King County, WA

Senior Vulnerability Engineer

King County, WA  •  $119k - $151k/yr  •  United States (Hybrid)  •  4 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Posting number: 2026-28156

Department: KCIT - Information Technology

Division: Office of the CIO

Job classification: IT Production Engineer-Senior (C19 : PROTEC17-Information Tech)

Posting type: Open & Promotional

Categories: IT and Computers

Summary

20260821150130_Group 1 Banner.png

King County Information Technology (KCIT) is seeking a Senior Vulnerability Engineer to join the Information Security, Risk & Compliance team and lead the technical execution of its enterprise vulnerability management program. The role is responsible for identifying, assessing, validating, and prioritizing vulnerabilities across infrastructure, cloud environments, applications, and network devices. It serves as the technical authority ensuring vulnerabilities are accurately identified, risk-prioritized, and remediated according to policies and SLAs. The position collaborates closely with infrastructure, application, cloud, networking, security operations, and governance teams to reduce cyber risk through continuous monitoring, threat-informed prioritization, automation, and process improvement. Additionally, the engineer provides technical leadership in evaluating emerging threats, implementing vulnerability technologies, developing remediation strategies, and advancing program maturity.

About King County Department of Information Technology (KCIT)

King County is committed to being the best-run government in the nation, and King County Information Technology (KCIT) is helping lead that transformation. KCIT harnesses the power of technology to modernize operations, advance digital equity and social justice, and deliver innovative solutions that engage, empower, and serve our residents, businesses, and community partners.

Recognized by the National Association of Counties (NACo) for excellence in vision, strategy, innovation, and collaboration, KCIT is focused on delivering smart, secure, and customer-centered technology services that strengthen county operations and support thriving, resilient communities. As the technology business partner to all 18 County departments, KCIT provides the foundational systems and services that power many of the region’s most essential functions. We work side-by-side with our partners to design and deliver technology solutions that enhance customer experience and advance King County’s mission. Learn more about KCIT at: http://kingcounty.gov/depts/it.aspx.

This recruitment may be used to fill additional vacancies that may occur.

Examples of duties

Vulnerability Operations

  • Manage enterprise vulnerability scanning
  • Validate scanner accuracy and investigate false positives
  • Tune scan templates and credentials
  • Maintain asset inventory coverage
  • Monitor scan health and failures
  • Validate remediation effectiveness
  • Maintain vulnerability exceptions
  • Track remediation SLAs
  • Support external penetration testing

Risk-Based Prioritization

  • Evaluate potential impacts of vulnerabilities
  • Reviewing Microsoft's Patch Tuesday releases
  • Assess vendor advisories
  • Monitor threat intelligence feeds
  • Determine emergency patch requirements
  • Develop remediation recommendations

Engineering & Automation

  • Integrate vulnerability platforms with ticketing systems
  • Automate remediation workflows
  • Develop PowerShell/Python scripts
  • Create APIs between scanning platforms and CMDBs
  • Automate executive reporting
  • Reduce manual effort

Stakeholder Engagement

  • Communicate vulnerability findings to stakeholders in clear, business focused language
  • Provide guidance on remediation strategies, expected timelines, and resource needs
  • Coordinate with engineering, product, infrastructure, and operations teams to ensure timely vulnerability resolution
  • Set and manage expectations around remediation windows, technical constraints, and risk acceptance considerations
  • Build and maintain strong cross-functional relationships with technical teams, leadership, and compliance groups
  • Recommend secure development practices and process improvements based on recurring vulnerability patterns
  • Act as the escalation point for high-risk or complex vulnerabilities requiring urgent cross-team coordination

Threat & Incident Response Support

  • Evaluate emergency vulnerabilities
  • Determine exposure within the environment
  • Identify affected assets
  • Recommend mitigations
  • Coordinate emergency patching
  • Produce executive impact assessments
  • Support incident response teams

Program Improvement

  • Identify systemic issues and streamline vulnerability management processes
  • Enhance scanning tools, asset coverage, reporting, and remediation workflows
  • Maintain and refine policies and procedures to improve program maturity
  • Strengthen prioritization models to align remediation with business risk
  • Integrate security practices earlier in the SDLC through cross-team collaboration
  • Define and track KPIs to measure program effectiveness and guide strategy
  • Lead automation initiatives to reduce manual work and speed remediation
  • Support capability growth through maturity roadmaps and team mentorship

Qualifications

  • Four (4) or more years of experience in information security, vulnerability management, application security, security engineering, or related discipline.
  • Strong understanding of modern security vulnerabilities, exploit techniques, and common attack vectors.
  • Deep knowledge of vulnerability scanning tools (e.g., Rapid7, Qualys, Tenable), asset inventory systems, and security orchestration platforms.
  • Familiarity with cloud security (AWS, Azure, GCP), container security, and modern DevOps workflows.
  • Strong understanding of operating systems, networking fundamentals, and secure development practices.
  • Awareness of regulatory, compliance, and industry security standards.
  • Ability to translate technical findings into clear business risk for diverse stakeholders.
  • Strong analytical skills for evaluating vulnerability risk, prioritization, and remediation strategies.
  • Excellent communication and relationship-building skills across technical and non-technical teams.
  • Skill in automating repetitive tasks and improving workflows.
  • Ability to lead cross-team efforts, manage escalations, and drive timely decision-making.

Desirable Qualifications

  • Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent practical experience)
  • Relevant security certifications such as OSCP, OSWE, CISSP, GIAC (GSEC, GCIH, GPEN), Security+ or similar are preferred

Supplemental information

Hybrid Work: KCIT works in a hybrid model, with days in the office as well as telecommuting. The ratio of remote to onsite work will be dependent on business needs and is subject to change. The primary onsite location is the Chinook Building, 401 5th Ave, Seattle, WA 98104.

Employees must reside in Washington state and within a reasonable distance to their King County worksite to respond to workplace reporting requirements.

King County has a robust collection of tools and resources to support working remotely. The individual selected for this opportunity will join an innovative and progressive team that is redefining how we work as we transition to the department's hybrid environment. Employees will be provided with a County-issued laptop and must maintain a home workspace with an internet connection where they can reliably perform work and remain available and responsive during scheduled work hours.

Work Schedule: The normal workweek for this position is Monday through Friday, 8:00 a.m. to 5:00 p.m. Alternative schedules may be considered by your manager. This position will participate on the After-Hours Support (AHS) team rotating across a pool of 12 to 15 staff (24x7, 7-day rotation Monday-Sunday).

FLSA Status: This position is FLSA Exempt and is not eligible for overtime pay.

Classification: IT Production Engineer-Senior (Job code: 741601)

Union: This position is represented by Protec17: Information Technology.

Who May Apply: This recruitment is open to all qualified candidates. We value diversity, diverse perspectives and life experience and encourage people of all backgrounds to apply.

Are you ready to make a difference? Come join the team dedicated to serving one of the nation's best places to live, work and play.

Application Process

Applicants must complete the online application to include:

  1. Employment history going back at least seven years if possible (or more to include all relevant experience).
  2. A resume including all relevant experience.
  3. A cover letter detailing how your experience and qualifications make you a fit for this position.

If you are interested in pursuing this position and supporting King County’s vision for unified, equitable, and high-performing government, please follow the application instructions carefully. Provide us with your work history as applicable, ensuring that you provide details that highlight your ability to fulfill the requirements for this position.

If you need this announcement in an alternate language or format, or you would like to request accommodation or assistance in the application or assessment process, please contact Angelia Remolana at aremolana@kingcounty.gov

King County's Vision, Mission, and ACTIVATE Values unite us.

King County serves residents with a relentless sense of urgency, delivering on commitments with transparency and accountability. We are action-oriented, creative problem solvers who collaborate across roles, engage directly with communities, and challenge the status quo to achieve meaningful impact. As a unified team, we uphold high ethical and stewardship standards, embrace change, stay curious, and continuously improve. Across all interactions, we listen first, act quickly, and stay aligned as a team to earn and sustain public trust. Learn more about our Vision, Mission, and ACTIVATE Values here and visit our Why work at King County page here.

King County is an Equal Employment Opportunity (EEO) Employer

No person is unlawfully excluded from employment opportunities based on sex, race, color, national origin, ethnicity, religious affiliation, disability, sexual orientation, gender identity or expression, age except by minimum age and retirement provisions, pregnancy, status as a family caregiver, parental status, marital status, military status or status as a veteran who was honorably discharged or who was discharged solely as a result of the person's sexual orientation or gender identity or expression, citizenship or immigration status, genetic information, or other protected class. However, to the extent that distinction or differential treatment on the basis of citizenship or immigration status is authorized by either federal or state law, regulation, or government contract, it is not an unfair practice.

Our EEO policy applies to all employment actions, including but not limited to recruitment, hiring, selection for training, promotion, transfer, demotion, layoff, termination, rates of pay or other forms of compensation.

King County, WA

About King County, WA

King County is one of the best places to work in Washington and one of the state's largest employers with 14,000 dedicated employees. Together, we are changing the way government does business and delivering vital services for more than 2 million residents. #GoPublic

Industry
Government & Public Safety
Company Size
5,001-10,000 employees
Headquarters
Seattle, Washington
Year Founded
Unknown
Social Media