Cloud Vulnerability Management Engineer

NTT DATA, Inc.
Atlanta, GA, United States
3 days ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$135,200.0 - $147,680.0
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) Artificial Intelligence Amazon Web Services Systems Engineering Microsoft Azure Bash Shell Big Data Cloud Computing Cloud Computing Security Cloud Engineering Code Review CompTIA Security+
+50 more
Cyber Security Continuous Integration Linux DevOps Github Apache Hadoop Identity and Access Management Java Virtual Machine (JVM) Python (Programming Language) Key Management Network Security Windows Servers Open Source Technology Open Web Application Security Windows PowerShell Reliability Engineering Software Engineering Software Vulnerability Management Enterprise Data Management Data Logging Data Processing Scripting Java Application Server Enterprise Software Applications Apache Spark Software Security Multi-Cloud Electronic Medical Records HybridCloud Cloudformation Gitlab-ci Kubernetes Information Technology Patch Management Apache Kafka Data Management CIS Benchmarks Terraform Prisma Cloud Platform Devsecops Software Library Qualys Amazon Elastic Mapreduce (EMR) Docker Security Orchestration, Automation & Response Jenkins Static Application Security Testing Databricks Vulnerability Analysis Dynamic Application Security Testing

Job description

  • Manage the end-to-end vulnerability management lifecycle for enterprise applications and infrastructure hosted across hybrid cloud, Microsoft Azure, and AWS environments.
  • Analyze vulnerability scan results and identify security vulnerabilities affecting cloud infrastructure, operating systems, containers, application dependencies, open-source libraries, and cloud-hosted data platforms.
  • Perform vulnerability assessment and prioritization based on CVE/CVSS severity, exploitability, application criticality, external exposure, and overall business risk.
  • Work closely with Application Development, Cloud Engineering, DevOps, SRE, Infrastructure, and Cybersecurity teams to define and execute vulnerability remediation plans.
  • Support identification and remediation of vulnerabilities across AWS and Azure cloud services, Linux/Windows servers, Kubernetes, containers, Docker images, Java applications, and open-source components.
  • Support vulnerability management for Apache Spark-based applications and data-processing platforms, including Spark runtime versions, Java/JVM dependencies, libraries, packages, and associated cloud infrastructure.
  • Work with engineering teams to troubleshoot the technical root cause of vulnerabilities and recommend appropriate remediation, including patching, dependency upgrades, configuration changes, infrastructure changes, or compensating controls.
  • Validate successful remediation through rescanning, technical verification, and security evidence collection.
  • Track Critical and High vulnerabilities against established remediation SLAs and proactively escalate overdue vulnerabilities, blockers, and risks.
  • Identify recurring vulnerability patterns and recommend systemic solutions and preventive controls to reduce repeat findings.
  • Integrate vulnerability and security scanning into CI/CD and DevSecOps pipelines, enabling earlier identification of vulnerabilities during the software development lifecycle.
  • Support cloud security posture assessments and remediation of configuration weaknesses across Azure, AWS, and hybrid-cloud environments.
  • Develop scripts and automation to improve vulnerability identification, remediation tracking, validation, reporting, and compliance evidence collection.
  • Create dashboards and reports covering open vulnerabilities, remediation aging, SLA compliance, risk acceptance, remediation trends, and vulnerability reduction.
  • Participate in vulnerability governance and operational review meetings and communicate technical risks, remediation status, dependencies, and blockers to engineering and management stakeholders.

Requirements

  • Minimum 7+ years of experience in IT engineering, Cloud Engineering, DevOps/SRE, Cybersecurity, Application Security, or Vulnerability Management within enterprise environments.
  • Minimum 4+ years of hands-on experience in Vulnerability Management / Application Security / Cloud Security, including vulnerability analysis, prioritization, remediation, and validation.
  • Minimum 4+ years of experience working with public cloud technologies, with strong hands-on knowledge of AWS and/or Microsoft Azure.
  • Minimum 2+ years of experience supporting hybrid-cloud or multi-cloud environments, preferably involving application migration or transformation between Azure and AWS.
  • Minimum 3+ years of experience using enterprise vulnerability/security platforms such as Qualys, Tenable, Rapid7, Wiz, Prisma Cloud, Microsoft Defender for Cloud, AWS Inspector, or comparable tools.
  • Minimum 3+ years of experience analyzing and remediating CVE/CVSS-based vulnerabilities, including operating-system vulnerabilities, application dependencies, open-source libraries, containers, and cloud infrastructure.
  • Minimum 2+ years of experience supporting security or vulnerability management for Apache Spark, Databricks, EMR, Hadoop, or similar large-scale data-processing platforms.
  • Minimum 2+ years of experience working with Java/JVM applications and open-source dependency vulnerability remediation, including upgrading vulnerable libraries and packages.
  • Minimum 2+ years of experience working with containers and container orchestration technologies such as Docker and Kubernetes, including container/image vulnerability management.
  • Minimum 2+ years of experience with CI/CD and DevSecOps technologies such as GitLab CI, GitHub Actions, Jenkins, Azure DevOps, or comparable platforms.
  • Minimum 2+ years of experience integrating or working with security controls such as SAST, DAST, Software Composition Analysis (SCA), container scanning, secrets scanning, and Infrastructure-as-Code scanning.
  • Minimum 2+ years of experience with scripting or automation using Python, Bash, PowerShell, or equivalent technologies.
  • Strong understanding of AWS and Azure security concepts, including IAM/access controls, cloud configuration, network security, logging/monitoring, and cloud security posture management.
  • Strong knowledge of vulnerability-management concepts including CVE, CVSS, risk-based prioritization, patch management, vulnerability SLAs, remediation validation, security exceptions, and risk acceptance.
  • Strong analytical, troubleshooting, and communication skills with the ability to translate security findings into actionable technical remediation for engineering teams.

Travel:

  • This position may require occasional travel based on client and project requirements.
  • Degree:
  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or equivalent work experience.

Nice to Have:

  • Experience working in Banking, Financial Services, or other highly regulated enterprise environments.
  • Experience securing enterprise data platforms utilizing Apache Spark, Databricks, AWS EMR, Kafka, Hadoop, or related technologies.
  • Experience with cloud security services including AWS Security Hub, Inspector, GuardDuty, CloudTrail, Config, Microsoft Defender for Cloud, Azure Policy, and Entra ID.
  • Experience with Infrastructure as Code technologies such as Terraform and AWS CloudFormation.
  • Knowledge of security standards and frameworks including NIST, CIS Benchmarks, OWASP, and cloud security best practices.
  • Experience implementing automated vulnerability-remediation and security-validation workflows.
  • Experience applying AI/LLM-based capabilities to vulnerability analysis, remediation recommendations, or security automation.
  • Familiarity with SRE, observability, production support, and incident-management practices.
  • Relevant certifications such as AWS Certified Security Specialty, Microsoft Azure Security Engineer, CISSP, CCSP, Security+, or equivalent cloud/security certifications.

Benefits & conditions

Where required by law, NTT DATA provides a reasonable range of compensation for specific roles. The starting hourly range for this remote role is ($65-$71/hour). This range reflects the minimum and maximum target compensation for the position across all US locations. Actual compensation will depend on several factors, including the candidate’s actual work location, relevant experience, technical skills, and other qualifications. This position may also be eligible for incentive compensation based on individual and/or company performance.

This position is eligible for company benefits that will depend on the nature of the role offered. Company benefits may include medical, dental, and vision insurance, flexible spending or health savings account, life, and AD&D insurance, short-and long-term disability coverage, paid time off, employee assistance, participation in a 401k program with company match, and additional voluntary or legally required benefits .

About NTT DATA

About the company

NTT DATA is a $30 billion trusted global innovator of business and technology services. We serve 75% of the Fortune Global 100 and are committed to helping clients innovate, optimize and transform for long term success. As a Global Top Employer, we have diverse experts in more than 50 countries and a robust partner ecosystem of established and start-up companies. Our services include business and technology consulting, data and artificial intelligence, industry solutions, as well as the development, implementation and management of applications, infrastructure and connectivity. We are one of the leading providers of digital and AI infrastructure in the world. NTT DATA is a part of NTT Group, which invests over $3.6 billion each year in R&D to help organizations and society move confidently and sustainably into the digital future. Visit us at us.nttdata.com

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

3:46 min

Navigating a career in cloud transformation consulting

Piet Van Dongen · LIVE

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · World Congress 2026 Europe

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all