Nelnet Logo

Nelnet

Vulnerability Management Engineer

Posted One Month Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in Centennial, CO, USA
75K-125K Annually
Junior
In-Office or Remote
Hiring Remotely in Centennial, CO, USA
75K-125K Annually
Junior
Lead and improve vulnerability management program: configure and run scanners, analyze findings, prioritize risks, drive remediation with technology teams, and align controls to industry benchmarks and frameworks.
The summary above was generated by AI

Nelnet is a diversified and innovative company committed to enriching lives through the power of service as a student loan servicer, professional services company, consumer loan originator and servicer, payments processor, renewable energy solutions, and K-12 and higher education expert. For over 40 years, Nelnet has been serving its customers, associates, and communities.

The perks of working at Nelnet go beyond our benefits package. When you join the Nelnet team, you're part of a community invested in the success of each individual. That support comes through in our work, as we are united by our mission of creating opportunities for people where they live, learn, and work.

Nelnet Cyber Security Group (CSG) is looking for an experienced and skilled individual to join the Vulnerability Operations (VO) team. Nelnet’s Vulnerability Operations team is responsible for managing the attack surface and collaboration with various business units to assess risk by identifying vulnerabilities and threats to our organization and working to drive remediation of identified security risks. The Vulnerability Operations team sits with in the larger Nelnet Cyber Security Group and works closely with the Nelnet Security Operations Center (SOC) and Offensive Operations team. Join Nelnet to lead and improve our efforts to identify, understand, and reduce the attack surface of Nelnet while helping our business units achieve the Nelnet core values for our customers, employees and communities we serve.
This position requires work in support of the Company’s contract with the United States Department of Education (“ED”). As such, the United States Government requires that any applicant for this position must complete United States Government security clearance. Effective June 1, 2018, ED has informed Nelnet that security clearance applications for foreign nationals are not being accepted or processed. In light of this direction from ED, Nelnet will be unable to hire applicants without United States citizenship for such positions.This position offers a hybrid work option. Nelnet values flexibility and understands the importance of work-life integration. Our hybrid work environment allows associates Living within 30 miles of an office location to work remotely for part of the week, while also fostering collaboration and team connection through in-office presence three days per week.

Please note that we are unable to provide visa sponsorship for this position. To be considered, candidates must already be authorized to work in the United States without the need for current or future sponsorship.

JOB RESPONSIBILITIES:

  • •    Lead the design, development, and continuous improvement of the organization’s vulnerability management strategy, aligning with business objectives and security requirements.
    •    Stay up to date on emerging security threats and vulnerabilities, and ensure the program adapts accordingly.
    •    Oversee the configuration and maintenance of vulnerability scanning tools.
    •    Analyze vulnerability data to assess risk and recommend appropriate mitigation strategies.
    •    Develop and implement vulnerability remediation plans, working collaboratively with all technology teams and the business.
    •    Collaborate with cross-functional teams to assess vulnerability risks, prioritize remediation efforts, and ensure timely resolution of critical vulnerabilities to minimize security risks and operational impact.
    •    Knowledge of CIS benchmarks, DISA STIGs, NSA Hardening Guides, and other industry security frameworks.
    •    Demonstrated passion for continuous learning.

EDUCATION: 

Bachelor’s degree in cyber security or information systems OR relevant work experience.

Cyber Security related certifications such as GIAC GSEC, GCED, GEVA, CompTIA Security+ , CySA+, ISC2 CISSP are a plus.

EXPERIENCE: 

•    2+ years of experience in vulnerability management and/or security operations.
•    Experience with Vulnerability management solutions (Rapid 7, Qualys, Tenable, etc.)
•    Experience with patching tools like Microsoft MECM.
•    Experience with EDR administration (Microsoft Windows Defender, CrowdStrike Falcon, VMware Carbon Black, Palo Alto Network Cortex XDR, Tanium etc.)
•    Solid understanding of cloud-based hosting platforms, with background on security threats deriving from Azure, AWS and GCP hosted services being preferred.
•    Partner with the SOC, Cyber Threat Intel, Offensive Security Team, and other stakeholders to refine prioritization, to validate impact of suspected vulnerabilities, to advise owners on mitigation strategies or compensating controls, and to provide accurate & timely reporting that informs remediation progress.

•    Knowledge of python programming language is required.

Pay range for this role is $75,000-$125,000 annually, depending on experience.

#LI-CW1

#LI-Remote

Our benefits package includes medical, dental, vision, HSA and FSA, generous earned time off, 401K/student loan repayment, life insurance & AD&D insurance, employee assistance program, employee stock purchase program, tuition reimbursement, performance-based incentive pay, short- and long-term disability, and a robust wellness program. Click here to learn more about our benefits: Benefits & Perks - Nelnet Inc.


Nelnet is committed to providing a welcoming and respectful workplace where all associates have the opportunity to succeed. As an Equal Opportunity Employer, we ensure that all qualified applicants are considered for employment. Employment decisions are made without regard to race, color, religion/creed, national origin, gender, sex, marital status, age, disability, use of a guide dog or service animal, sexual orientation, military/veteran status, or any other status protected by federal, state, or local law. We value the unique contributions of every team member and believe that a positive work environment benefits everyone.  


Qualified individuals with disabilities who require reasonable accommodations in order to apply or compete for positions at Nelnet may request such accommodations by contacting Corporate Recruiting at 402-486-5725 or [email protected].


Nelnet is a Drug Free and Tobacco Free Workplace.


Use of Artificial Intelligence in Hiring

We may use automated or artificial intelligence enabled tools to assist with the initial review of applications, such as identifying relevant skills or experience. These tools are used to support human review and do not make hiring decisions. A recruiter reviews applications and determines which candidates move forward in the hiring process. For more information, see our Privacy Policy and Pre-Use Notice: Automated Tools in Hiring

Nelnet Centennial, Colorado, USA Office

7150 S Fulton Street, Centennial, United States, 80112

Similar Jobs

21 Days Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
Mid level
Mid level
Artificial Intelligence • Big Data • Cloud • Security • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Own and improve vulnerability management across cloud, on-premises, network, and endpoint environments. Responsibilities include scanning, triage, risk-based prioritization, remediation coordination, SLA tracking, exception management, closure validation, asset reconciliation, reporting, incident support, on-call participation, and audit documentation. The role partners with Engineering, SRE, IT, and Infrastructure teams and uses security tooling and AI-assisted workflows to reduce exposure and recurring vulnerabilities.
Top Skills: Api AutomationAWSCmdbQualysRapid7 InsightvmTenableWiz
7 Days Ago
Remote
United States
90K-113K Annually
Senior level
90K-113K Annually
Senior level
Big Data • Cloud • Hardware • Software • App development
Maintains and secures enterprise end-user computing environments across Windows, macOS, Android, and iOS. Responsibilities include endpoint configuration, vulnerability patching, software packaging, virtual desktop administration, policy management, troubleshooting, documentation, hardware standards, automation, root cause analysis, vendor coordination, and support rotation participation.
Top Skills: Active Directory Group PolicyAnsibleAzureAzure Virtual DesktopBatchCitrixIntuneJAMFmacOSPowershellPythonServicenowShellVMwareVmware HorizonWindowsWorkspace One
One Month Ago
Remote
United States
170K-231K Annually
Senior level
170K-231K Annually
Senior level
Cloud • Security • Software
Lead Chainguard's vulnerability pipeline: measure, disclose, and report thousands of novel vulnerabilities; run CNA/CVE assignments; coordinate embargoes with customers and maintainers; automate large-scale pipelines; represent Chainguard with standards bodies and AI model vendors to shape disclosure practices.

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account