Security Engineer II @Nasuni
All Others
Salary unspecified
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted 1mth ago

[Hiring] Security Engineer II @Nasuni

1mth ago - Nasuni is hiring a remote Security Engineer II. 💸 Salary: unspecified 📍Location: USA

Role Description

Nasuni is hiring a Security Engineer II to strengthen vulnerability management across our cloud workloads, on-premises infrastructure, network assets, and employee endpoints. You will own the recurring operational work that turns security findings into measurable risk reduction:

  • Maintaining scanning coverage
  • Triaging vulnerabilities
  • Setting risk-based priorities
  • Coordinating remediation
  • Tracking service-level commitments
  • Validating closure
  • Producing actionable reporting

This is a hands-on vulnerability-management position, well suited to someone who has personally owned, shaped, and operated vulnerability workflows and followed findings through remediation.

You will join a well-supported security organization that includes a dedicated SecOps function responsible for most day-to-day detection and incident response. You will lead and contribute to incidents, including but not limited to, when vulnerability, asset and endpoint security, or infrastructure expertise is required. Participation in an on-call rotation is required.

You will independently manage defined areas of Nasuni’s vulnerability-management program within established security standards, making day-to-day prioritization and escalation decisions, coordinating with asset owners, and recommending improvements based on risk trends.

You will partner with senior security team members on program strategy, material risk exceptions, and broader security architecture decisions.

What you will do

  • Own recurring vulnerability scanning, triage, prioritization, remediation tracking, exception follow-up, and closure validation across hybrid infrastructure.
  • Operate and improve vulnerability-management tooling, including Rapid7 InsightVM or comparable platforms.
  • Use Wiz and other asset or cloud-security data to add workload, exposure, ownership, and business context to vulnerability decisions.
  • Maintain accurate visibility into servers, network devices, endpoints, cloud workloads, and other in-scope assets by reconciling scanner, endpoint, cloud, and inventory data.
  • Prioritize findings using exploitability, exposure, asset criticality, business impact, compensating controls, and available threat intelligence—not CVSS alone.
  • Partner with Engineering, SRE, IT, and Infrastructure teams to assign owners, agree on remediation plans, manage blockers, and verify that risk has been reduced.
  • Track remediation SLAs, exceptions, recurring weaknesses, and coverage gaps; escalate material risk using clear evidence.
  • Produce concise reporting that helps technical teams act and gives security leadership an accurate view of exposure and progress.
  • Recommend practical improvements to patching, configuration hygiene, asset ownership, reporting, and remediation workflows.
  • Lead and support security incidents as part of an on-call rotation.
  • Maintain runbooks, evidence, scan records, and remediation documentation for operational continuity and audit readiness.
  • Use AI-assisted tools to accelerate triage, analysis, reporting, and workflow improvement while protecting sensitive data, validating outputs, and remaining accountable for decisions.

Expected impact

You will improve asset and scanning coverage, make remediation priorities more actionable, strengthen SLA performance, improve closure validation, and help reduce recurring vulnerabilities through durable operating improvements.

Qualifications

  • Hands-on experience operating a recurring vulnerability management program or major workstream.
  • Experience with vulnerability discovery, triage, risk-based prioritization, remediation coordination, and closure validation.
  • Experience working with infrastructure, endpoint, network, or cloud asset owners to drive remediation.
  • Practical experience with a platform such as Rapid7 InsightVM, Tenable, Qualys, or equivalent.
  • Experience supporting security incidents as part of an on-call rotation.
  • Demonstrable experience in vulnerability management in a hybrid environment (AWS preferred).
  • Understanding of CVE/CVSS concepts, exploitability, asset criticality, network exposure, and compensating controls.
  • Working knowledge of infrastructure and network security fundamentals.
  • Ability to translate technical findings into clear priorities and actions.
  • Demonstrated ownership, follow-through, and early escalation of blockers.
  • Practical experience using AI-assisted tools in a professional workflow, with appropriate review, validation, and data-handling judgment.

Preferred qualifications

  • Experience with Rapid7 InsightVM.
  • Experience using Wiz or another CSPM platform for cloud workload vulnerability context.
  • Experience reconciling scanner data with CMDB, endpoint, cloud inventory, or ticketing systems.
  • Familiarity with CIS Benchmarks, CISA Known Exploited Vulnerabilities, EPSS, and risk-exception workflows.
  • Scripting, API, workflow-automation, or security-reporting experience.

Experience guidelines

Typically, 3–5 years of relevant security experience, including at least 2 years of direct vulnerability-management responsibility. Equivalent practical experience is valued. A relevant degree or certifications such as Security+, CySA+, or a cloud-security certification is helpful but not required.

Benefits

  • Best in class employee onboarding and training
  • "Take What You Need” paid time off policy
  • Comprehensive health, dental and vision plans
  • Company-paid life and disability insurance
  • 401(k) and Roth IRA retirement plan
  • Generous employee referral bonuses
  • Flexible remote work policy
  • 10 Paid Holidays
  • Wide array of wellbeing offerings
  • Pre-tax savings accounts with company contributions
  • Great team culture and social activities
  • Collaborative workspaces
  • Free on-site fitness centers and stocked kitchens in select office locations
  • Professional development resources
Before You Apply
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Security Engineer II @Nasuni
All Others
Salary unspecified
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted 1mth ago
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
×
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews

⚡ 127,070+ remote jobs, refreshed hourly

🔔 Real-time alerts: Apply first, direct to employer

🛡️ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later