Remote Security Specialist, Vulnerability Management

11 hours ago

Victoria, British Columbia, Canada Axon-networks Full-time

 



AXON Networks delivers a robust AI-driven, analytics-based orchestration platform and a wide portfolio of next-gen high-speed routers that leverage the newest Wi-Fi technologies. Together, these technologies give ISPs the ability to manage and troubleshoot their networks in real time, and to deliver an outstanding customer experience.


AXON Networks is a trusted strategic partner for its customers, helping them evaluate their current technologies and business models, and creating and executing strategies that enable them to innovate faster, accelerate their digital transformations, and strengthen their relationships with consumers.


AXON Networks is headquartered in Irvine, CA USA with Asia HQ in Singapore and also operating in Denmark, Spain and Vietnam.




The Security Specialist, Vulnerability Management will establish and operate a risk-based vulnerability management capability across the company’s cloud platform, applications, Kubernetes and container environments, network infrastructure, software supply chain, and cloud-managed customer-premises equipment (CPE), including broadband gateways, routers, ONTs and connected-home devices. This is a hands-on security engineering role for someone who can distinguish a scanner finding from a vulnerability that is relevant and exploitable in the company’s actual environment. 




The engineer will select and configure scanning approaches, validate findings, analyze CVEs, prioritize risk, coordinate remediation, verify closure and create the dashboards, evidence and operating standards needed for a repeatable program. The engineer will explain risk clearly to operational and engineering leaders and will not rely on severity scores alone. 




Role mandate 






  • Establish authoritative visibility into vulnerabilities across cloud, application, container, Kubernetes, network, endpoint, dependency, firmware and CPE asset classes. 








  • Determine whether findings and CVEs apply to the versions, configurations, exposure paths and controls actually present in the environment. 








  • Prioritize remediation using technical severity, known exploitation, likelihood, reachability, asset criticality, customer impact and compensating controls. 








  • Create a durable operating model for intake, validation, assignment, service levels, exceptions, rescanning, closure and executive reporting. 








  • Partner with Engineering, DevOps, NOC, Support, Product and Compliance to reduce measurable exposure without disrupting reliable customer service. 






What you will own 




Scanning strategy and coverage 






  • Inventory the attack surface and define coverage for internet-facing and internal assets, cloud services, hosts, network devices, containers, Kubernetes clusters, applications, APIs, source code, third-party dependencies, images, infrastructure as code and supported CPE/firmware. 








  • Design, configure and maintain authenticated and unauthenticated scans, agent-based assessments, cloud-native configuration checks, container and dependency scans, external attack-surface discovery and targeted validation tests. 








  • Establish safe scan windows, credentials, rate limits, exclusions and testing procedures so scans do not destabilize production, customer environments or large CPE fleets. 








  • Evaluate, select and administer appropriate capabilities from platforms such as Tenable Ne