> Markdown version of [/jobs/ext/2021378-cybersecurity-specialist](https://www.wearedevelopers.com/jobs/ext/2021378-cybersecurity-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Specialist - **Company:** Caterpillar - **Location:** Irving, TX, United States - **Salary:** $128,470.0 - $208,770.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing, Configuration Management Databases, Cyber Security, System Configuration, Linux, DevOps, Python (Programming Language), Machine Learning, Routing, Windows PowerShell, Systems Integration, Transmission Control Protocol (TCP), Software Vulnerability Management, Web Applications, Scripting, Microsoft Power Automate, System Availability, Patch Management, Qualys, Servicenow, Vulnerability Analysis - **Published:** August 11, 2026 - **Apply:** https://www.juju.com/job/00000000gmoxln ## About the Role + Vulnerability management and security operations expertise + Hands-on experience with Qualys or similar vulnerability management platforms + Vulnerability scanning, authenticated scans, Cloud Agents, and asset management + Knowledge of Windows, Linux, TCP/IP networking, AWS, and Azure + Experience analyzing vulnerability data, CVSS scores, and threat intelligence + Strong problem-solving, communication, and stakeholder management skills + Familiarity with AI, machine learning, and predictive risk modeling + Experience using Microsoft Copilot, Security Copilot, or similar AI tools for security operations and reporting + Ability to collaborate across security, infrastructure, and application teams Top Candidates Will Also Have: + Qualys Certifications (e.g., Qualys Vulnerability Management, Policy Compliance, Web Application Scanning, VMDR, CSAM, ETM, Cloud Agent, or EASM). + Experience with ITIL processes, ticketing platforms (ServiceNow, Remedy), and CI/CD pipelines as well as integrating Qualys with ServiceNow, CMDB, reporting, ticketing, cloud, or security platforms. + Experience with scripting for automation (Python, PowerShell). + Experience operating in large-scale, complex enterprise environments like Caterpillar. + Strong communication skills with ability to translate technical findings into actionable direction for non-technical teams. ## Description The Qualys Platform Lead owns the administration, operation, governance, and continuous improvement of Caterpillar's enterprise Qualys platform. This role provides technical leadership for vulnerability scanning, scanner appliances, Cloud Agents, platform configuration, asset data quality, reporting, integrations, and roadmap delivery across a global environment. The role serves as the primary Qualys subject matter expert and works closely with Cybersecurity, Infrastructure, Cloud, Application, ServiceNow, Governance and Compliance, and leadership teams to support effective vulnerability identification, prioritization, routing, and remediation coordination. What You Will Do: Platform Ownership & Administration + Manage platform configurations, scan profiles, scanner appliances, schedules, authentication records, asset tags, user access, and permissions, subscription usage, and operational health. + Ensure high availability, accuracy, and scalability of vulnerability scanning across enterprise-wide infrastructure and coordinate rescanning and validation activities as needed. + Maintain integrations between Qualys, ServiceNow, CMDB, cloud platforms, reporting systems, and approved security technologies. + Oversee host discovery, authenticated infrastructure scanning, scanner appliance operations, and Cloud Agent deployments. + Analyze vulnerability data to identify trends, coverage gaps, systemic issues, and areas requiring attention. + Support risk-based prioritization using Qualys Detection Scores, ETM and TruRisk capabilities, threat intelligence, exploitability, and asset context. Lead prioritization efforts using Caterpillar's risk criteria and Qualys capabilities (e.g., TruRisk, Threat Protection, Patch Management modules if applicable). + Leverage AI-assisted security analytics and risk-scoring capabilities to improve vulnerability prioritization and remediation decision-making. + Evaluate and validate AI-generated insights from Qualys TruRisk, threat intelligence platforms, and security analytics tools to reduce false positives and focus remediation efforts on exploitable risks. + Utilize predictive analytics to identify emerging vulnerability trends, attack paths, and areas of heightened exposure. + Evaluate AI use cases and emerging technologies to improve operational efficiency, asset discovery, threat exposure analysis, and remediation effectiveness. Governance, Reporting & Metrics + Work closely with Governance and Compliance teams to support audits, controls, and regulatory requirements. + Create, update, and maintain operational documentation, standards, and processes for vulnerability lifecycle management. + Assess and mitigate risks associated with AI-generated recommendations and automated remediation activities. Cross-Functional Collaboration + Partner with Infrastructure, Cloud, Application, and DevOps teams to drive remediation plans and support secure system configurations. + Serve as a trusted advisor to IT partners, educating them on vulnerability risks, remediation techniques, and Qualys usage best practices. + Provide escalation support and root cause analysis for scan failures, agent issues, or false positives. Continuous Improvement + Evaluate and implement new Qualys modules, features, or scanning techniques aligned with Caterpillar's security roadmap. ETM/TruRisk, CSAM (Asset Management), QPM (Patch Management) and QPA (Policy Control/Audit, EASM (Attack Surface Management). + Drive automation opportunities for asset onboarding, reporting, ticketing, and scanning workflows. + Identify process gaps and propose enhancements to strengthen vulnerability management maturity across the organization. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)