Senior Cybersecurity Engineer

AeroVironment

Apply for this job

Job Description

Worker Type
Regular
Job Description

Summary
The Cybersecurity Engineer is responsible for supporting the organization's Vulnerability Management and Endpoint Security programs, with a primary focus on the administration, engineering, and optimization of Tanium.
This position combines hands-on security engineering with vulnerability identification, prioritization, remediation, patch management, asset visibility, endpoint compliance, and security automation. The engineer will work closely with Cybersecurity Operations, IT Infrastructure, application owners, and business stakeholders to identify security exposures and drive vulnerabilities through remediation.
The ideal candidate possesses strong technical troubleshooting skills, understands enterprise endpoint environments, and can translate vulnerability and asset data into actionable remediation activities.
Position Responsibilities
Vulnerability Management
Support the enterprise Vulnerability Management program across workstations, servers, cloud workloads, and other supported infrastructure.
Identify, analyze, validate, prioritize, and track vulnerabilities across the enterprise.
Use vulnerability intelligence, asset criticality, exploitability, business impact, and threat intelligence to prioritize remediation activities.
Perform risk-based vulnerability prioritization rather than relying solely on CVSS scores.
Monitor newly disclosed vulnerabilities, zero-day threats, CISA Known Exploited Vulnerabilities (KEV), and vendor security advisories.
Coordinate with IT, infrastructure, application, cloud, and system owners to remediate identified vulnerabilities.
Validate remediation and ensure vulnerabilities are successfully closed.
Identify recurring vulnerabilities and systemic remediation issues.
Develop vulnerability dashboards, metrics, KPIs, and executive reporting.
Support vulnerability remediation SLAs and exception/risk-acceptance processes.
Assist with vulnerability management requirements associated with NIST, CMMC, CIS, and other applicable security frameworks.
Tanium Administration & Engineering
Serve as a technical administrator and subject matter resource for the Tanium platform.
Configure, maintain, troubleshoot, and optimize Tanium modules and services.
Develop and maintain Tanium sensors, questions, packages, actions, computer groups, dashboards, and reporting.
Use Tanium to identify hardware, software, operating systems, configurations, applications, and security posture across enterprise endpoints.
Develop dynamic computer groups to support security operations and targeted remediation.
Monitor Tanium client health, platform coverage, communication status, and endpoint participation.
Identify and remediate unhealthy, missing, stale, or non-communicating Tanium clients.
Support deployment, upgrade, and maintenance of the Tanium Client.
Troubleshoot Tanium Client, server, module, sensor, package, and action issues.
Maintain Tanium role-based access controls and administrative permissions.
Assist with platform upgrades, configuration changes, testing, and lifecycle management.
Tanium Comply & Vulnerability Assessment
Administer and optimize Tanium Comply for vulnerability and configuration assessment.
Configure vulnerability assessments and compliance scans across supported endpoint populations.
Analyze vulnerability findings and identify affected systems.
Support configuration assessments against applicable CIS Benchmarks, DISA STIGs, and organizational security standards.
Develop dashboards and reports showing vulnerability exposure and remediation progress.
Correlate Tanium vulnerability information with other vulnerability and security platforms.
Investigate discrepancies between Tanium and other vulnerability scanners or asset-management systems.
Use Tanium data to validate remediation activities and identify residual exposure.
Patch & Remediation Management
Support enterprise patch and vulnerability remediation activities using Tanium Patch and Deploy or integrated endpoint-management technologies.
Analyze missing patches and identify endpoints requiring remediation.
Develop and maintain patch deployment groups and maintenance windows.
Coordinate security patching with IT and system owners.
Support emergency remediation activities for critical and actively exploited vulnerabilities.
Test and validate security patches prior to broad deployment when appropriate.
Track patch deployment status, failures, exceptions, and remediation progress.
Troubleshoot failed patch installations and deployment issues.
Support automated remediation of vulnerabilities where technically and operationally appropriate.
Asset Visibility & Endpoint Hygiene
Use Tanium to maintain accurate visibility into enterprise endpoint assets.
Identify unmanaged, unknown, stale, duplicate, or non-compliant devices.
Assist with reconciliation of Tanium data against CMDB, endpoint management, EDR, vulnerability management, and other asset sources.
Identify systems missing required security agents or controls.
Support security control coverage reporting for EDR, vulnerability scanning, patching, encryption, endpoint management, and other technologies.
Develop queries and dashboards that identify gaps in endpoint security coverage.
Assist with improving overall asset inventory accuracy and endpoint hygiene.
Security Engineering & Automation
Develop scripts and automation to improve vulnerability management and endpoint security processes.
Use PowerShell, Python, APIs, or similar technologies to automate repetitive security tasks.
Integrate Tanium with SIEM/XDR, vulnerability management, ITSM, CMDB, and other enterprise security platforms.
Support automated ticket generation and remediation workflows for vulnerability findings.
Develop queries, dashboards, and reporting that provide actionable security information.
Identify opportunities to reduce manual remediation activities through automation.
Document technical configurations, procedures, standards, and operational processes.
Security Operations Support
Support Cybersecurity Operations during vulnerability-related incidents and emerging threats.
Rapidly identify systems affected by critical vulnerabilities or compromised software.
Use Tanium to query enterprise endpoints during incident investigations.
Support emergency containment or remediation actions when required.
Work with threat intelligence and SOC teams to determine organizational exposure to emerging threats.
Assist with identifying indicators, vulnerable software, configurations, or endpoint conditions associated with active threats.
Basic Qualifications (Required Skills & Experience)
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or a related field, or equivalent professional experience.
3+ years of cybersecurity, endpoint engineering, vulnerability management, systems administration, or related technical experience.
Hands-on experience administering or supporting Tanium in an enterprise environment.
Experience with vulnerability management and remediation processes.
Working knowledge of Windows enterprise environments.
Understanding of vulnerability scoring, CVSS, exploitability, and risk-based vulnerability prioritization.
Experience with enterprise patch-management processes.
Understanding of endpoint security technologies and architecture.
Strong troubleshooting and root-cause analysis skills.
Ability to analyze large amounts of endpoint and vulnerability data.
Ability to communicate technical risks and remediation requirements to technical and non-technical stakeholders.
Strong documentation and organizational skills.
Other Qualifications & Desired Competencies
Experience with several of the following is highly desirable:
Tanium
Microsoft Defender Vulnerability Management
Microsoft Defender for Endpoint
Microsoft Intune
Linux
PowerShell
Python
REST APIs
SQL / data analytics
SIEM/XDR platforms
Experience supporting large, distributed enterprise environments is preferred.
Experience supporting aerospace, defense, manufacturing, government, or other regulated environments is also desirable.
Compliance Frameworks & Knowledge
CMMC
NIST SP 800-171
NIST Cybersecurity Framework
NIST SP 800-53
CIS Controls
CIS Benchmarks
DISA STIGs
Risk Management Framework (RMF)
Certifications
Relevant certifications are preferred but not required and may include:
Tanium Certified Operator
Tanium Certified Administrator
CompTIA Security+
CompTIA CySA+
GIAC certifications
Microsoft security certifications
Other relevant cybersecurity or endpoint-management certifications
Key Competencies
Tanium Administration
Vulnerability Management
Risk-Based Vulnerability Prioritization
Patch Management
Endpoint Security
Asset Visibility
Security Configuration Management
Vulnerability Remediation
Security Automation
PowerShell / Scripting
Technical Troubleshooting
Security Metrics & Reporting
Cross-Functional Collaboration
What Success Looks Like
The successful Cybersecurity Engineer provides the organization with accurate visibility into its endpoint attack surface and drives measurable reduction of vulnerability risk.
This individual does more than identify vulnerabilities. The engineer determines which vulnerabilities matter most, identifies the systems affected, coordinates remediation, validates successful resolution, and uses Tanium and automation to improve the speed and scalability of the vulnerability management lifecycle.
The role serves as a technical bridge between Cybersecurity Operations, Vulnerability Management, Endpoint Engineering, and IT Operations, helping transform vulnerability data into measurable risk reduction.
Physical Demands
Ability to work in an office environment (Constant)
Required to sit and stand for long periods; talk, hear, and use hands and fingers to operate a computer and telephone keyboard (Frequent)
Clearance Level

No Clearance
The salary range for this role is:
$91,000 - $138,750
AeroVironment
considers several fact

Newest government jobs in New Mexico