CareerRiver

Vulnerability Operations Engineer

Fred Hutchinson Cancer Center · Seattle, WA

📍 Seattle, WAvia icimsPosted 2026-06-30
Apply on company site ↗
CareerRiver pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Fred Hutchinson Cancer Center.
Overview Fred Hutchinson Cancer Center is an independent, nonprofit organization providing adult cancer treatment and groundbreaking research focused on cancer and infectious diseases. Based in Seattle, Fred Hutch is the only National Cancer Institute-designated cancer center in Washington. With a track record of global leadership in bone marrow transplantation, HIV/AIDS prevention, immunotherapy and COVID-19 vaccines, Fred Hutch has earned a reputation as one of the world’s leading cancer, infectious disease and biomedical research centers. Fred Hutch operates eight clinical care sites that provide medical oncology, infusion, radiation, proton therapy and related services, and network affiliations with hospitals in five states. Together, our fully integrated research and clinical care teams seek to discover new cures to the world’s deadliest diseases and make life beyond cancer a reality. At Fred Hutch we value collaboration, compassion, determination, excellence, innovation, integrity and respect. Our mission is directly tied to the humanity, dignity and inherent value of each employee, patient, community member and supporter. Our commitment to learning across our differences and similarities make us stronger. We seek employees who bring different and innovative ways of seeing the world and solving problems. As a senior member of the Information Security Operations team, you will anchor the organization’s Vulnerability Operations (VulnOps) practice, serving as a subject matter expert who owns the discover, prioritize, remediate, and validate loop end to end. You will drive risk-based exposure management, mentor junior team members, and shape how Fred Hutch identifies, assesses, and orchestrates the remediation of vulnerabilities across a complex hybrid estate. We are looking for a Vulnerability Operations Engineer to mature our exposure management program beyond scan-and-patch toward exploitability-in-context prioritization. Reporting to the Director of Information Security Engineering & Operations, you will scope and run scanning across cloud and on-premises assets, validate and triage findings, separate noise from materially risky exposure, and translate results into clear, owner-assigned remediation that actually gets fixed. You will partner closely with Fred Hutch architecture, development, systems engineering, and network engineering teams to embed vulnerability checks into their workflows, build automation that scales the program, and raise our level of compliance with information security standards. If this sounds like you, come help Fred Hutch in the fight against cancer and infectious disease by reducing the attack surface that protects our research and our patients! This role will have the opportunity to work partially at our campus and remotely. Evening and/or weekend work may occasionally be required. Responsibilities Own the vulnerability management lifecycle end to end—asset scoping, scanning, validation, triage, and remediation tracking—across cloud, on-premises, and hybrid environments. Lead risk-based, exploitability-in-context prioritization that separates noise from materially risky exposure, combining CVSS with EPSS, CISA KEV, and vendor advisories along with asset and reachability context, rather than ranking by raw score alone. Interpret scan results at scale: filter false positives, correlate findings with exploitability and active threat intelligence, and translate them into clear, prioritized tickets with named owners and actionable remediation guidance. Build, tune, and maintain the exposure management toolchain—evaluating and integrating vulnerability scanners, attack-surface and asset-graph tooling, and exposure management platforms for operational fit. Design and run remediation orchestration: set patch SLAs by risk tier, drive remediation campaigns (for example, end-of-life asset cleanup and TLS/certificate uplift), and keep multiple remediation streams moving across the teams that own the fix. Develop and maintain automation and scripting (Python, PowerShell, Bash) to de-duplicate findings, enrich them with CMDB and asset data, and push outputs into ticketing and notification systems instead of working from static reports. Integrate vulnerability operations into operational workflows through APIs for scanners, CMDB, and ITSM platforms, and partner with DevOps and engineering teams to embed vulnerability and infrastructure-as-code checks into CI/CD pipelines. Maintain a runtime-validated, identity-aware view of the asset estate, working toward reachability analysis that can answer which assets an identity can reach and which identities can reach a given asset. Operationalize software supply chain visibility—keeping SBOMs queryable and current so exposure to a newly disclosed component vulnerability can be answered in minutes rather than days. Define and maintain repeatable exception, risk-acceptance, and revalidation processes, ensuring accepted risk is documented, time-bound, and periodically re-reviewed. Build and report program metrics that turn raw findings into managed exposure—mean time to remediate, percentage of criticals closed within SLA, exploitability-weighted backlog, and exposure by business unit—including executive- and board-ready summaries that emphasize trend over point-in-time numbers. Apply AI-assisted tooling where it adds leverage—for example, to accelerate triage, enrichment, exploit reasoning, and code or configuration review—while maintaining human validation and sound judgment over automated findings. Serve as the subject matter expert for the vulnerability operations domain, providing technical guidance and mentorship to Level I and Level II engineers. Align vulnerability operations with threat intelligence and active incidents, prioritizing exposures under active exploitation and supporting incident response when a vulnerability is implicated. Contribute to compliance audits and

More Seattle, WA jobs

Seattle, WA jobs · Browse all locations