> Markdown version of [/jobs/ext/2915713-senior-information-security-specialist-vulnerability-management](https://www.wearedevelopers.com/jobs/ext/2915713-senior-information-security-specialist-vulnerability-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Security Specialist - Vulnerability Management - **Company:** Amway - **Location:** Forest Hills, MI, United States - **Experience:** Expert - **Salary:** $118,248.0 - $130,696.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), JavaScript (Programming Language), .NET Framework, Application Programming Interfaces (APIs), Agile Methodology, Artificial Intelligence, Software System Penetration Testing, Build Automation, Cloud Computing, Cloud Engineering, Cyber Security, Computer Engineering, Continuous Integration, Multi-protocol Systems, Python (Programming Language), Open Web Application Security, Red Team (Cyber Security), Secure Coding, Security Software, Software Engineering, SonarQube, TypeScript, Software Vulnerability Management, Software Security, Veracode, Infrastructure Automation Frameworks, Information Technology, Checkmarx, Prisma Cloud Platform, Devsecops, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 15, 2026 - **Apply:** https://www.careerjet.com/job/us2d758d2d843774f71c2ca8f6be110cd0/eaa ## About the Role * BA/BS Degree in Computer Science, Computer Science Engineering, Information Security, or related field * Good working knowledge of large and mid-range operating systems and related security software in a large, complex, multi-server, multi-protocol environment. * Strong knowledge of application security concepts including OWASP Top 10, SAST, DAST, SCA, secret scanning, API Security, secure code review practices, and Secure Software Development Lifecycle (SSDLC). * Attention to detail * Good customer service orientation * Good written and oral communication and interpersonal skills Skills to be successful in the role: * Strong understanding of vulnerability management, risk assessment, remediation lifecycle management, and vulnerability prioritization frameworks. * Experience coordinating vulnerability assessments, penetration testing, red team exercises, and security reviews across application, infrastructure, cloud, API, endpoint, and container environments. * Working knowledge of Java, .NET, Python, JavaScript/TypeScript, cloud-native architectures, DevSecOps, CI/CD pipelines, source code repositories, build automation, containers, Infrastructure-as-Code (IaC), and deployment platforms. * Knowledge of infrastructure, cloud, network, endpoint, and container security principles. * Experience administering, automating, and optimizing vulnerability management and application security tools, including Tenable, Invicti, GHAS, Prisma Cloud, SonarQube, Veracode, Checkmarx, or equivalent platforms. * Strong analytical, problem-solving, stakeholder management, communication, and collaboration skills, with experience validating findings, assessing risk, driving remediation against SLAs, influencing cross-functional teams, and recommending effective mitigation strategies. * Experience preparing security metrics, dashboards, executive reporting, and risk summaries; supporting audit, regulatory, compliance, and cyber insurance requirements; and evaluating emerging security technologies. * Knowledge of AI-assisted security assessment capabilities, AI security risks, governance, and secure AI lifecycle practices, including the use of automation and AI to improve security operations and mitigate risks associated with internal and third-party AI solutions. * Familiarity with Agile methodologies and continuous improvement practices. ## Description We use cookies to offer you the best possible website experience. Your cookie preferences will be stored in your browser's local storage. This includes cookies necessary for the website's operation. Additionally, you can freely decide and change any time whether you accept cookies or choose to opt out of cookies to improve website's performance, as well as cookies used to display content tailored to your interests. Your experience of the site and the services we are able to offer may be impacted if you do not accept all cookies. Modify Cookie Preferences Reject All Cookies Accept All Cookies Search Jobs, The role serves as the primary liaison between Global stakeholders and the Vulnerability Management team. Managing security assessments, penetration testing, remediation tracking, reporting, and security governance activities to reduce cyber risk and strengthen the organization's security posture. Providing vulnerability assessments to the Amway businesses globally through a comprehensive testing process. Someone that is comfortable in identifying, assessing, prioritizing, and driving the remediation of security vulnerabilities. Looking for a candidate that is team player, collaborative, analytical, persistent and comfortable challenging the status quo. What You'll Do: As a senior-level contributor, the individual is expected to evaluate emerging security technologies, mentor others, influence stakeholders, and champion continuous improvement initiatives. Stay informed on evolving threats and leverage AI-assisted security capabilities, automation, and advanced analytics to improve vulnerability management, penetration testing, and security operations outcomes. Additionally, they help assess and govern risks associated with internally developed and externally sourced solutions, ensuring secure adoption and alignment with enterprise security standards. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Automated Code Quality Checks with Custom SonarQube Rules](https://www.wearedevelopers.com/videos/428-automated-code-quality-checks-with-custom-sonarqube-rules) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)