Full-Time

Senior Conmon Engineer

Confirmed live in the last 24 hours

Coalfire

Coalfire

501-1,000 employees

Cybersecurity advisory and managed services provider

Compensation Overview

$86k - $148k/yr

Senior

Denver, CO, USA

Candidates must be based in the United States.

Category
Cybersecurity
IT & Security
Required Skills
Prisma
PowerShell
Microsoft Azure
Python
AWS
Google Cloud Platform
Requirements
  • 5–7 years of professional experience in vulnerability management, compliance monitoring, or related security operations roles
  • Extensive background in managing vulnerabilities across operating systems, databases, networks, containers, web applications, and APIs
  • Experience supporting vulnerability management in at least two of the following cloud providers: AWS, Azure, GCP, with a proven track record of integrating tools into cloud workflows
  • Involvement with at least one compliance framework (for example, FedRAMP, HITRUST, PCI), contributing to security assessments and risk-based reporting
  • Demonstrated success producing periodic vulnerability status reports, ensuring timely remediation efforts and accountability across multiple stakeholders
  • Advanced administrative understanding of AWS, Azure, or GCP
  • Strong expertise in vulnerability scanning technologies and methods, including scoring systems (CVSS, CMSS)
  • Excellent communication, organizational, and documentation skills, with the ability to convey technical findings and remediation plans to both internal teams and clients
  • Demonstrated ability to coordinate and influence technical teams, fostering collaboration for effective vulnerability mitigation
  • Proficiency in scripting (for example, Python, PowerShell) for automating tasks and scaling vulnerability management solutions
  • Familiarity with defining and enforcing baseline configuration standards (for example, CIS Benchmarks) and presenting compliance findings
  • Professional/Expert level certifications in Azure *or* AWS *or* GCP
  • Security-focused cloud certifications for Azure *or* AWS *or* GCP
Responsibilities
  • Provide senior-level oversight for enterprise vulnerability management tools (for example, Tenable, Nessus, Burp, Qualys, Rapid7, Wiz, Prisma, Microsoft Defender), ensuring they remain updated and fully operational
  • Lead the execution of regular and on-demand scans across a variety of environments (operating systems, databases, web applications, containers), then collaborate with technical teams (for example, SRE and client administrators) to prioritize and remediate vulnerabilities
  • Serve as a key point of contact for monthly reporting on open vulnerabilities, vendor dependencies, and operational requirements, delivering clear data-driven updates to clients
  • Offer strategic, risk-based recommendations to improve vulnerability posture, aligning remediation with organizational and compliance objectives
  • Work closely with cross-functional teams to refine and integrate vulnerability management processes in cloud environments (AWS, Azure, GCP)
  • Enhance internal standards, processes, and documentation for vulnerability management, including training materials, standard operating procedures, and best practices
  • Lead or support security assessment and authorization initiatives to ensure adherence to compliance frameworks such as FedRAMP, HITRUST, and PCI
Desired Qualifications
  • Security+
  • CISSP
  • Terraform

Coalfire provides cybersecurity advisory services to help businesses safeguard their digital assets and enhance their security protocols. The company focuses on cloud technology and develops scalable security programs tailored to various clients, including large enterprises and organizations in regulated sectors like healthcare and finance. Coalfire's services encompass cybersecurity risk assessments, threat and vulnerability management, compliance assessments, and third-party risk management. They also offer cloud security consulting and managed services to ensure secure cloud environments. Unlike many competitors, Coalfire emphasizes specialized compliance services, such as HIPAA and HITRUST guidance, to help clients meet strict security requirements. The company's goal is to advance cybersecurity practices while supporting education in the field through initiatives like the Richard E. Dakin Fund.

Company Size

501-1,000

Company Stage

Series B

Total Funding

$9.4M

Headquarters

Westminster, Colorado

Founded

2001

Simplify Jobs

Simplify's Take

What believers are saying

  • Coalfire's Cyber Security On-Demand portfolio offers flexible, tailored cybersecurity services.
  • The Snyk partnership accelerates vulnerability remediation in code development.
  • RAMPCon event boosts Coalfire's reputation in FedRAMP and cloud security.

What critics are saying

  • Rapid office expansion may strain Coalfire's resources and operational efficiency.
  • Integrating third-party platforms like Snyk could introduce security vulnerabilities.
  • FedRAMP involvement may risk compliance failures, impacting reputation and trust.

What makes Coalfire unique

  • Coalfire's deep expertise in cloud technology sets it apart in cybersecurity advisory.
  • The company offers specialized services like HIPAA and HITRUST compliance guidance.
  • Coalfire's partnerships with Snyk and Tenable enhance its threat-focused security solutions.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Flexible Work Hours

Remote Work Options

Parental Leave

Unlimited Paid Time Off

Professional Development Budget

Mental Health Support

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

Growth & Insights and Company News

Headcount

6 month growth

-1%

1 year growth

1%

2 year growth

1%
BizWest
Sep 11th, 2024
Exabeam appoints chief customer success officer

BROOMFIELD - Kish Dill has been appointed as chief customer success officer for Exabeam Inc., a global cybersecurity company.

BizWest
Aug 23rd, 2024
Sovrn hires pair of executives

Coalfire hires pair of execsWESTMINSTER - Coalfire Systems Inc., a Westminster-based cybersecurity firm, has hired Chris Kloes as chief...

PR Newswire
Aug 5th, 2024
Coalfire And Snyk Partner To Drive Threat-Informed Application And Code Development

This partnership brings Coalfire's hacker expertise as a managed service for optimizing application securityLAS VEGAS, Aug. 5, 2024 /PRNewswire/ -- BLACK HAT CONFERENCE -- Coalfire , an industry-leading cybersecurity services and solutions company, today announced a partnership with Snyk , the leader in developer security, to operationalize application and code security faster than ever. This partnership brings Coalfire's hackers and defenders to the critical work of detecting and stopping vulnerabilities in the code development phase and beyond. Combining Snyk's leading Developer Security Platform with Coalfire's hacker expertise provides a threat-informed view of vulnerabilities, enabling enterprises to more rapidly address the most pressing flaws in their code and applications.Organizations of all sizes often struggle with enabling their security teams to reduce risk in their development environments, whether in proprietary code, open source modules, containers, or Infrastructure as Code. Snyk's world class platform enables developer teams to identify and fix those vulnerabilities and misconfigurations from the integrated development environment (IDE) to the operation of their cloud environments. The addition of Coalfire's hackers and defenders brings in a threat-informed perspective to prioritize the remediation of those vulnerabilities, which optimizes security outcomes for customers.Through this partnership, Coalfire's experts assist clients with deployment of the Snyk platform, implementing Snyk best practices, facilitating comprehensive testing, reviewing scan results and prioritizing vulnerabilities, as well as providing expert guidance on risk management and secure coding

The Software Report
Aug 5th, 2024
Procore Technologies Initiates FedRAMP Authorization Process to Enhance Security Compliance

Procore has partnered with Coalfire, a renowned cybersecurity and compliance services company, to ensure that its customers benefit from standardized security and continuous monitoring across its product suite, efficiently achieving audit-ready status.

Help Net Security
Jul 24th, 2024
Coalfire announces Cyber Security On-Demand portfolio

Coalfire announced its Cyber Security On-Demand portfolio to provide a flexible set of services that reduce cyber risks and remediate security vulnerabilities in customer environments.