We are hiring an experienced Vulnerability Assessment Engineer for our client in Khobar, Saudi Arabia to own the end-to-end vulnerability management lifecycle, from assessment and risk prioritization through remediation tracking and reporting.
The role will primarily work with CrowdStrike Spotlight while conducting supplemental vulnerability assessments across infrastructure and devices outside agent coverage.
Key Responsibilities:Triage and prioritize vulnerability findings from CrowdStrike Spotlight across approximately 3,600 devices and 250 servers
Prioritize vulnerabilities using CVSS-based risk scoring and business impact
Coordinate remediation timelines for server/OS patching and network device firmware updates
Conduct supplemental vulnerability assessments for assets outside CrowdStrike coverage, including network devices, firewalls, and unmanaged/IoT devices
Assess infrastructure involving technologies such as Palo Alto, Fortinet, and Cisco MerakiCoordinate periodic internal and external penetration testing and track identified findings through closure
Monitor remediation SLAs and ensure vulnerabilities are addressed within agreed timelines
Produce recurring vulnerability posture, remediation, and compliance reports
Escalate confirmed high-risk vulnerabilities to the Security Analyst for inclusion in security monitoring workflows
Required Technical Skills:Strong hands-on experience in vulnerability management and assessmentExperience with CrowdStrike SpotlightStrong understanding of CVSS scoring and risk-based vulnerability prioritizationNetwork and infrastructure vulnerability assessment methodologies
Knowledge of vulnerability assessment across firewalls, network devices, servers, and endpoints
Penetration testing fundamentals or experience coordinating penetration testing activities
Patch management and remediation tracking
Experience managing vulnerability remediation SLAs
Compliance-focused vulnerability reporting, including support for regulatory requirements such as PDPLCandidates with strong experience across vulnerability assessment, vulnerability management, risk prioritization, remediation tracking, and enterprise security environments are encouraged to apply.
Only shortlisted candidates will be contacted.