Security Engineer II - Cloud & Vulnerability Management
Venturefizz Product Management Community
Security Engineer II – Cloud & Vulnerability Management
The Security Engineer II – Cloud & Vulnerability Management is a key contributor to Nasuni's Information Security program, focused on protecting our hybrid and multi-cloud infrastructure through strong asset visibility, vulnerability management, and endpoint security. This role has a clear owner in the asset and vulnerability space: you will manage and operate the tools and workflows that keep our cloud, on-premises, and endpoint environments understood, assessed, and hardened. You will work within a well-supported security team that includes a dedicated SecOps function (handling the bulk of day-to-day detection and incident response). Your focus is on the engineering and operational work that keeps our infrastructure posture healthy and measurable, with meaningful incident response responsibilities when your expertise is relevant. Participation in an on-call rotation is required.
This role is responsible for executing and continuously improving vulnerability management, asset visibility, and cloud security processes. The Security Engineer II works independently within defined areas of ownership while partnering with senior security team members on broader security strategy and program evolution.
Asset & Vulnerability Management
- Own day-to-day execution of Nasuni's vulnerability management processes and tooling across cloud infrastructure (Wiz), on-premises and network assets (Rapid7), while contributing to ongoing program improvements.
- Support the maintenance of a current, accurate asset inventory across cloud workloads, physical infrastructure, network devices, and employee endpoints.
- Manage the full vulnerability lifecycle, including identification, triage, prioritization, remediation coordination, and validation.
- Partner with Engineering, SRE, and IT/Infrastructure teams to drive remediation activities.
- Produce clear, actionable vulnerability reporting for Engineering and IT/Infrastructure stakeholders and security leadership.
- Track remediation SLAs, identify patterns in recurring weaknesses, and recommend systemic improvements to reduce exposure.
- Contribute to patch management coordination efforts and support secure configuration baseline reviews across key asset classes.
- Maintain visibility and inventory accuracy across cloud, endpoint, network, and infrastructure assets in partnership with IT/Infrastructure teams.
Cloud and Infrastructure Security
- Monitor cloud security posture via Wiz across AWS, Azure, and GCP environments — identifying misconfigurations, high-risk exposures, and policy violations.
- Support secure configuration of cloud workloads, network controls, IAM, and infrastructure components in collaboration with engineering and SRE teams.
- Identify and escalate configuration drift, excessive permissions, and security gaps in cloud infrastructure.
- Provide security input on infrastructure changes and support security reviews as needed.
Incident Response
- Support security incidents where infrastructure, asset, or vulnerability context is needed.
- Independently manage and investigate moderate-severity security incidents within your domain; conduct root cause analysis and contribute to post-incident reviews.
- Maintain and improve documentation and runbooks for asset, vulnerability, and endpoint-related incident response procedures.
- Support additional incident response efforts as needed.
Compliance and Documentation
- Support internal and external evidence collection and control documentation for within your areas of ownership.
- Maintain accurate records of scanning activity, remediation outcomes, and asset coverage for audit readiness.
- Contribute to security awareness initiatives and help communicate security expectations around patch and configuration hygiene to engineering teams.
Growth and Collaboration
- Share knowledge and support team development through collaboration and peer guidance.
- Identify operational gaps and recommend practical improvements to strengthen security posture and program effectiveness.
- Leverage AI-assisted tools to improve security analysis, vulnerability triage, reporting, and operational workflows while validating outputs and maintaining accountability for decisions.
Expected Impact
- Improve visibility across cloud and infrastructure assets.
- Support timely vulnerability remediation against established SLAs.
- Improve vulnerability reporting quality and stakeholder actionability.
- Reduce recurring findings through operational improvements and stronger configuration hygiene.
What You Will Bring
Experience
- 3–6 years of experience in security engineering, cloud security, vulnerability management, or a closely related role.
- Hands-on experience managing vulnerability scanning or asset management programs in a cloud or hybrid environment.
- Experience coordinating remediation efforts across Engineering, Infrastructure and/or IT teams.
- Experience prioritizing vulnerabilities using risk-based methodologies and business context.
- Experience using AI-enabled tools to improve operational efficiency, analysis, investigation, or reporting while applying appropriate validation and security controls.
Skills
- Experience with cloud security platforms, ideally including Wiz or a comparable CSPM tool; familiarity with AWS, Azure, or GCP security fundamentals.
- Hands-on experience with vulnerability management tools such as Rapid7 InsightVM, Qualys, Tenable, or equivalent.
- Working knowledge of network protocols, network security fundamentals, and infrastructure security concepts (TCP/IP, firewall logic, segmentation).
- Familiarity with secure configuration standards such as CIS Benchmarks and common vulnerability frameworks (CVSS, CVE).
- Strong written and verbal communication skills. Able to translate vulnerability findings into clear, prioritized guidance for cross-functional partners.
- Ownership mindset: you follow through on commitments, track your own work, and raise blockers early.
- Collaborative and reliable partner across engineering, IT/infrastructure, and security teams.
Education and Certifications
- Bachelor's degree in Information Security, Computer Science, or a related field; or equivalent practical experience.
- Certifications preferred: CompTIA Security+, AWS Security Specialty, CySA+, or equivalent.
Why work at Nasuni?
As part of our commitment to your well-being, we are pleased to offer comprehensive benefits packages to employees across the US. Benefits packages generally include:
- Best in class employee onboarding and training
- "Take What You Need" paid time off policy
- Comprehensive health, dental and vision plans
- Company-paid life and disability insurance
- 401(k) and Roth IRA retirement plan
- Generous employee referral bonuses
- Flexible remote work policy
- 10 Paid Holidays
- Wide array of wellbeing offerings
- Pre-tax savings accounts with company contributions
- Great team culture and social activities
- Collaborative workspaces
- Free on-site fitness centers and stocked kitchens in select office locations
- Professional development resources
Compensation Transparency:
In accordance with U.S. pay transparency laws, Nasuni is committed to providing visibility into compensation for all U.S.-based roles. Actual compensation will be based on a variety of factors, including a candidate's experience, skills, education, and work location.
To all recruitment agencies: Nasuni does not accept agency resumes. Please do not forward resumes to our job boards, Nasuni employees or any other company location. Nasuni is not responsible for any fees related to unsolicited resumes.
Nasuni is an equal opportunity employer. The equal employment opportunity policy at Nasuni protects employees and job applicants from discrimination on the bases of race, religion, color, sex (including pregnancy, gender identity, and sexual orientation), parental status, national origin, age, disability, family medical history or genetic information, political affiliation, military service, or other non-merit based factors. These protections extend to all management practices and decisions, including recruitment and hiring practices, appraisal systems, promotions, and training and career development programs.
This privacy notice relates to information collected (whether online or offline) by Nasuni Corporation and our corporate affiliates (collectively, "Nasuni") from or about you in your capacity as a Nasuni employee, independent contractor/service provider or as an applicant for an employment or contractor relationship with Nasuni.
$74.5k - $87.4k
...related national security customers. Backed by Falfurrias Management Partners, the platform... ...programs, digital engineering, systems... ...with standards for cloud implementations. Architect... ...Conduct risk and vulnerability assessments and... .../ 8140 IAT Level II certification...SuggestedPermanent employmentFull timeContract workWork experience placementImmediate startRemote work- ...success. What You'll Be Doing The Security Engineer II - Cybersecurity Incident Response (... ...tools to help mitigate security vulnerabilities and automate repeatable tasks. Involvement... ...security incidents and escalate to management or other team members. Solid...SuggestedDay shift
$53 - $60.5 per hour
..., CA 90032 REMOTE Job Title : Security Engineer II, Attack Surface Management ssignment Duration : Direct Hire... ...discovering assets, identifying vulnerabilities, and driving remediation across infrastructure, cloud, applications, AI and connected/medical...SuggestedCasual workRemote work- ...Paragon is recruiting for a Security Engineer II to work on the PEO-T contract for USTRANSCOM... ...provides technical support in the areas of vulnerability and risk assessment, network security... ...recommendations and working with management to improve efficiency in processes...SuggestedContract workWork at office
- ...success . What You’ll Be Doing The Security Engineer II - Cybersecurity Incident Response (CSIR... ...tools to help mitigate security vulnerabilities and automate repeatable tasks. Involvement... ...security incidents and elevate to management or other team members. Solid understanding...SuggestedDay shift
$188k - $275k
...CoreWeave is The Essential Cloud for AI™. Built for pioneers... ...We are seeking a Staff Security Engineer to lead the most complex technical... ...work in CoreWeave's Vulnerability Management program. You will design and... ...U.S. citizen or national, (ii) U.S. lawful permanent resident...Permanent employmentTemporary workCasual workWork at officeFlexible hours- ...True Zero Vulnerability Management Position True Zero Technologies, a veteran... ...environments, including cloud and on-site scanning while... ...posture for program office and engineering partners. Job... ...Bachelor's degree ~3 years security-related experience. ~ Experience...Work at office
- ...redistribution and freight management to cutting-edge logistics technology... ...the supply chain. The Engineer II, Security position, reporting to the... ..., and security for all cloud-based infrastructure... ...capabilities Perform advanced vulnerability assessments and penetration...Local areaFlexible hours
- ...We're seeking a team member for the role of SVP, Vulnerability Management & Cloud Security Posture Platform Engineering to join our Cybersecurity Engineering Tools & Platforms team. This role is located in New York, NY; Pittsburgh, PA; or Washington, DC . This...Work experience placement
- ...global financial institution is seeking a Security Engineer II to join their Cybersecurity Software... ...security solutions, analyzing vulnerabilities, and collaborating with various stakeholders... ...and a strong understanding of cloud platforms are desired. #J-18808-Ljbffr...
- MWI Animal Health is seeking an Engineer II in Information Security to strengthen our cybersecurity framework. The ideal candidate will support information... ...threats. You will conduct penetration testing and vulnerability assessments, coordinate with various IT teams, and...
- ...Vulnerability Analyst II Purchase, New York Category: Data, Data Analysis... ...of vulnerability management data across multiple sources... ...closely with engineering, application, cloud, and governance teams to... ...vulnerability management tools, security concepts, and risk-based...Contract work
$165k - $242k
...CoreWeave is The Essential Cloud for AI™. Built for pioneers by... ...What You'll Do As a Cloud Security Engineer at CoreWeave, you'll drive the... ...and monitoring, configuration management, and data protection Utilize... ...) U.S. citizen or national, (ii) U.S. lawful permanent...Permanent employmentTemporary workCasual workWork at officeFlexible hours$65 - $75 per hour
...cybersecurity operational environment and Vulnerability Management related requirements/needs; Engage... ...scanning; Work Cyber related security operations ITSM (ServiceNow) assigned... ...workstation anti-virus software, DAT, and engineer updates. Performs virus scans and...Full time- ...Vulnerability Management / Security Engineer Sonoma Consulting is one of the fastest growing national IT Consulting and Executive Search company in the United States, which was founded in 2011 by Mark McGee, the President and CEO. Sonoma Consulting has two business...Local area
$50 per hour
...Our client is seeking a Security Engineer . This individual will play a key role in identifying... ...assessing, and remediating security vulnerabilities across cloud and on-premise environments. This is... ...Responsibilities and Duties Manage and improve the organization's...$125k - $152k
...Engineer Cyber II The Engineer Cyber II serves as a subject-matter expert... ...plans, and formal program management documentation to guide... ...consultation to Information System Security Officers (ISSO's) to ensure... ...leadership in the Army vulnerability management and Assess and...Temporary workWork experience placementInterim roleImmediate startFlexible hoursShift work- ...Senior Security Engineer II For Identity And Access Management (Iam) As a Senior Security Engineer II for Identity and Access Management (IAM) at Aledade, you... ...enhancing the security posture of our enterprise, cloud-native environments, and applications. We are seeking...Temporary workRemote workFlexible hours
- ...As a Senior Security Engineer II for Identity and Access Management (IAM) at Aledade, you will play a central role in enhancing the security posture of our enterprise, cloud-native environments, and applications. We are seeking a dedicated professional with in-depth knowledge...Temporary workRemote workFlexible hours
$187k - $220k
...and so are the rewards. At Robinhood, we view security as an engineering and design challenge, not an administrative one. We... ...next-generation automated defense systems. As a Senior Vulnerability Management Engineer, you will transform the program into a self-scaling...Work at officeFlexible hoursShift work3 days per week- ...Job Title: Security Engineer II Location: Milford, DE Type: Direct Hire... ...Technology Services to managing escalated security incidents... ...performance, and security for all cloud-based infrastructure... ...emerging threats. Perform vulnerability assessments and penetration...Permanent employmentFull timeLocal areaNight shiftWeekend work
- ...Network Security Engineer - II America Networks is a leading sensor and networking solutions partner... ...Industrial, Manufacturing, and Waste management space. We design and manufacture... ...solution and push the data on the best cloud platform to fit your needs, including...
$157k - $185k
...high, and so are the rewards. The Security Engineering team builds systems and practices that... ..., and operational resilience across cloud and application environments. We... ...efficiently. As a Security Engineer - AI Vulnerability Management, you will help evolve Robinhood’s...Permanent employmentWork at officeFlexible hoursShift work3 days per week- ...is seeking a motivated IT professional for their Systems Administration team. This role focuses on vulnerability analysis and remediation while collaborating with security experts to maintain standards. Candidates should have a bachelor's degree and experience with...
- CGI Njoyn is seeking a Senior Security Engineer to lead a dedicated vulnerability management practice within a significant banking environment. The role demands hands-on involvement with visible impacts, supported by a delivery team. Qualified candidates should have over...
- ...health care innovation firm is seeking a Senior Security Engineer II specializing in Identity and Access Management. This role will be responsible for designing, implementing... ...solutions, enhancing security measures across cloud-native environments. The ideal candidate will...Remote job
- ...difference for national security by joining a team of... ...of SAIC is seeking a Vulnerability Management Analyst to support a... ...Provides desktop engineering efforts to deploy, maintain... ...Eligibility). IAT-II Certification (i.e.,... ...IT, including cloud services; cyber; software...Flexible hours
- ...to enable national security missions worldwide.... ...seeking a Risk and Vulnerability Analyst II to support vulnerability... ...· Support cloud compliance scans and... ...with cyber defense engineering and system teams to... ..., and vulnerability management activities Qualifications...Full timeContract workWork at officeWorldwideMonday to FridayWeekend workAfternoon shift
$150k - $175k
...alternative investment managers, including private... ...improving a robust and secure technology foundation... ...and drive the firm's vulnerability management and patching... ...coordinate fixes directly with engineering and infrastructure... .... Knowledge of cloud security posture management...Shift work- ...Security Consultant II (Web Application Penetration Tester) NetSPI® pioneered Penetration... ...50+ pentest types, attack surface management, and vulnerability prioritization. The NetSPI... ...concentration in Computer Science, Engineering, Math, or IT preferred, or equivalent...Work experience placementRemote workWorldwideAfternoon shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer II - Cloud & Vulnerability Management. Be the first to apply!
- hardware security engineer United States
- endpoint security engineer United States
- associate security engineer United States
- senior cloud security engineer United States
- java security engineer United States
- product security engineer United States
- security infrastructure engineer United States
- lead security engineer United States
- entry level security engineer United States
- security engineering manager United States


