IT Compliance Vulnerability Engineer | 100% Remote (CA)

Company: Zeektek

Location: Anywhere

Location/Schedule: Remote (California-based candidates only) • Long-term contract • Daily 9:00 AM standups • After-hours availability required for critical remediation

Overview

A growing organization is hiring an IT Compliance Vulnerability Engineer for a long-term contract engagement. This hands-on systems administration role focuses on remediating vulnerabilities against strict SLAs and documenting fixes as audit evidence, following the organization’s recent SOC 2 certification and ongoing alignment to NIST controls. You’ll join a small infrastructure team (3 systems administrators, 2 database administrators) supporting a hybrid Azure and on-premise datacenter environment.

Responsibilities

Analyze vulnerability scan results (Tenable/Nessus) across servers, endpoints, and infrastructure; remediate findings hands-onMeet SLA-driven remediation timelines: Critical–24 hrs, High–7 days, Medium–30 days, Low–60 days, Internal systems–5 daysAutomate remediation at scale using PowerShellTrack all work in ServiceNow to support SOC 2 evidence collection and audit readinessPartner with system/application owners to drive vulnerabilities to a fix or documented exceptionPresent to and participate in the Change Advisory Board (CAB) for patching, hardening, and baseline changesSupport patch management: deployment, testing, change control adherenceImplement/maintain secure configuration baselines (CIS Benchmarks, Microsoft Security Baselines, or DISA STIGs)Administer endpoint management/EDR tooling: SentinelOne, Intune, Group PolicyMaintain technical documentation, standards, and remediation proceduresDevelop operational metrics and compliance reporting for leadership and auditorsRequired Qualifications

3+ years in systems administration, cybersecurity operations, vulnerability management, endpoint management, or related fieldStrong Windows Server and Windows endpoint administrationPowerShell automation for remediation tasks (preferred method)Group Policy administration and registry-level configuration/remediationHands-on vulnerability remediation experience — able to speak to specific fixes executedExperience with a vulnerability scanner (Tenable or Nessus)Endpoint management/EDR experience with SentinelOne and Microsoft IntuneTicket-based documentation discipline (ServiceNow or comparable)Experience presenting to a CAB or participating in formal change managementWorking familiarity with Azure environmentsStrong grasp of cybersecurity principles and system hardening standardsAbility to prioritize competing workloads under deadline pressureAvailability for after-hours remediation work as neededPreferred Qualifications

Automox or comparable enterprise patching platformSprinto or another continuous compliance/evidence platformMicrosoft Defender for CloudLight Linux administration (environment is predominantly Windows)AWS exposure alongside AzureExperience with CIS Benchmarks, Microsoft Security Baselines, or DISA STIGs implementationSOC 2 support experience; NIST, CIS Controls, or ISO 27001 familiarityAudit logging, event collection, and security monitoring administrationOperational metrics/compliance reporting development experience

Apply / view original listing

← Back to all jobs