Vulnerability Management Engineer
- Hiring from
- United States
- Work type
- Hybrid
- Posted
- Sep 25, 2026
Who you are:
You are not satisfied with a scanner that emails out a list of forty thousand findings. You want to know which ten actually matter, why, and how to get them fixed, ideally without a person having to chase each one.
You are a builder at heart. You would rather write the automation that closes the loop than track the ticket by hand, and you are excited by the idea of AI agents that triage, correlate, and remediate alongside you.
You like working with people across infrastructure, cloud, application, and manufacturing teams, and you know that making it easy to fix things is most of the job.
Helping You Thrive By:
- Offering competitive wages and benefits, that support your life both in and out of work
- Providing a flexible hybrid work schedule, meaning we expect the office to be your primary place of work, balanced with choice and control.
- Creating continuous learning opportunities to help you grow and upskill.
- Fostering a culture of inclusion where employees feel seen, heard and valued — and living it out every day.
- Empowering you to make a meaningful impact on people and the planet through your work and Steelcase’s ongoing commitment.
You’ll Support Meaningful Work By:
- Owning the vulnerability management program end to end across endpoints, servers, cloud, containers, applications, and manufacturing environments.
- Building AI-assisted triage and prioritization that combines exploitability, threat intelligence, asset context, and business impact so we fix what attackers will actually use, not what a severity score says.
- Designing automated remediation workflows: patch orchestration, ticket creation and routing, exception handling, and verification, with people in the loop where it matters and out of the loop where it does not.
- Partnering with infrastructure, cloud, application, and plant-floor teams to make secure configuration and rapid patching the default rather than the exception.
- Running and improving attack surface management, external exposure monitoring, and penetration test coordination and follow-through.
- Turning noisy data into clear metrics and stories that help leaders see where risk is shrinking and where it is not.
- Experimenting constantly: evaluating new tooling, building proofs of concept, and sharing what you learn with the broader security team.
Minimum Qualifications
- Hands-on experience with vulnerability scanning, assessment, or remediation in an enterprise environment.
- An automation-first instinct: you reach for a repeatable solution rather than a manual one. How you get there is up to you — scripting in Python or PowerShell, working with APIs, or using AI and low-code tooling to build what you need.
- Understanding of how vulnerabilities are exploited and how to prioritize them in context, using inputs such as CVSS, EPSS, known-exploited lists, and asset criticality.
- A collaborative working style and the ability to explain technical risk clearly to the people who need to fix it.
- Bachelor’s degree in a related field, or equivalent experience.
Desired Skills and Experience
- Experience with platforms such as Qualys, Tenable, Rapid7, Wiz, Nuclei, or Microsoft Defender Vulnerability Management.
- Experience with cloud security posture management, container security, or application security testing.
- Familiarity with OT/ICS or manufacturing environments and their patching constraints.
- Experience using large language models, agents, or workflow automation to enrich, triage, or act on security findings.
- Experience with ServiceNow or similar platforms for remediation workflows.
- Certifications such as Security+, GSEC, GCIH, OSCP, CISSP, or cloud provider security certifications.
Qualified applicants must be authorized to work in the United States on a full-time basis. Steelcase will not provide support for or sponsor work authorization and/or visas for this role.
#mid_senior_level
#LI-Onsite
#Information_Technology
#Management
#Consulting
#LI-EW1
At Steelcase, we put people at the center of everything we do. We understand the role of work and believe that it can bring meaning and purpose to the lives of our customers and our employees. We prioritize supporting our employees both in and out of work, in all aspects of their lives. When we bring our talents together, we make a positive lasting impact through our work and communities.
Steelcase provides employment opportunities to all qualified employees and applicants without regard to race, color, creed, genetic information, religion, national origin, gender, sexual orientation, gender identity and expression, age, disability, or veteran status and bases all employment decisions only on valid job requirements. If we can make the application process easier through accommodation, please email us at myhr@steelcase.com.