Senior Vulnerability Management Engineer urgent Daily Rate remote contractor required to build and operate the vulnerability management program supporting Cyber Essentials Plus (CE+) certification and broader enterprise compliance objectives. This role is the technical owner of authenticated vulnerability scanning, SLA-driven remediation coordination, and the continuous evidence pipeline required to demonstrate ongoing control effectiveness to assessors and executive leadership.
This is a strategic, audit-facing role that combines deep technical execution with cross-functional partnership across Trust Compliance, Device Trust, Networking, and asset owners across Autodesk. The successful candidate will establish the foundation for a vulnerability management capability that scales beyond CE+ into Network, Data Center, and Cloud Infrastructure scope.
Responsibilities
- Own end-to-end vulnerability management for CE+ in-scope assets — endpoints, servers, and supporting infrastructure
- Configure and operate authenticated vulnerability scanning across Windows, macOS, Linux, and cloud workloads
- Define and enforce SLA logic aligned to CE+ v3.3 — Critical/High vulnerabilities (CVSS ≥7.0) remediated within 14 days
- Build and own the continuous evidence pipeline — scan coverage reporting, SLA compliance dashboards, vulnerability lifecycle audit trails, and quarterly attestation packs
- Own the exception register — document risk-accepted items with compensating controls, named risk owners, and remediation roadmaps
- Partner directly with CE+ assessors during certification and recertification cycles; serve as the technical voice defending control effectiveness
- Coordinate remediation across Device Engineering, Device Trust, Networking, and business asset owners
- Integrate vulnerability findings with ITSM workflows to ensure auto-ticketing, ownership assignment, and SLA tracking
- Contribute to broader enterprise vulnerability and patch management strategy as scope expands into Network, Data Center, and Cloud Infrastructure
- Support adjacent compliance frameworks by leveraging the VM evidence foundation
Minimum Qualifications
- 7+ years of experience in vulnerability management, security engineering, or related roles
- Hands-on experience operating enterprise vulnerability management platforms (Microsoft Defender Vulnerability Management, Qualys, Tenable, or Rapid7)
- Strong understanding of CVSS scoring, vulnerability prioritization, and remediation lifecycle management
- Experience producing audit evidence for compliance frameworks (CE+, SOC 2, ISO 27001, PCI, or equivalent)
- Demonstrated ability to partner with auditors, assessors, or regulators in a technical capacity
- Strong cross-functional collaboration skills — comfortable working with compliance, engineering, networking, and business stakeholders
- Familiarity with endpoint management platforms and identity platforms
- Experience scaling vulnerability management programs across endpoint, network, data center, and cloud scope
Preferred Qualifications
- Direct experience with Cyber Essentials Plus or comparable UK/EU certification schemes
- Experience with Microsoft Defender for Endpoint and Defender Vulnerability Management at scale
- Familiarity with patch management platforms
- Experience building security evidence dashboards using Power BI, Splunk, or equivalent
- Scripting and automation skills (PowerShell, Python, KQL)
- Industry certifications: GIAC GCIH, GCED, GPEN, CISSP, or equivalent
Call Lindsay O’Leary for further spec details. 00 353 86 8311808
#LI-LO1
