About the role
About Client:
The client is a prominent global technology solutions provider, renowned for its comprehensive range of services and products tailored to meet the diverse needs of businesses.
The company's core focus revolves around assisting organizations in managing and optimizing their IT operations, thereby driving productivity, efficiency, and innovation. It offers an extensive array of services, including strategic consulting, technology implementation, cloud computing, data center management, cybersecurity, software licensing, and hardware procurement.
In addition to its business-to-business (B2B) services, it also serves as a valuable resource for IT professionals and decision-makers, providing valuable insights and thought leadership through its various publications, webinars, and events.
Rate Range: $70-$75/Hr
Job Description:
- Contract Vulnerability Management Engineer to stand up a mature, sustainable vulnerability management program across Client s large and continuously changing asset estate. Over a 12–16 week engagement the resource will: (1) reconcile an authoritative asset inventory across Tenable, CrowdStrike, identity/endpoint sources, and the ServiceNow CMDB, with coverage-gap identification; (2) baseline current-state vulnerability posture, enriched with exploit intelligence (CVSS, EPSS, CISA KEV, validated-exploitable); (3) build a ServiceNow Vulnerability Response remediation workflow with risk-based prioritization and SLAs, and drive initial remediation waves; and (4) author runbooks and operate the program in steady state.
- This is a build-and-operate role - the ServiceNow Vulnerability Response workflow is the core deliverable.
- Reconcile asset data across Tenable, CrowdStrike, Okta / Active Directory / Intune, and the ServiceNow CMDB; identify scanner and agent coverage gaps.
- Aggregate and de-duplicate vulnerability findings; baseline posture; enrich with CVSS, EPSS, CISA KEV, and NodeZero validated-exploitable status; produce a risk-ranked register.
- Build and configure the ServiceNow remediation workflow (intake prioritize assign track verify/re-scan close); define SLAs; stand up the exception / risk-acceptance process.
- Drive initial remediation waves on highest-risk exposures in partnership with asset owners; report program metrics.
- Author operational runbooks and operate the program in steady state; provide weekly status.
- Apply frontier AI models (ChatGPT Enterprise, Claude) to accelerate de-duplication and analysis, prioritization, reporting, and workflow design.
Must-haves:
- Hands-on experience operating enterprise vulnerability tooling - Tenable and CrowdStrike (Falcon Spotlight / Exposure Management) at minimum.
- Risk-based prioritization using CVSS, EPSS, and CISA KEV; validated-exploitability a plus.
- ServiceNow Vulnerability Response / SecOps workflow build. Non-negotiable; this is the engagement s core (capital) deliverable.
- Remediation orchestration across infrastructure and application owners; SLA design; metrics and executive-ready reporting.
- Proficiency with AI frontier models (e.g., ChatGPT Enterprise, Claude) applied to security-engineering work, with an understanding of secure, governed AI use in an enterprise setting.
- NodeZero or other autonomous-pentest familiarity; patch and change-management integration; CMDB reconciliation.
- Insurance, financial-services, or other regulated-industry experience.
- Expectations: Self-directed build-and-operate; comfortable driving remediation through other teams and holding SLAs.
- Fully remote. Collaborative, fast-paced IT Security engineering team operating in a SAFe Agile model. ServiceNow is used for ITSM and SecOps; Zoom for collaboration.
- The culture is AI-forward, with frontier models actively used across security workflows. A heavy M&A cadence means the environment changes constantly.
- Tenable; CrowdStrike (Falcon Spotlight / Exposure Management, NG-SIEM); NodeZero; Okta, Active Directory, Intune / MDM; ServiceNow (Vulnerability Response, SecOps, CMDB); ChatGPT Enterprise and Claude.
- Joins an approximately 11-person security engineering team under IT Security leadership. Works closely with the in-house ServiceNow SecOps developer on the Vulnerability Response workflow build, coordinates remediation with infrastructure, endpoint, and application owners, and partners with the Compliance team on the exception / risk-acceptance process. Operates within SAFe Agile cadences.
- The Vulnerability Management project: asset and coverage inventory, current-state vulnerability assessment, the ServiceNow Vulnerability Response remediation workflow build with SLAs and initial remediation, and operational runbooks with steady-state operation.
About ApTask:
ApTask is a leading global provider of workforce solutions and talent acquisition services, dedicated to shaping the future of work. As an African American-owned and Veteran-owned company, ApTask offers a comprehensive suite of services, including staffing and recruitment solutions, managed services, IT consulting, and project management. With a focus on excellence, collaboration, and innovation, ApTask provides unparalleled opportunities for professional growth and development. As a member of the ApTask team, you will have the chance to connect businesses with top-tier professionals, optimize workforce performance, and drive success across diverse industries. Join us at ApTask and be part of our mission to empower organizations to thrive while fostering a diverse and inclusive work environment.
Applicants may be required to attend interviews in person or by video conference. In addition, candidates may be required to present their current state or government issued ID during each interview.
Candidate Data Collection Disclaimer:
At ApTask, we prioritize safeguarding your privacy. As part of our recruitment process, certain Personally Identifiable Information (PII) may be requested by our clients for verification and application purposes. Rest assured, we strictly adhere to confidentiality standards and comply with all relevant data protection laws. Please note that we only collect the necessary information as specified by each client and do not request sensitive details during the initial stages of recruitment.
If you have any concerns or queries about your personal information, please feel free to contact our compliance team at [email protected].
Applicant Consent:
By submitting your application, you agree to ApTask's (www.aptask.com) Terms of Use and Privacy Policy, and provide your consent to receive SMS and voice call communications regarding employment opportunities that match your resume and qualifications. You understand that your personal information will be used solely for recruitment purposes and that you can withdraw your consent at any time by contacting us at 732-355-8000 or [email protected]. Message frequency may vary. Msg & data rates may apply.