Senior Security Specialist, Vulnerability Management
About the role
We’re looking for a Vulnerability Management expert to evaluate, prioritize, and drive remediation of security vulnerabilities across Viasat’s global infrastructure. You’ll cut through the noise of daily CVE disclosures, determine the most efficient mitigation paths, and scale the program through automation while ensuring alignment with internal and external audit requirements.
Responsibilities
- Efficiently evaluate and respond to the daily influx of newly disclosed CVEs, separating theoretical risks from immediate, real-world threats to our business.
- Determine the optimal mitigation path—whether that means coordinating a full software/OS update, deploying a temporary configuration workaround, or implementing compensating security controls.
- Navigate system ownership by tracking down and identifying the exact system owners and engineering teams responsible for vulnerable assets, ensuring every high-priority vulnerability is routed to the right person for swift remediation.
- Design and build automation concepts with fellow security engineers to scale the program, allowing us to handle a high volume of threats without increasing manual overhead.
- Serve as the technical representative during internal and external audit reviews, collaborating directly with auditors to illustrate program maturity and detail vulnerability scanning methodologies.
- Create automated dashboards to track operational efficiency metrics, including Mean Time to Detect (MTTD) relevant CVEs and Mean Time to Remediate (MTTR).
- Lead zero-day assessments as the initial responder during urgent vulnerability disclosures, quickly scoping exposure, assessing the blast radius across infrastructure and codebases, and coordinating response efforts.
- Develop automated data visualizations and reporting tools that retrieve audit evidence on demand, such as proof of patching SLA adherence, historical scanning cadences, and approved risk exceptions.
- Analyze internal data against advisories to identify critical risks relevant to our infrastructure and work to mitigate them.
- Support audits and regulatory compliance by serving as the technical point of contact, demonstrating program maturity, and explaining vulnerability scanning methodologies.
Requirements
- 5+ years of experience in Vulnerability Management, with at least 3 years dedicated specifically to tactical vulnerability management.
- In-depth knowledge of modern vulnerability evaluation frameworks, including EPSS, CVSS, SSVC, and KEV.
- Demonstrable experience preparing for and participating in external third-party security audits (e.g., ISO 27001, PCI, or CMMC).
- Demonstrated ability to confidently explain vulnerability prioritizations, technical workarounds, and formal risk acceptance/exception decisions to both internal compliance teams and external auditors.
- Deep hands-on experience with enterprise scanners and cloud-native security platforms.
- Good understanding of operating system internals, container environments, and cloud security fundamentals.
- Demonstrable ability to translate complex vulnerability details into clear, actionable technical instructions for engineering partners without direct authority.
Skills
- Artificial Intelligence: Familiarity with AI technologies, with a strong preference for knowledge in AI risk and governance frameworks (experience applying these concepts to vulnerability management is a major plus).
- Penetration Testing: Experience with penetration testing methodologies and tools to help validate vulnerability exploitability and assist with remediation prioritization.
- Workflow Automation: Prior experience building security pipelines inside automation and orchestration platforms.
- CI/CD: Familiarity with CI/CD tools and automated configuration/deployment environments.
- Active Security Community Engagement: A passion for following emerging threats, exploit trends, and security research.
- Industry Certifications: SANS GPEN or GEVA.
- Web Applications: Experience in assessments or penetration testing of web applications and Internet-facing tech stacks.
Pay
Salary range: $121,000.00 - $191,000.00 annually. For specific work locations within San Jose, the San Francisco Bay area, and the New York City metropolitan area, the base pay range for this role is $150,000.00 - $225,000.00 annually.
Base pay may vary depending on job-related knowledge, skills, and experience. Additional cash or stock incentives may be provided as part of the compensation package, in addition to a range of medical, financial, and/or other benefits, dependent on the position offered.
Benefits
Learn more about Viasat’s comprehensive benefit offerings that are focused on your holistic health and wellness at https://careers.viasat.com/benefits.