Security Specialist, Vulnerability Management
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
AXON Networks delivers a robust AI-driven, analytics-based orchestration platform and a wide portfolio of next-gen high-speed routers that leverage the newest Wi‑Fi technologies. Together, these technologies give ISPs the ability to manage and troubleshoot their networks in real time, and to deliver an outstanding customer experience.
AXON Networks is a trusted strategic partner for its customers, helping them evaluate their current technologies and business models, and creating and executing strategies that enable them to innovate faster, accelerate their digital transformations, and strengthen their relationships with consumers.
AXON Networks is headquartered in Irvine, CA USA with Asia HQ in Singapore and also operating in Denmark, Spain and Vietnam.
The Security Specialist, Vulnerability Management will establish and operate a risk-based vulnerability management capability across the company’s cloud platform, applications, Kubernetes and container environments, network infrastructure, software supply chain, and cloud‑managed customer‑premises equipment (CPE), including broadband gateways, routers, ONTs and connected‑home devices. This is a hands‑on security engineering role for someone who can distinguish a scanner finding from a vulnerability that is relevant and exploitable in the company’s actual environment.
The engineer will select and configure scanning approaches, validate findings, analyze CVEs, prioritize risk, coordinate remediation, verify closure and create the dashboards, evidence and operating standards needed for a repeatable program. The engineer will explain risk clearly to operational and engineering leaders and will not rely on severity scores alone.
Role mandate
- Establish authoritative visibility into vulnerabilities across cloud, application, container, Kubernetes, network, endpoint, dependency, firmware and CPE asset classes.
- Determine whether findings and CVEs apply to the versions, configurations, exposure paths and controls actually present in the environment.
- Prioritize remediation using technical severity, known exploitation, likelihood, reachability, asset criticality, customer impact and compensating controls.
- Create a durable operating model for intake, validation, assignment, service levels, exceptions, rescanning, closure and executive reporting.
- Partner with Engineering, DevOps, NOC, Support, Product and Compliance to reduce measurable exposure without disrupting reliable customer service.
What you will own
Scanning strategy and coverage
- Inventory the attack surface and define coverage for internet‑facing and internal assets, cloud services, hosts, network devices, containers, Kubernetes clusters, applications, APIs, source code, third‑party dependencies, images, infrastructure as code and supported CPE/firmware.
- Design, configure and maintain authenticated and unauthenticated scans, agent‑based assessments, cloud‑native configuration checks, container and dependency scans, external attack‑surface discovery and targeted validation tests.
- Establish safe scan windows, credentials, rate limits, exclusions and testing procedures so scans do not destabilize production, customer environments or large CPE fleets.
- Evaluate, select and administer appropriate capabilities from platforms such as Tenable, Nessus, Qualys, Rapid7, Wiz, Orca, Prisma Cloud, Snyk, Veracode, Checkmarx, Trivy, Grype, Nuclei or equivalent tools; integrate results rather than requiring one product to solve every use case.
- Measure coverage, scan health, credential success, stale assets and blind spots; continuously improve asset‑to‑owner mapping and data quality.
Finding validation and CVE analysis
- Review new and existing scan findings and determine whether each is a true positive, false positive, duplicate, accepted risk, mitigated condition or actionable vulnerability.
- Analyze CVE applicability using affected component and version, package provenance, CPE or firmware bill of materials, runtime reachability, configuration, network exposure, privileges, exploit prerequisites and existing controls.
- Reproduce or safely validate material findings when needed using vendor advisories, proof‑of‑concept analysis, logs, configuration evidence, package inspection and non‑production testing.
- Document defensible disposition evidence and prevent unsupported suppression of findings or indefinite exception status. <