Security Specialist, Vulnerability Management (US Remote)
Irvine, CA - USA
Job Summary
AXON Networks delivers a robust AI-driven analytics-based orchestration platform and a wide portfolio of next-gen high-speed routers that leverage the newest Wi-Fi technologies. Together these technologies give ISPs the ability to manage and troubleshoot their networks in real time and to deliver an outstanding customer experience.
AXON Networks is a trusted strategic partner for its customers helping them evaluate their current technologies and business models and creating and executing strategies that enable them to innovate faster accelerate their digital transformations and strengthen their relationships with consumers.
AXON Networks is headquartered in Irvine CA USA with Asia HQ in Singapore and also operating in Denmark Spain and Vietnam.
The Security Specialist Vulnerability Management will establish and operate a risk-based vulnerability management capability across the companys cloud platform applications Kubernetes and container environments network infrastructure software supply chain and cloud-managed customer-premises equipment (CPE) including broadband gateways routers ONTs and connected-home devices. This is a hands-on security engineering role for someone who can distinguish a scanner finding from a vulnerability that is relevant and exploitable in the companys actual environment.
The engineer will select and configure scanning approaches validate findings analyze CVEs prioritize risk coordinate remediation verify closure and create the dashboards evidence and operating standards needed for a repeatable program. The engineer will explain risk clearly to operational and engineering leaders and will not rely on severity scores alone.
Establish authoritative visibility into vulnerabilities across cloud application container Kubernetes network endpoint dependency firmware and CPE asset classes.
Determine whether findings and CVEs apply to the versions configurations exposure paths and controls actually present in the environment.
Prioritize remediation using technical severity known exploitation likelihood reachability asset criticality customer impact and compensating controls.
Create a durable operating model for intake validation assignment service levels exceptions rescanning closure and executive reporting.
Partner with Engineering DevOps NOC Support Product and Compliance to reduce measurable exposure without disrupting reliable customer service.
Inventory the attack surface and define coverage for internet-facing and internal assets cloud services hosts network devices containers Kubernetes clusters applications APIs source code third-party dependencies images infrastructure as code and supported CPE/firmware.
Design configure and maintain authenticated and unauthenticated scans agent-based assessments cloud-native configuration checks container and dependency scans external attack-surface discovery and targeted validation tests.
Establish safe scan windows credentials rate limits exclusions and testing procedures so scans do not destabilize production customer environments or large CPE fleets.
Evaluate select and administer appropriate capabilities from platforms such as Tenable Nessus Qualys Rapid7 Wiz Orca Prisma Cloud Snyk Veracode Checkmarx Trivy Grype Nuclei or equivalent tools; integrate results rather than requiring one product to solve every use case.
Measure coverage scan health credential success stale assets and blind spots; continuously improve asset-to-owner mapping and data quality.
Review new and existing scan findings and determine whether each is a true positive false positive duplicate accepted risk mitigated condition or actionable vulnerability.
Analyze CVE applicability using affected component and version package provenance CPE or firmware bill of materials runtime reachability configuration network exposure privileges exploit prerequisites and existing controls.
Reproduce or safely validate material findings when needed using vendor advisories proof-of-concept analysis logs configuration evidence package inspection and non-production testing.
Document defensible disposition evidence and prevent unsupported suppression of findings or indefinite exception status.
Monitor vulnerability intelligence and vendor advisories for cloud Kubernetes Linux networking broadband/CPE open-source and commercial technologies used by the company.
Use CVSS as a severity input not a standalone risk decision and enrich prioritization with CISA Known Exploited Vulnerabilities EPSS exploit availability exposure reachability asset criticality tenant/customer impact and compensating controls.
Define remediation and mitigation targets by risk tier; rapidly escalate actively exploited or internet-reachable vulnerabilities and coordinate emergency response when .
Create clear remediation records with affected assets evidence owners due dates recommended actions validation criteria and customer or operational considerations.
Partner with Engineering and DevOps on patches upgrades configuration changes image rebuilds dependency updates firmware releases and compensating controls; verify closure through rescans or equivalent evidence.
Manage risk exceptions with documented rationale accountable approval compensating controls expiration dates and scheduled reassessment.
Understand the end-to-end service path from cloud control plane and APIs through messaging device-management protocols and access networks to broadband gateways routers ONTs and connected-home devices.
Assess vulnerabilities in the context of multi-tenant cloud services remote device management certificates and secrets provisioning telemetry firmware delivery administrative interfaces and fleet-scale exposure.
Work with Engineering to identify affected device models hardware revisions firmware branches software components and deployed cohorts; support safe remediation planning and rollout validation.
Recognize the different evidence and remediation paths for cloud software third-party dependencies network appliances embedded Linux and customer-deployed CPE.
Build integrations and automation for asset enrichment deduplication risk scoring ticket creation ownership routing SLA tracking notifications rescans exception expiry and evidence collection.
Maintain dashboards for coverage exploitable exposure aging remediation performance repeat findings exceptions asset ownership and risk trends by service customer product and device cohort.
Develop playbooks standards and procedures for routine vulnerability handling critical CVEs zero-day response scanner administration and tool outages.
Provide concise reporting to technical owners and leaders separating raw finding volume from material risk and clearly identifying decisions or overdue actions.
Support audits and customer security inquiries with traceable evidence while protecting sensitive vulnerability and customer information.
5 years of hands-on experience in vulnerability management vulnerability assessment security engineering product security cloud security or a closely related discipline.
Demonstrated ownership of enterprise scanning and vulnerability-management workflows including scanner configuration authenticated scanning coverage analysis finding validation false-positive handling remediation tracking and rescanning.
Strong CVE analysis skills and the ability to determine applicability and exploitability using versions configurations exposure reachability privileges controls and business context.
Experience with one or more enterprise vulnerability platforms and practical familiarity with complementary cloud container dependency application and open-source scanning tools.
Working knowledge of CVE/CWE NVD CVSS CISA KEV EPSS vendor advisories software bills of materials and risk-based prioritization.
Hands-on knowledge of Linux TCP/IP DNS TLS/PKI identity and access controls APIs cloud infrastructure containers and Kubernetes.
Ability to read code package manifests container images configurations logs and network evidence sufficiently to validate findings and guide remediation.
Scripting or programming ability in Python Go PowerShell Bash or a comparable language plus experience integrating security platforms with APIs ticketing and dashboards.
Strong written and verbal communication including the ability to explain technical risk uncertainty tradeoffs and required decisions to engineers and operational leaders.
Bachelors degree in cybersecurity computer science engineering or equivalent practical experience.
Security experience with service providers broadband operators telecom equipment/software vendors managed-network providers or large distributed device fleets.
Experience assessing embedded Linux firmware broadband gateways routers ONTs Wi-Fi/mesh systems or other CPE/IoT products.
Familiarity with TR-069/CWMP TR-369/USP TR-181 ACS/USP controllers device provisioning telemetry certificates and remote firmware lifecycle management.
Experience with Google Cloud Platform Kubernetes Terraform Helm CI/CD and cloud-native security posture or workload-protection platforms.
Experience with software composition analysis SBOM/VEX container/image scanning secret scanning SAST/DAST/API security testing and infrastructure-as-code scanning.
Experience with coordinated vulnerability disclosure penetration-test finding intake zero-day response or product security incident response.
Familiarity with NIST Cybersecurity Framework NIST SP 800-40 CIS Controls OWASP guidance PCI DSS SOC 2 or ISO 27001 control expectations.
Relevant certifications such as Security CySA GSEC GCIH GPEN CISSP CCSP or vendor-specific vulnerability-management credentials; practical expertise is valued more than certification alone.
Work primarily during normal business hours with escalation availability for critical actively exploited or zero-day vulnerabilities.
Handle sensitive vulnerability exploit and customer information with strict need-to-know access and evidence controls.
Coordinate intrusive scans validation tests and production-impacting work through approved change and maintenance processes.
Challenge scanner results and remediation claims constructively while maintaining clear evidence ownership and deadlines.
This position is fully remote within North America. Please note that we are unable to offer visa sponsorship for this role.
Annual salary range: $120000 - $175000
Join AXON Networks!
At AXON Networks we promote equal opportunities in all our recruitment processes ensuring non-discrimination on the basis of gender age origin disability or any other personal circumstances. We assess talent based on objective criteria and foster an inclusive and diverse working environment.
Required Experience:
IC