# Lead Vulnerability Management Engineer

**Company:** [Cloudflare](https://hotfix.jobs/companies/cloudflare)
**Location:** Austin, TX
**Role:** Security Engineering
**Experience:** 5+ years
**Skills:** Vulnerability Management, Vulnerability Scanning, Qualys, Nessus, Rapid7 Insightvm, Cvss, Epss, Python, Artificial Intelligence, Jira, Nist, Pci-Dss, SOC 2, ISO 27001, FedRAMP
**Posted:** 2026-08-19

> Leads architecture, technology integration, scanning, risk prioritization, and remediation strategy for a global vulnerability management program. The role requires senior-level vulnerability management experience, security framework expertise, audit support, and the ability to automate workflows with AI.

## Job Description

## Responsibilities
- Serve as the primary technical lead for the Vulnerability Management team, providing architectural guidance and mentoring.
- Lead architecture, systems design, technology evaluation, and systems integration for the global vulnerability management program.
- Conduct advanced vulnerability scanning and validate findings, filter false positives, and triage and prioritize critical risks.
- Collaborate with technology owners and engineering teams to drive remediation or mitigation of complex vulnerabilities.
- Manage and track the remediation backlog and report on systemic security trends and risk-reduction progress.
- Design and implement AI-driven solutions to automate the vulnerability lifecycle and repetitive operational tasks.
- Improve global vulnerability management standards, procedures, and playbooks.
- Liaise with GRC teams to translate technical vulnerabilities and mitigations into compliance context for SOC 2, PCI-DSS, and FedRAMP readiness.
- Own technical reporting and evidence generation for audits, ensuring scanning cadences and remediation workflows meet compliance baselines.
- Translate regulatory requirements into technical scanning policies and integrate mandated checks into the scanning program.
- Be available for occasional on-call support outside standard working hours.

## Requirements
- 5+ years of vulnerability management experience in a senior or lead technical capacity.
- Bachelor's degree in Computer Science, Information Security, or a related field, or relevant security certifications.
- Strong understanding of security frameworks such as SOC 2, NIST, and PCI.
- Strong communication, interpersonal, and analytical skills.
- Understanding of CVSS and EPSS risk-scoring methodologies.
- Hands-on experience with vulnerability scanning platforms such as Qualys, Nessus, or Rapid7 InsightVM.
- Experience using AI to develop and manage complex workflows and applications.
- Experience supporting GRC or external audit cycles, including PCI-DSS, SOC 2, or ISO 27001.
- Ability to translate compliance requirements into technical scanning configurations and remediation SLAs.

## Nice-to-haves
- Python or other scripting languages for automation.
- AI development tools such as Opencode or Windsurf.
- JIRA or similar ticketing tools.
- Infrastructure penetration-testing tools.

## Compensation and Benefits
- Eligible to participate in Cloudflare's equity plan.
- Medical, dental, and vision insurance.
- Flexible spending and commuter spending accounts.
- Fertility and family-forming benefits.
- Mental health support and Employee Assistance Program.
- Global travel medical insurance.
- Short- and long-term disability insurance.
- Life and accident insurance.
- 401(k) retirement savings plan.
- Employee stock participation plan.
- Flexible paid time off and leave programs, including parental, pregnancy health, medical, and bereavement leave.

## Similar jobs

- [SOC Lead](https://hotfix.jobs/jobs/1b4ce51d-67b7-4000-a328-a6f0e74f22a6) - Idme - McLean, VA - $96k – $112k/yr
- [Senior Security Engineer](https://hotfix.jobs/jobs/9286e91d-ca35-4449-bb47-da0dc51b2aaa) - ConductorOne - Remote - $100k – $200k/yr
- [Security GRC Lead](https://hotfix.jobs/jobs/2eb261b0-5ff9-435d-b0fb-eaf5933051d1) - Mercor - San Francisco, CA - $350k – $425k/yr
- [Lead, Security Controls Assurance - SOX](https://hotfix.jobs/jobs/a1c11627-c920-4e31-abc6-2e170042a626) - Anthropic - San Francisco, CA - $410k – $510k/yr
- [Senior Platform Security Engineer](https://hotfix.jobs/jobs/3ac667bf-62fa-4280-8ccb-2af3468d8579) - Discord - $196k – $245k/yr

**Apply:** https://hotfix.jobs/jobs/8ea61c5d-6e75-4bdd-a56c-c2bd3f4e211c
**Canonical:** https://hotfix.jobs/jobs/8ea61c5d-6e75-4bdd-a56c-c2bd3f4e211c