Loading jobs…
Loading jobs…
Nasuni
ABOUT THE ROLE
The Security Engineer II - Cloud & Vulnerability Management is a key contributor to Nasuni's Information Security program, focused on protecting our hybrid and multi-cloud infrastructure through strong asset visibility, vulnerability management, and endpoint security. This role has a clear owner in the asset and vulnerability space: you will manage and operate the tools and workflows that keep our cloud, on-premises, and endpoint environments understood, assessed, and hardened.
Responsibilities
when your expertise is relevant. Participation in an on-call rotation is required. Level and Scope This role is responsible for executing and continuously improving vulnerability management, asset visibility, and cloud security processes.
The Security Engineer II works independently within defined areas of ownership while partnering with senior security team members on broader security strategy and program evolution.
WHAT YOU WILL DO
Asset & Vulnerability Management Own day-to-day execution of Nasuni's vulnerability management processes and tooling across cloud infrastructure (Wiz), on-premises and network assets (Rapid7), while contributing to ongoing program improvements. Support the maintenance of a current, accurate asset inventory across cloud workloads, physical infrastructure, network devices, and employee endpoints. Manage the full vulnerability lifecycle, including identification, triage, prioritization, remediation coordination, and validation.
Partner with Engineering, SRE, and IT/Infrastructure teams to drive remediation activities. Produce clear, actionable vulnerability reporting for Engineering and IT/Infrastructure stakeholders and security leadership. Track remediation SLAs, identify patterns in recurring weaknesses, and recommend systemic improvements to reduce exposure.
Contribute to patch management coordination efforts and support secure configuration baseline reviews across key asset classes. Maintain visibility and inventory accuracy across cloud, endpoint, network, and infrastructure assets in partnership with IT/Infrastructure teams. Cloud and Infrastructure Security Monitor cloud security posture via Wiz across AWS, Azure, and GCP environments — identifying misconfigurations, high-risk exposures, and policy violations.
Support secure configuration of cloud workloads, network controls, IAM, and infrastructure components in collaboration with engineering and SRE teams. Identify and escalate configuration drift, excessive permissions, and security gaps in cloud infrastructure. Provide security input on infrastructure changes and support security reviews as needed.
Incident Response Support security incidents where infrastructure, asset, or vulnerability context is needed. Independently manage and investigate moderate-severity security incidents within your domain; conduct root cause analysis and contribute to post-incident reviews. Maintain and improve documentation and runbooks for asset, vulnerability, and endpoint-related incident response procedures.
Support additional incident response efforts as needed. Compliance and Documentation Support internal and external evidence collection and control documentation for within your areas of ownership. Maintain accurate records of scanning activity, remediation outcomes, and asset coverage for audit readiness.
Contribute to security awareness initiatives and help communicate security expectations around patch and configuration hygiene to engineering teams. Growth and Collaboration Share knowledge and support team development through collaboration and peer guidance.