> Markdown version of [/jobs/ext/524719-it-risk-mitigation-engineer-ii-remote](https://www.wearedevelopers.com/jobs/ext/524719-it-risk-mitigation-engineer-ii-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Risk Mitigation Engineer II - REMOTE - **Company:** PSCU, LLC - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $75,800.0 - $96,700.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Software System Penetration Testing, Cloud Computing, CompTIA Security+, Cyber Security, Python (Programming Language), Linux Servers, Open Web Application Security, PCI Data Security Standards, Windows PowerShell, Security Information and Event Management, Software Engineering, Software Vulnerability Management, YAML, Scripting, IT General Controls (ITGC), Information Technology, Nessus, Data Management, CIS Benchmarks, Qualys, Servicenow, Vulnerability Analysis - **Published:** June 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=a9c032909cf83207 ## About the Role Do you have experience in Research?, Do you have a Associate's degree?, * Associates degree or competency-based degree in a related IT discipline preferred * Relevant industry certifications such as A+, Network+, Security+, CISSP, CISM, or equivalent are a plus * Experience with Tanium is a plus * 2+ years of experience in vulnerability management / compliance monitoring or the equivalent as derived from participating in a role that directly included those responsibilities * Knowledge of and/or experience with technical concepts such those associated within Windows and/or Linux server operating systems, cloud computing, automation, networking, and application development * Experience reviewing vulnerability scans, penetration tests, network admission control, and/or SIEM systems such as Nessus, Rapid7, Qualys, etc. * Experience with IT controls monitoring for regulatory and compliance requirements * Knowledge of vulnerability data management and reporting process automation * Knowledge of OWASP tools and methodologies a plus * Knowledge of scripting languages (i.e., Powershell, Python, YAML, etc.) a plus * Experience with ServiceNow a plus * Functional knowledge of information security best practices * Functional knowledge of ITIL principles and practices ## Description As a Risk Mitigation Engineer II, the incumbent will be responsible for assisting in the core, day-to-day functions of the Risk Mitigation (RM) team. In this role the incumbent acts as a technical support specialist within the larger RM team. This role will promote directives within the team to support IT infrastructure and application teams across the organization to ensure a risk-based approach to vulnerability management is embedded into their daily work. The RM Engineer II will focus the majority of their time on hands-on solutions and tools, such as those that are typically used for monitoring, assessment, tracking, and reporting. The ideal candidate will have excellent technical, organizational, and communication (written and verbal) skills, along with a willingness to assist where needed with overall team tasks. A sense of ownership, and a want and willingness to learn, assume new responsibilities, and an overall initiative-based drive are keys to success in this position and successive/advanced roles within the team. Day in the Life: * Assume a critical, supportive, technical role within the RM team. Assist both technical and team initiatives to shape and guide the focus and execution of remediation solutions that provide effective, accurate, comprehensive, and actionable reporting, best practices configurations, timely patching, etc., toward a goal of overall reductions in vulnerabilities across all department accountable technologies. * Under guidance, collaborate with Security and IT Infrastructure to maintain or implement risk-based, actionable remediation requirements for all supported, auditable technologies. * Utilize a breadth of technical background to identify and research the vulnerabilities, then partner with the proper technology team to remediate the findings. * Assist with or directly maintain and support vulnerability management programs that include reviewing regular scans and assessments of the organization's systems, network and applications to identify security vulnerabilities. * Resolve or assist with the resolution of information security vulnerability findings, including zero-day or targeted threats, and/or internal or external weaknesses in IT platforms, appliances, systems, services, applications or configurations. * Work with multiple teams to align scanning, reporting and tracking in compliance with industry best-practices, regulations, and standards related to vulnerability management, such as PCI-DSS, SOC II, NIST, CIS benchmarks, or other compliance regulations required by either industry mandates or Velera standards. * Improve reporting maturity through automation, consolidation, and other techniques as necessary. * Perform or assist with recurring and on-demand scanning of organization systems and cloud environments. * Maintain detailed documentation regarding Velera's threat management standards, policies, and procedures * Improve and automate, wherever possible, existing vulnerability management systems ## Related Videos - [CI/CD with Github Actions](https://www.wearedevelopers.com/videos/856-ci-cd-with-github-actions) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Startup Presentation: Achieving True Developer Self-Service in Kubernetes](https://www.wearedevelopers.com/videos/1181-startup-presentation-achieving-true-developer-self-service-in-kubernetes) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Job Boards for Remote Work for Developers](https://www.wearedevelopers.com/magazine/290-best-job-boards-for-remote-work-for-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)