Posted Tuesday, August 11, 2026 at 4:00 AM OEC provides software solutions to those who work in the automotive parts and repair industry. Our solutions make it easier for automotive industry professionals to buy and sell parts, conduct repair research & planning, optimize estimates, improve the parts supply chain, and more. OEC partners with many of the world’s largest manufacturers, dealers and suppliers, shops and repairers, and service providers, giving our customers access to a comprehensive network and a streamlined workflow. Job Summary/Objective Serves as a hands-on Security Engineer to help shape and execute the company’s modern security vision. Designs, builds, and scales a holistic, end-to-end Vulnerability Management and Application Security program. Establishes clear risk metrics, embedding security into software development workflows, and partners closely with Engineering and IT to ensure pragmatic, timely remediation. Delivers steady, incremental security improvements without stalling engineering velocity. Key Responsibilities & Duties (essential to the job) Builds and oversees a unified Vulnerability Management Life Cycle spanning AWS cloud environments, legacy co-located infrastructure, containers, and application code. Defines, tracks, and reports on core program metrics (e.g., MTTR by severity, SLA compliance, SLA breach rates, patch coverage) to demonstrate risk reduction to executive leadership. Establishes clear, risk-based Remediation SLAs in collaboration with Engineering, DevOps, and IT Operations. Shifts security "left" by embedding automated SAST, DAST, SCA, and secret-scanning tools into modern developer pipelines (e.g., CI/CD workflows, Terraform checks). Expands application security controls beyond basic infrastructure/log monitoring to cover open-source dependency risk, code composition, and secure development practices. Designs and maintains security standards and architectures within AWS. Secures cloud configurations and Infrastructure as Code (IaC) templates in AWS using automated security scanning and continuous compliance rules. Partners with IT Infrastructure and Systems teams to streamline patch management practices across hybrid datacenter and cloud workloads. Monitors emerging threat vectors, zero-day vulnerabilities, and active exploits (EPSS/KEV catalogs) to dynamically adapt remediation priorities. Coordinates targeted vulnerability assessments, third-party penetration testing, and post-remediation verification. Education A bachelor’s degree from an accredited college or university is required, with a focus in Cybersecurity, Computer Science, Information Technology, or related discipline. In the absence of a degree, equivalent work experience directly related to the key responsibilities of the role will be considered as a substitute for the degree. Experience, Skills and Key Competencies At least 6 years of experience in hand-on cybersecurity, with significant experience operating as a Senior/Lead Security Engineer or Security Architect in growing engineering organizations, demonstrated experience navigating hybrid environments, and deep practical experience writing and deploying Terraform. Experience, Skills and Key Competencies (continued) Must also be able to demonstrate the following knowledge, skills and abilities: Strong working knowledge of native AWS security services (GuardDuty, Security Hub, IAM, KMS, Org-level controls). Versatile, generalist knowledge across Security Operations (SecOps), SIEM architecture, Detection & Response, and Vulnerability Management life cycles. Ability to build strong relationships with DevOps, IT, and software development teams through collaborative problem-solving rather than rigid auditing. Understanding of AWS architecture and Terraform configuration scanning to identify cloud-native misconfigurations and drift. Demonstrated ability to define program SLAs, build executive dashboards, and drive culture change around patch compliance and code hygiene. Flexible and adaptable approach to work and can easily adjust to shifts in priorities as the needs of the business change. Able to effectively work and thrive in a remote work environment that has limited opportunities for in-person interactions. Excellent communication skills and can tailor messaging to a specific audience/situation. Special Position Requirements Willing and able to attend virtual meetings with the laptop camera on. What makes working at OEC awesome? It varies from employee to employee. For some, it's the flexibility - whether it's remote work or a hybrid or in-person role, OEC takes our teams across multiple time zones and international communities. For others, it's the strong sense of camaraderie and community that celebrates both individuals and team-driven contributions. Or it could be the empowerment and how the team is encouraged to take risks, learn, and grow within a dynamic and supportive environment. But no matter what gets us out of bed in the morning, our whole global community is inspired to be forward thinking and drive innovative solutions for the automotive parts and repair industry. OEConnection is subject to certain governmental recordkeeping and reporting requirements for the administration of civil rights laws and regulations. In order to comply with these laws, we invite applicants and employees to voluntarily self-identify their gender, race and ethnicity. Submission of this information is strictly voluntary and refusal to provide it will not subject you to any adverse treatment. The information obtained will be kept confidential and may only be used in accordance with the provision of applicable laws, executive orders, and regulations, including those that require the information to be summarized and reported to the federal government for civil rights enforcement. When reported, data will not identify any specific individual. This information will be maintained separately from your application for employment. If you do not wish to self-identify at this time, you may do so in the future by submitting this form. Failure to provide the following information will not subject you to any adverse action or treatment. OEConnection is an Equal Opportunity/ Affirmative Action employer. We provide equal employment opportunities to all qualified employees and applicants for employment without regard to race, religion, sex, age, marital status, national origin, sexual orientation, citizenship status, veteran status, disability or any other legally protected status. We prohibit discrimination in decisions concerning recruitment, hiring, compensation, benefits, training, termination, promotions, or any other condition of employment or career development.
Vulnerability Management Security Analyst
University of Notre Dame
Software Engineer, Vulnerability Management
Stripe
Vulnerability Management Lead (R-00190)
True Zero Technologies
Vulnerability Management Engineer
Foresite
Senior Security Engineer, Vulnerability Management
1Password
Lead Information Security Engineer - Vulnerability Management
Fifththird