layiq
worthy; deserving; fitting; suitable.
A role, opportunity, or path that merits attention, time, and pursuit.
Loading LAYIQ…Job opportunity
Ulta Beauty
Bolingbrook, Illinois
Source: Ulta Beauty careers · View original posting
From Ulta Beauty's posting. “We” and “our” refer to the employer.
OVERVIEW
Live the experience
. From professional empowerment to continual learning opportunities. From ongoing investment in new and emerging technologies to a career of self-determination. At Ulta Beauty, our tech team is critical to our scalability—and is recognized that way. We’ve been defined as a “mature start-up.” A place where interdepartmental exposure, open doors, and genuine collaboration is ubiquitous. Where challenges come fast and furious, requiring agility, mental dexterity, and creativity.
Where our passion for better solutions drives us and is core to who we are.
We’re engineering for the future of retail, and it’s no-holds-barred. But for those motivated by continual change and ambiguity, by superior leadership, by whip smart colleagues who will press you daily for your very best, you’ll find that virtually nothing’s impossible at Ulta Beauty.
The Engineer - Vulnerability Management is responsible for working with the VM Manager to design, implement, and maintain a robust vulnerability management program across hybrid environments, including on-premises, cloud, containers, and SaaS platforms.
This role focuses on technical execution—deploying and tuning scanning tools (Tenable Security Center/Falcon Exposure Management), then using continuous, data driven communication to remediation teams via ServiceNow VR so that they are empowered to address the riskiest vulnerabilities within their environments. The engineer will leverage risk-based prioritization, threat intelligence, and business context to reduce exposure and improve resilience.
This position requires deep technical expertise in vulnerability scanning technologies, scripting and automation, and security practices across the traditional and cloud-native spectrum. The engineer will collaborate closely with infrastructure, cloud, application, and security teams to drive remediation according to organizational SLAs, and continuously improve program maturity through metrics, automation, and emerging technologies.
Prioritize findings using context: exploit likelihood (EPSS), Known Exploited Vulnerabilities (CISA KEV), network exposure, business impact, compensating controls, and asset criticality
Correlate with threat intel and active detections (EDR/XDR/SIEM), elevating actively exploited vulnerabilities to emergency treatment
Define severity thresholds and SLAs per asset class; manage exceptions with time-bound risk acceptance and compensating controls.
Remediation & Ticketing
Drive remediation by regularly partnering with Infra/Platform, Cloud, and App teams to empower them to make informed decisions when weighing the priority of patches and configuration changes versus compensating controls and operational realities
Integrate with ticketing systems (ServiceNow VR) to ensure that proper assignment logic is in place, and that automated validation scans determine the status of fix actions.
Assist the Security Operations team as they execute zero‑day/rapid-response playbooks (e.g. scans/queries, exploitability assessments, validations, enrich post‑mortems)
Asset & Exposure Discovery
Contribute to and help maintain an accurate, continuously updated asset inventory across a primary scope of endpoints, servers, and network devices, as well as containers, mobile, OT/IoT, and cloud resources (IaaS, PaaS, SaaS)
Maintain policy/standards for scanning coverage, remediation SLAs, and risk acceptances.
Work across groups to identify opportunities for improvement within the environment, both technical and operational, along with plans to capture those benefits.
Responsible for ensuring adherence to existing processes both operationally, and in support of PCI and/or SOX audit requirements.
Collaborate with other members of the Engineering organization to create and maintain standards and operating procedures, and provide information as appropriate to manager, project manager, and various departments within the Company.
The pay range for this position is $90,800.00 - $120,000.00 / Year with the opportunity for eligible associates to earn additional compensation pursuant to the Company’s bonus plan. Exact pay will be based on factors including, but not limited to relevant education, qualifications, certifications, experience, level, shift, geographic location, and business and organizational needs. Full-time positions are eligible for paid time off, health, dental, vision, life and disability benefits.
Part-time positions are eligible for dental, vision, life, and disability benefits. For additional information concerning our benefits, visit our Benefits and Career Development page: https://learn.bswift.com/ulta
At
Ulta Beauty
(NASDAQ: ULTA), the possibilities are beautiful
. Ulta Beauty is the largest North American beauty retailer and the premier beauty destination for cosmetics, fragrance, skin care products, hair care products and salon services. We bring possibilities to life through the power of beauty each and every day in our stores and online with more than 25,000 products from approximately 500 well-established and emerging beauty brands across all categories and price points, including Ulta Beauty’s own private label.
Ulta Beauty also offers a full-service salon in every store featuring—hair, skin, brow, and make-up services.
We will consider for employment all qualified applicants, including those with arrest records, conviction records, or other criminal histories, in a manner consistent with the requirements of any applicable state and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, the San Francisco Fair Chance Ordinance, and the New York City Fair Chance Act.
This position requires deep technical expertise in vulnerability scanning technologies, scripting and automation, and security practices across the traditional and cloud-native spectrum. The engineer will collaborate closely with infrastructure, cloud, application, and security teams to drive remediation according to organizational SLAs, and continuously improve program maturity through metrics, automation, and emerging technologies.
Prioritize findings using context: exploit likelihood (EPSS), Known Exploited Vulnerabilities (CISA KEV), network exposure, business impact, compensating controls, and asset criticality
Correlate with threat intel and active detections (EDR/XDR/SIEM), elevating actively exploited vulnerabilities to emergency treatment
Define severity thresholds and SLAs per asset class; manage exceptions with time-bound risk acceptance and compensating controls.
Remediation & Ticketing
Drive remediation by regularly partnering with Infra/Platform, Cloud, and App teams to empower them to make informed decisions when weighing the priority of patches and configuration changes versus compensating controls and operational realities
Integrate with ticketing systems (ServiceNow VR) to ensure that proper assignment logic is in place, and that automated validation scans determine the status of fix actions.
Assist the Security Operations team as they execute zero‑day/rapid-response playbooks (e.g. scans/queries, exploitability assessments, validations, enrich post‑mortems)
Asset & Exposure Discovery
Contribute to and help maintain an accurate, continuously updated asset inventory across a primary scope of endpoints, servers, and network devices, as well as containers, mobile, OT/IoT, and cloud resources (IaaS, PaaS, SaaS)
Maintain policy/standards for scanning coverage, remediation SLAs, and risk acceptances.
Work across groups to identify opportunities for improvement within the environment, both technical and operational, along with plans to capture those benefits.
Responsible for ensuring adherence to existing processes both operationally, and in support of PCI and/or SOX audit requirements.
Collaborate with other members of the Engineering organization to create and maintain standards and operating procedures, and provide information as appropriate to manager, project manager, and various departments within the Company.
LAYIQ is an independent job-discovery service. This listing does not imply a partnership with or endorsement by the employer. Review the original posting for current details and availability.
Employer posted: