facilities recognized by the World Economic Forum as part of the Global Lighthouse Network for advanced 4IR innovations. These facilities were also recognized as Sustainability Lighthouses for breakthroughs in efficient operations. With our global reach, we ensure the global supply chain has access to the Flash memory it needs to keep our world moving forward.

Job Description

We are seeking a highly skilled and experienced Senior Vulnerability Management Engineer to spearhead our vulnerability assessment, remediation, and attack surface reduction efforts.

This position involves leading the identification, assessment, and mitigation of vulnerabilities across various platforms, networks, and applications, with a focus on reducing the organization's attack surface.

The ideal candidate will have deep understanding of Enterprise IT and Engineering landscape and a proven track record in vulnerability management, with in-depth expertise in identifying, prioritizing, and mitigating vulnerabilities across complex enterprise environments.

ESSENTIAL DUTIES AND RESPONSIBILITIES:

  • Lead Vulnerability Management: Take ownership of the vulnerability management lifecycle, including identification, assessment, prioritization, remediation, and reporting of security vulnerabilities. Oversee regular vulnerability scans, penetration tests, and security assessments to identify weaknesses in systems, networks, and applications.
  • Attack Surface Reduction: Analyze and map the organization’s attack surface, identifying potential entry points and areas of exposure. Develop and implement strategies to reduce the attack surface across all digital assets, ensuring proactive defense against emerging threats. Continuously monitor changes to the IT environment to ensure the attack surface remains minimized.
  • Collaboration & Mentorship: Work closely with cross-functional teams, including IT, DevOps, and security operations, to integrate vulnerability management practices into development and operational processes. Provide mentorship and training to junior security team members.
  • Stakeholder Communication: Effectively communicate vulnerability management activities, findings, and risk mitigation strategies to technical and non-technical stakeholders, including senior leadership.
  • Critical Decision-Making: Make informed, critical decisions in high-pressure situations, ensuring the protection of the organization’s infrastructure and data.
  • Governance & Continuous Improvement: Stay current with the latest vulnerability management tools, technologies, and methodologies, and continuously improve the organization’s vulnerability management program. Ensure that vulnerability and attack surface management processes comply with industry standards, regulations, and organizational policies.
  • Automation and Tooling: Evaluate and implement tools and technologies to automate vulnerability scanning, risk assessment, and remediation tracking. Develop and maintain scripts, tools, and processes to streamline and enhance the effectiveness of the vulnerability management program.

Qualifications

REQUIRED:

  • Deep understanding of vulnerability management tools (e.g., Nessus, Qualys, Tenable), systems architecture, and security technologies.
  • Extensive experience in vulnerability assessment and management within large-scale, complex IT environments.
  • Working with large eco systems with a number of security related tools such as Asset Management, Vulnerability Scanners (Nessus, Qualys), Endpoint Protection (CrowdStrike, Defender), SEIM etc…
  • Proficiency in scripting languages (e.g., Golang, Python, Bash, PowerShell) and experience with automation tools.
  • Relevant certifications such as CISSP, CISM, or CEH are preferred

PREFERRED:

  • Exceptional communication skills, with the ability to translate technical issues into business risks for stakeholders.
  • Ability to make critical decisions under pressure and in complex situations.
  • High level of integrity, professionalism, and attention to detail.
  • Prior experience in a global, large-scale manufacturing environment is a plus.

Additional Information

Sandisk is committed to providing equal opportunities to all applicants and employees and will not discriminate based on their race, color, ancestry, religion (including religious dress and grooming standards), sex (including pregnancy, childbirth or related medical conditions, breastfeeding or related medical conditions), gender (including a person’s gender identity, gender expression, and gender-related appearance and behavior, whether or not stereotypically associated with the person’s assigned sex at birth), age, national origin, sexual orientation, medical condition, marital status (including domestic partnership status), physical disability, mental disability, medical condition, genetic information, protected medical and family care leave, Civil Air Patrol status, military and veteran status, or other legally protected characteristics. We also prohibit harassment of any individual on any of the characteristics listed above. Our non-discrimination policy applies to all aspects of employment. We comply with the laws and regulations set forth in the Equal Employment Opportunity is the Law poster.

Sandisk thrives on the power and potential of diversity. As a global company, we believe the most effective way to embrace the diversity of our customers and communities is to mirror it from within. We believe the fusion of various perspectives results in the best outcomes for our employees, our company, our customers, and the world around us. We are committed to an inclusive environment where every individual can thrive through a sense of belonging, respect and contribution.

Sandisk is committed to offering opportunities to applicants with disabilities and ensuring all candidates can successfully navigate our careers website and our hiring process. Please contact us at [email protected] to advise us of your accommodation request. In your email, please include a description of the specific accommodation you are requesting as well as the job title and requisition number of the position for which you are applying.

Based on our experience, we anticipate that the application deadline will be 05/24/2025 (3 months from posting), although we reserve the right to close the application process sooner if we hire an applicant for this position before the application deadline. If we are not able to hire someone from this role before the application deadline, we will update this posting with a new anticipated application deadline.

#LI-RT1

Compensation & Benefits Details

  • An employee’s pay position within the salary range may be based on several factors including but not limited to (1) relevant education; qualifications; certifications; and experience; (2) skills, ability, knowledge of the job; (3) performance, contribution and results; (4) geographic location; (5) shift; (6) internal and external equity; and (7) business and organizational needs.
  • The salary range is what we believe to be the range of possible compensation for this role at the time of this posting.  We may ultimately pay more or less than the posted range and this range is only applicable for jobs to be performed in California, Colorado, New York or remote jobs that can be performed in California, Colorado and New York.  This range may be modified in the future.
  • You will be eligible to participate in Sandisk's Short-Term Incentive (STI) Plan, which provides incentive awards based on Company and individual performance.  Depending on your role and your performance, you may be eligible to participate in our annual Long-Term Incentive (LTI) program, which consists of restricted stock units (RSUs) or cash equivalents, pursuant to the terms of the LTI plan. Please note that not all roles are eligible to participate in the LTI program, and not all roles are eligible for equity under the LTI plan. RSU awards are also available to eligible new hires, subject to Sandisk's Standard Terms and Conditions for Restricted Stock Unit Awards.
  • We offer a comprehensive package of benefits including paid vacation time; paid sick leave; medical/dental/vision insurance; life, accident and disability insurance; tax-advantaged flexible spending and health savings accounts; employee assistance program; other voluntary benefit programs such as supplemental life and AD&D, legal plan, pet insurance, critical illness, accident and hospital indemnity; tuition reimbursement; transit; the Applause Program, employee stock purchase plan, and the Sandisk's Savings 401(k) Plan.
  • Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, benefits, or any other form of compensation and benefits that are allocable to a particular employee remains in the Company's sole discretion unless and until paid and may be modified at the Company’s sole discretion, consistent with the law.

Average salary estimate

$140000 / YEARLY (est.)
min
max
$120000K
$160000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Vulnerability Management Engineer, SanDisk

Are you ready to take on the role of Senior Vulnerability Management Engineer with Sandisk in Milpitas, CA? If you’re passionate about security and thrive in a dynamic environment, then this is the opportunity for you! At Sandisk, we are more than just a tech company; we are innovators at the forefront of the data revolution, creating solutions that empower people and businesses around the globe. In this position, you will be leading our vulnerability management efforts, ensuring the identification and remediation of security vulnerabilities while reducing our attack surface. Your day-to-day role will involve conducting vulnerability assessments, overseeing security scans, and implementing robust strategies to mitigate risks. You will collaborate with cross-functional teams and mentor junior members, fostering a shared understanding of security across the organization. You'll communicate findings to a variety of stakeholders, ensuring everyone understands the risks and the necessary actions to take. We are looking for someone with extensive experience in vulnerability management and a deep understanding of enterprise IT systems. Your skills in automation, scripting, and using tools like Nessus and Qualys will be essential to your success. With your expertise, you will help us maintain a secure environment that not only supports our current operations but also opens up new avenues for innovation. Join Sandisk’s vibrant culture equipped with a commitment to diversity and inclusion, where your contributions truly make a difference!

Frequently Asked Questions (FAQs) for Senior Vulnerability Management Engineer Role at SanDisk
What are the main responsibilities of a Senior Vulnerability Management Engineer at Sandisk?

At Sandisk, a Senior Vulnerability Management Engineer is responsible for leading the entire vulnerability management lifecycle. This includes identifying, assessing, prioritizing, and remediating security vulnerabilities within our complex IT infrastructure. You’ll perform regular vulnerability scans, collaborate with IT and DevOps teams to integrate security practices, and develop strategies to minimize the attack surface across our digital assets.

Join Rise to see the full answer
What qualifications are required to apply for the Senior Vulnerability Management Engineer position at Sandisk?

To qualify for the Senior Vulnerability Management Engineer role at Sandisk, candidates should possess a deep understanding of vulnerability management tools like Nessus, Qualys, or Tenable. Extensive experience in large-scale IT environments is essential, along with proficiency in scripting languages such as Python or PowerShell. Relevant certifications such as CISSP or CISM are preferred, highlighting your commitment to cybersecurity.

Join Rise to see the full answer
How does the Senior Vulnerability Management Engineer role at Sandisk support attack surface reduction?

In the role of Senior Vulnerability Management Engineer at Sandisk, you’ll analyze and map the organization’s attack surface to identify potential vulnerabilities. By developing and implementing effective strategies for attack surface reduction, you’ll ensure that emerging threats are proactively addressed, ultimately protecting our data and IT infrastructure.

Join Rise to see the full answer
What skills are essential for successful communication in the Senior Vulnerability Management Engineer role at Sandisk?

Exceptional communication skills are crucial for a Senior Vulnerability Management Engineer at Sandisk. You will need to explain technical vulnerabilities to both technical and non-technical stakeholders clearly. Being able to translate complex issues into business risks will play a pivotal role in your ability to drive necessary actions and foster a culture of security awareness.

Join Rise to see the full answer
What tools and technologies will I work with as a Senior Vulnerability Management Engineer at Sandisk?

In the Senior Vulnerability Management Engineer position at Sandisk, you will work with a range of tools and technologies, including vulnerability scanners like Nessus and Qualys, endpoint protection solutions such as CrowdStrike or Defender, and various security-related tools like SIEM systems. You'll also leverage scripting and automation tools to enhance the effectiveness of our vulnerability management strategies.

Join Rise to see the full answer
Common Interview Questions for Senior Vulnerability Management Engineer
Can you explain your experience with vulnerability management tools?

When addressing this question, highlight your specific experiences with tools like Nessus, Qualys, or Tenable. Discuss how you've used these tools in past roles to identify, assess, and mitigate vulnerabilities within a complex IT environment, emphasizing both your hands-on skills and strategic application of these tools to improve security posture.

Join Rise to see the full answer
How do you prioritize vulnerabilities found during assessments?

Demonstrating your ability to assess risk is key here. Explain how you take into account factors such as the potential impact on the organization, the exploitability of the vulnerability, and existing mitigations in place. Discuss any frameworks or approaches you adhere to, such as CVSS scoring, to prioritize and focus on the most critical vulnerabilities.

Join Rise to see the full answer
Describe a time when you had to communicate a security risk to a non-technical audience.

Focus on a specific example from your past experience where clear communication was crucial. Discuss how you simplified technical jargon to make the risks understandable, detailing the methods you used to engage your audience and explain the importance of the necessary actions.

Join Rise to see the full answer
How do you approach collaboration with cross-functional teams?

Highlight your belief in building strong cross-departmental relationships. Talk about how you engage with IT, DevOps, and security teams, emphasizing your communication strategies and how you work together to integrate security practices seamlessly into operational routines.

Join Rise to see the full answer
What steps do you take to monitor changes in the IT environment that could impact security?

Outline your proactive approach to continuous monitoring, mentioning regular scans, assessments, and the use of threat intelligence sources. Discuss how you adapt the vulnerability management strategies based on the changing landscape of the IT environment and emerging threats.

Join Rise to see the full answer
Can you provide an example of a successful vulnerability remediation?

Share a specific instance where your actions led to successful remediation of a significant vulnerability. Discuss what steps you took, how you coordinated with teams, and what tools and methodologies you employed to address the issue effectively.

Join Rise to see the full answer
What are the most common vulnerabilities you've encountered?

Discuss widely known vulnerabilities you've encountered in your career, such as SQL injection, cross-site scripting, or misconfigurations. Provide insights into how these vulnerabilities can be mitigated and the importance of addressing them promptly.

Join Rise to see the full answer
How do you stay current with emerging threats and vulnerabilities?

Describe your routine for staying informed about the latest vulnerabilities and threats, whether it's through attending industry conferences, participating in webinars, or following cybersecurity news outlets and blogs. Emphasize your commitment to continuous learning in the ever-evolving field of cybersecurity.

Join Rise to see the full answer
What role does automation play in your vulnerability management process?

Explain the importance of automation in streamlining the vulnerability management process. Discuss specific tools or scripts you've used to automate tasks, such as scanning and reporting, and how this has improved efficiency and allowed you to focus on more complex security issues.

Join Rise to see the full answer
How would you approach teaching a junior team member about vulnerability management?

Share your mentoring philosophy and describe how you would break down complex concepts into manageable lessons. Discuss any resources you would provide, practical exercises you’d assign, and how you would encourage open communication to build confidence in their skills.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 10 days ago

Join Sandisk as an SSD Reliability Engineer to enhance the performance and reliability of cutting-edge storage solutions.

Photo of the Rise User
Posted 10 days ago

Seeking an experienced Principal Engineer in Reliability Engineering to lead reliability initiatives at Sandisk, a forefront company in advanced memory technologies.

Photo of the Rise User

Join Eagle Integrated Services as an Associate System Administrator to support IT services at FEMA, ensuring effective client solutions and user support.

Photo of the Rise User
Omilia Remote No location specified
Posted 8 days ago

Omilia is on the lookout for a skilled Product Security Manager to lead security initiatives and foster a culture of security across the organization.

Photo of the Rise User
Posted 13 days ago

Join Eurofins as an Information Technology Integration Specialist to improve efficiencies through technology integration in a leading bioanalytical testing company.

Photo of the Rise User

Join Peraton as an Information Assurance Security Advisor, where you'll enhance network and information security systems with cutting-edge technical solutions.

Photo of the Rise User
GE HealthCare Hybrid IL03-01-Chicago-500 W Monroe St
Posted 9 days ago

Join GE HealthCare as a Senior IT Auditor to shape our internal audit processes and ensure effective risk management in the healthcare technology sector.

As an Application Security Engineer at Clear Capital, you will enhance application security by identifying vulnerabilities and promoting secure coding practices.

Photo of the Rise User
Posted 9 days ago

Join Rentokil Initial as an Epicor Functional Analyst where you'll optimize business processes using your Epicor expertise in a hybrid working environment.

Photo of the Rise User
Posted 11 days ago

Become a vital part of Agile Defense by managing incidents in a high-stakes operations environment as an EOC Incident Manager.

Photo of the Rise User
Posted 10 months ago
Photo of the Rise User
Posted 10 months ago
Photo of the Rise User
Inclusive & Diverse
Diversity of Opinions
Work/Life Harmony
Dare to be Different
Reward & Recognition
Empathetic
Take Risks
Growth & Learning
Transparent & Candid
Mission Driven
Passion for Exploration
Feedback Forward
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Learning & Development
Paid Time-Off
Maternity Leave
Social Gatherings

As a global leader in data storage solutions, we’re committed to making people's digital lives better by delivering innovative, reliable, high-performance products that consumers and businesses can count on.

87 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
February 26, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!