PitchMeAI
Paylocity

Vulnerability Assessment Engineer

Paylocity · United States

  • Hybrid
  • Full-time
  • $130,000 / year
  • United States
Tailored resumekeyword-matched to this role.
Hiring managerwe find who's hiring.
Intro emaildrafted to reach them directly.

Job highlights

  • Conduct comprehensive vulnerability assessments.
  • Prioritize risks and coordinate remediation efforts.
  • Develop vulnerability management policies.
  • Support cloud security initiatives.
  • Identify automation opportunities for efficiency.

About the role

About Paylocity

Paylocity is an award-winning provider of cloud-based HR and payroll software solutions, offering the most complete platform for the modern workforce. The company has become one of the fastest-growing HCM software providers worldwide by offering an intuitive, easy-to-use product suite that helps businesses automate and streamline HR and payroll processes, attract and retain talent, and build a strong workplace culture.

While traditional HR and payroll providers automate basic HR processes such as payroll and benefits administration, Paylocity goes further by developing tools that HR and businesses need to compete for talent and deliver against the expectations of the modern workforce.

We give our employees what they need to succeed, including great benefits and perks! We offer medical, dental, vision, life, disability, and a 401(k) match, as well as perks that support you, your family, and your finances. And if it’s career development you desire, we provide that, too! At Paylocity, people matter most and have always been at the heart of our business.

Help Paylocity enhance communication and enable employees to connect, collaborate, and create from anywhere with a position in Product & Technology! Want to develop the strategies and principles needed to deliver compelling software? Join our team and help us enhance our all-in-one software platform, elevate our one-of-a-kind technology, and improve the employee experience. Take your career to the next level at one of G2's Top 100 Software Companies. Explore our Product & Technology positions to see where you fit!

Position Overview

The Vulnerability Assessments Engineer conducts comprehensive vulnerability assessments across networks, systems, applications, and third-party vendors, prioritizing risks and coordinating remediation efforts in collaboration with internal teams and system owners. Develops and maintains vulnerability management policies, provides technical analysis and guidance, and ensures consistent reporting through standardized evaluation criteria. Supports cloud security initiatives and identifies opportunities to automate processes for improved scalability and efficiency, while staying current on emerging threats and best practices.

Primary Responsibilities

  • Research, identify, assess, and prioritize vendor and third-party security advisories and acts as a bridge between Information Security and system owners to see through the remediation activities.
  • Conduct vulnerability assessments of our organization's networks, systems, and applications.
  • Analyze vulnerability scan results to identify potential security risks.
  • Develop and maintain vulnerability management processes, policies, and procedures.
  • Collaborate with other teams to prioritize and remediate identified vulnerabilities.
  • Conduct security assessments of third-party vendors and ensure that their security practices meet our organization's standards.
  • Keep up to date with the latest security threats and vulnerabilities and provide recommendations on how to mitigate them.
  • Provide guidance and training to other teams on vulnerability management best practices.
  • Provide technical advice to associate team members on attacks.
  • Perform technical analysis on vulnerabilities emanating from Cloud Security Posture Management (CSPM) tools.
  • Create vulnerability evaluation standards for consistent reporting of vulnerabilities across various platforms.
  • Identify opportunities to automate repeatable tasks to solve scale and sustainability challenges associated with vulnerability triage.

Education and Experience

  • 5+ years of experience within an information security role.
  • Bachelor’s degree in computer science, information security, management information systems, or similar major is a plus.
  • Knowledge of vulnerability scanning tools and techniques.
  • Basic ability to script in one of the programming languages such as Python, Ruby, C#, Java, etc.
  • Experience working with vulnerability scanning tools such as Tenable, CrowdStrike, Rapid7, Qualys, etc.
  • Experience working with CVSS and ability to research vulnerabilities independently from sources such as NVD, VulndDB, etc.
  • Familiarity with security frameworks such as NIST, ISO 27001, and CIS Controls.
  • Professional certification such as the Security+, CEH, OSCP, AWS Certified Cloud Practitioner, Agile Scrum, CSM, CSPO, PMIACP, GSLC is a plus.
  • Strong knowledge of IT ecosystem ranging from hardware network devices, storage systems, workstations, mobile devices, operating systems, and application frameworks.
  • Intermediate knowledge of evolving technologies such as containers and cloud security.
  • Basic knowledge of common cloud platforms such as AWS, Azure, GCP, etc.
  • Ability to evaluate cloud vulnerabilities resulting from Cloud Security Posture Management (CSPM) Tools such as Wiz, Prisma.
  • Stays up to date and current on new threats and new developments in the information security field.
  • OWASP standards such as ASVS, Testing Guide, Mobile & API Top 10.
  • Experience with writing Burp plugins, opensource security tools, presenting at security conferences, writing technical research papers or publishing CVE is a plus.
  • Experience working with Payroll, HR, Time & Labor Management, and Online Benefits Enrollment applications is a plus.

Physical Requirements

  • Ability to sit for extended periods: The role requires sitting at a desk or workstation for long periods, typically 7-8 hours a day.
  • Use of computer and phone systems: The employee must be able to operate a computer, use phone systems, and type. This includes using multiple software programs and inquiries simultaneously.

Key Skills/Competency

  • Vulnerability Assessment
  • Network Security
  • Application Security
  • Third-Party Risk Management
  • Cloud Security
  • Risk Prioritization
  • Remediation Coordination
  • Security Policy Development
  • Vulnerability Scanning Tools
  • Information Security

Skills & topics

  • Vulnerability Assessment Engineer
  • Information Security
  • Cybersecurity
  • Network Security
  • Application Security
  • Cloud Security
  • Risk Management
  • Penetration Testing
  • Vulnerability Management
  • Security Auditing
  • Tenable
  • Rapid7
  • Qualys
  • Python
  • NIST
  • ISO 27001
  • CIS Controls
  • CVSS
  • HCM Software
  • SaaS

How to get hired

  • Customize your resume: Highlight experience with vulnerability scanning tools (Tenable, Qualys), scripting (Python), and security frameworks (NIST, ISO 27001).
  • Tailor your application: Emphasize your 5+ years in information security and any relevant certifications.
  • Prepare for technical questions: Be ready to discuss CVSS scoring, threat research, and cloud vulnerabilities.
  • Showcase collaboration skills: Demonstrate your ability to work with system owners and other teams for remediation.
  • Research Paylocity: Understand their HR/payroll software and commitment to employee experience.

Technical preparation

Master vulnerability scanning tools (Tenable, Rapid7).,Practice scripting with Python or similar.,Study CVSS, NVD, and threat intelligence.,Review security frameworks (NIST, ISO 27001).

Behavioral questions

Describe a complex vulnerability you found.,How do you prioritize remediation efforts?,How do you collaborate with system owners?,How do you stay updated on new threats?

Frequently asked questions

What are the primary responsibilities of a Vulnerability Assessment Engineer at Paylocity?
The Vulnerability Assessment Engineer at Paylocity conducts comprehensive vulnerability assessments across networks, systems, and applications, prioritizes risks, and coordinates remediation. This role involves developing vulnerability management policies, supporting cloud security, and identifying automation opportunities.
What qualifications are needed for the Vulnerability Assessment Engineer role at Paylocity?
A minimum of 5 years in information security is required, along with knowledge of vulnerability scanning tools (Tenable, Rapid7, Qualys) and basic scripting skills (Python). A Bachelor's degree in a related field and relevant certifications are a plus.
Is the Vulnerability Assessment Engineer position at Paylocity remote?
Yes, this is a fully remote position allowing you to work from your location within the U.S. There are no in-office requirements. However, the work arrangement is subject to change based on business needs.
What kind of security frameworks does Paylocity expect familiarity with for this role?
Familiarity with security frameworks such as NIST, ISO 27001, and CIS Controls is expected for the Vulnerability Assessment Engineer position at Paylocity.
What programming languages are useful for the Vulnerability Assessment Engineer at Paylocity?
While not strictly required, basic scripting ability in languages such as Python, Ruby, C#, or Java is beneficial for the Vulnerability Assessment Engineer role at Paylocity, particularly for automation tasks.
Does Paylocity offer career development opportunities for a Vulnerability Assessment Engineer?
Yes, Paylocity emphasizes career development and offers various opportunities for employees. They provide training, mentorship, and a path for growth within their Product & Technology teams.
What benefits does Paylocity offer to its employees?
Paylocity offers a comprehensive benefits package including medical, dental, vision, life, and disability insurance, a 401(k) match, and other perks that support employees and their families.
How does Paylocity approach diversity and inclusion for a Vulnerability Assessment Engineer?
Paylocity is committed to the full inclusion of all individuals and embraces diversity in all its forms. They actively cultivate differences through employee resource groups and experiences to drive innovation.

Similar roles

Open positions we recommend based on this role.