What are the responsibilities and job description for the Senior Vulnerability Engineer position at Sogeti?
**This is a hybrid role - candidates must go into the office 4 days a week located in Phoenix, AZ**
Role Summary:
The Senior Vulnerability Engineer is a hands-on role responsible for driving timely, high-quality remediation of security vulnerabilities and configuration gaps across enterprise environments. This position owns the remediation execution cadence—from tool-generated findings through validation, assignment, evidence collection, risk acceptance coordination, and closure—and is expected to operate effectively in a fast-paced, operational setting with minimal ramp-up time. The role requires clear communication, disciplined expectation setting with IT teams, early identification of blockers, and delivery of decision-ready status and risk reporting to stakeholders and leadership.
Demonstrate advanced proficiency with the ServiceNow Vulnerability Response (VR) module to manage end-to-end vulnerability workflows, including triage, assignment, SLA tracking, exception and risk acceptance processing, remediation evidence captures, and closure.
- Lead a high-tempo remediation cadence (weekly or biweekly) with IT teams; set clear expectations, drive action-item closure, and escalate impediments as required.
- Execute hands-on remediation activities to achieve SLA targets, including patching, configuration changes, implementation of compensating controls, and post-remediation validation; proactively manage at-risk items using documented recovery plans.
- Apply advanced ServiceNow Vulnerability Response (VR) capabilities, including vulnerability group and item management, routing and assignment, SLA and aging oversight, exception and risk acceptance handling, and closure workflows; utilize Rapid7 and Wiz as primary sources of findings.
- Partners with patching and IT teams to execute remediation plans, validate remediation effectiveness, and maintain accurate, auditable closure evidence.
- Provide concise, executive-ready reporting (Power BI and ServiceNow) on SLA performance, aging, risk trends, and decisions required for operational reviews and leadership updates.
Job Responsibilities:
- Drive remediation of tool-identified vulnerabilities by validating applicability and asset context, determining the appropriate remediation approach (patch, configuration change, compensating control), coordinating execution with IT teams, and verifying closure.
- Serve as a ServiceNow Vulnerability Response (VR) subject matter expert, including vulnerability group and item management, routing and assignment, SLA and aging tracking, evidence capture, exception and risk acceptance workflows, and audit-ready closure.
- Conduct monthly KPI/KRI and SLA health reviews; communicate risk and progress clearly, set expectations, and drive timely decisions with leadership and stakeholder teams.
- Develop and drive remediation action plans (owners, milestones, and escalation paths) for critical and high-severity vulnerabilities; maintain momentum and accountability in a fast-paced environment.
- Build and maintain actionable dashboards and reporting (Power BI and ServiceNow VR) that communicate remediation health, SLA risk, vulnerability aging, and trend insights.
- Facilitate exception and risk acceptance requests by ensuring documentation quality, appropriate approvals, defined expiration dates, and end-to-end tracking of compensating controls.
- Provide routine (daily/weekly) stakeholder updates that clearly communicate status, next steps, owners, and estimated timelines; escalate when expectations or SLAs are at risk.
- Document and continuously improve standard operating procedures (SOPs) and coach junior team members on remediation workflows and ServiceNow VR best practices.
What you will need:
- Bachelor’s degree or equivalent practical experience.
- Seven (7) or more years of experience in vulnerability remediation, patch and configuration management, and operational security engineering in fast-paced environments.
- Strong troubleshooting and hands-on remediation skills, including patching, configuration changes, validation and verification, and evidence collection.
- Demonstrated high skill in ServiceNow Vulnerability Response (VR), including vulnerability groups and items, routing and assignment, SLA and aging management, evidence capture, exception and risk acceptance workflows, and audit-ready closure.
- Clear, concise communicator (written and verbal) with demonstrated ability to set expectations, influence without authority, and coordinate across multiple IT teams in a matrixed environment.
- Experience with vulnerability scanning and exposure management tools (e.g., Rapid7, Wiz) and reporting/analytics (e.g., Power BI); ability to translate data into action.
- Demonstrated ability to operate as a self-starter with minimal oversight, manage multiple workstreams, set expectations, and drive remediation to closure.
- Experience in the financial services industry with proven regulatory and compliance discipline.
- Strong analytical skills with the ability to translate vulnerability data into remediation plans, operational metrics, and risk-based communication.
About Sogeti
Part of the Capgemini Group, Sogeti makes business value through technology for organizations that need to implement innovation at speed and want a local partner with global scale. With a hands-on culture and close proximity to its clients, Sogeti implements solutions that will help organizations work faster, better, and smarter. By combining its agility and speed of implementation through a DevOps approach, Sogeti delivers innovative solutions in quality engineering, cloud and application development, all driven by AI, data and automation.
Become Your Best | www.sogeti.us
Disclaimer
Capgemini is an Equal Opportunity Employer encouraging diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race, national origin, gender identity/expression, age, religion, disability, sexual orientation, genetics, veteran status, marital status or any other characteristic protected by law.
This is a general description of the Duties, Responsibilities and Qualifications required for this position. Physical, mental, sensory or environmental demands may be referenced in an attempt to communicate the manner in which this position traditionally is performed. Whenever necessary to provide individuals with disabilities an equal employment opportunity, Capgemini will consider reasonable accommodations that might involve varying job requirements and/or changing the way this job is performed, provided that such accommodations do not pose an undue hardship.
Capgemini is committed to providing reasonable accommodation during our recruitment process. If you need assistance or accommodation, please reach out to your recruiting contact.
Please be aware that Capgemini may capture your image (video or screenshot) during the interview process and that image may be used for verification, including during the hiring and onboarding process.
Click the following link for more information on your rights as an Applicant http://www.capgemini.com/resources/equal-employment-opportunity-is-the-law
Applicants for employment in the US must have valid work authorization that does not now and/or will not in the future require sponsorship of a visa for employment authorization in the US by Capgemini.
Capgemini discloses salary range information in compliance with state and local pay transparency obligations. The disclosed range represents the lowest to highest salary we, in good faith, believe we would pay for this role at the time of this posting, although we may ultimately pay more or less than the disclosed range, and the range may be modified in the future. The disclosed range takes into account the wide range of factors that are considered in making compensation decisions including, but not limited to, geographic location, relevant education, qualifications, certifications, experience, skills, seniority, performance, sales or revenue-based metrics, and business or organizational needs. At Capgemini, it is not typical for an individual to be hired at or near the top of the range for their role.
This role may be eligible for other compensation including variable compensation, bonus, or commission. Full time regular employees are eligible for paid time off, medical/dental/vision insurance, 401(k), and any other benefits to eligible employees.
Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, or any other form of compensation that are allocable to a particular employee remains in the Company's sole discretion unless and until paid and may be modified at the Company’s sole discretion, consistent with the law