Skip to content

Tenable Vulnerability Management Engineer

Symmetrio · Philadelphia, PA

Posted 9/2/2026 · last confirmed live 9/3/2026

Apply on Symmetrio’s site (opens in a new tab)
Symmetrio is recruiting a hybrid Tenable Vulnerability Management Engineer Consultant for our customer, a large government organization in Philadelphia, PA. This role is intended for an experienced, hands-on Tenable practitioner who can elevate and mature a large enterprise vulnerability management program. The successful candidate will bring recent, deep experience across the Tenable platform and will be expected to optimize how Tenable is configured, operated, automated, and used to drive risk-based vulnerability identification, prioritization, remediation, and executive reporting. This individual should be excited to expand the program beyond traditional infrastructure scanning by leveraging Tenable Vulnerability Management, Tenable Web App Scanning, APIs, automation, and other applicable Tenable capabilities. The candidate will also help advance the use of AI-enabled tools and techniques to analyze vulnerability data, identify patterns and exposures, improve prioritization, accelerate investigation, and support remediation decisions across a complex enterprise environment. Strong PowerShell and/or Python scripting skills are essential to automate repetitive activities, integrate data sources, enrich findings, and improve the efficiency and scale of the vulnerability management lifecycle. The ideal candidate is not simply a scanner operator; they are a vulnerability management engineer and program builder who can identify opportunities to improve coverage, data quality, risk prioritization, automation, metrics, and overall program maturity. This is a hybrid position, with 1–2 days per week required onsite at the Philadelphia office for team meetings, strategic planning, and stakeholder discussions. The position offers competitive compensation, health benefits, PTO, and a 401(k) plan. Responsibilities Conduct vulnerability assessments using Tenable to identify potential security vulnerabilities within our systems, networks, and applications. Collaborate with cross-functional teams to analyze and prioritize vulnerabilities based on risk levels and potential impact. Develop and implement vulnerability management processes, procedures, and best practices to ensure timely identification, remediation, and reporting of vulnerabilities. Monitor and track the remediation of identified vulnerabilities, ensuring that they are addressed within defined timelines. Stay updated with the latest security vulnerabilities, threats, and industry best practices to continuously improve the vulnerability management program. Perform regular vulnerability scanning and penetration testing to proactively identify and address potential security weaknesses. Work closely with IT teams to provide guidance and support in remediating vulnerabilities, including suggesting configuration changes, patches, and other remediation actions. Provide technical expertise and guidance to internal stakeholders on vulnerability management issues and best practices. Collaborate with the Incident Response team to investigate and respond to security incidents related to vulnerabilities. Requirements Bachelor's degree in Computer Science, Information Security, or a related field, preferred but not required with acceptable experience. 3-5 years of recent, hands-on experience administering and engineering Tenable solutions in a large enterprise environment is acceptable in replacement of education. Relevant certifications (e.g., CISSP, CEH, GIAC), including Tenable or other vendor certifications, are highly desirable. Demonstrated recent experience with the Tenable platform, with strong hands-on expertise in Tenable Vulnerability Management (Tenable.io) and Nessus, including scanner deployment and management, scan configuration, asset discovery, tagging, credentialed scanning, plugin management, troubleshooting, dashboards, reporting, and platform optimization. Experience using Tenable Web App Scanning to identify and assess vulnerabilities in web applications and APIs; experience with additional Tenable services and capabilities is strongly preferred. Proven experience designing, operating, and maturing an enterprise vulnerability management program, including vulnerability discovery, validation, risk-based prioritization, remediation tracking, exception management, metrics, reporting, and continuous improvement. Advanced scripting and automation skills, particularly PowerShell; Python or similar scripting experience is highly desirable. Must be able to create and maintain scripts that automate Tenable administration, data collection, enrichment, reporting, integrations, remediation workflows, and other vulnerability management activities. Experience working with Tenable APIs and integrating Tenable vulnerability and asset data with enterprise technologies such as ticketing systems, SIEM/SOAR platforms, CMDBs, asset inventories, dashboards, or other security tools. Demonstrated ability and interest in leveraging AI tools to assist with vulnerability analysis, data correlation, pattern identification, prioritization, remediation research, scripting, reporting, and other vulnerability management use cases while applying appropriate validation and security controls to AI-generated outputs. Strong understanding of vulnerability intelligence and risk-based prioritization, including CVE, CVSS, CISA Known Exploited Vulnerabilities (KEV), exploitability, threat intelligence, asset criticality, exposure, compensating controls, and business impact. Solid understanding of common vulnerabilities, attack vectors, mitigation techniques, network and application security concepts, and the ability to distinguish actionable risk from scanner noise or false positives. Experience with network scanning, authenticated/credentialed scanning, web application scanning, vulnerability validation, and penetration testing or vulnerability exploitation techniques. Knowledge of industry standards and frameworks such as CVSS, CVE, OWASP, NIST, and vulnerability management best practices. Strong analytical, troubleshooting, communication, and problem-solving skills, with the ability to translate technical vulnerability data into clear remediation guidance and risk information for infrastructure teams, application owners, leadership, and other stakeholders. Demonstrated ability to independently identify gaps in vulnerability coverage, tooling, processes, automation, reporting, and governance and recommend and implement improvements that measurably increase vulnerability management program maturity. Benefits Health Care Plan (Medical, Dental & Vision) Retirement Plan (401k) Paid Time Off (Vacation, Sick & Public Holidays)

How your resume reads against this

What this posting states beside what your resume says. No match percentage: there is not an honest one to give.

This reads the resume you have in the editor, and this browser has none yet.

Open the editor and upload yours

Free, no account. It stays in this browser and is never stored on our side.

This role is published by Symmetrio on workable. SwiftFit is not the employer and does not accept applications.