At ZOLL, we're passionate about improving patient outcomes and helping save lives.
We provide innovative technologies that make a meaningful difference in people's lives. Our medical devices, software and related services are used worldwide to diagnose and treat patients suffering from serious cardiopulmonary and respiratory conditions.
Due to the on‑site requirements of this position, applicants are expected to reside within a reasonable commuting distance of the designated work location (Chelmsford, MA). This role does not offer relocation.
About the Role
We are looking for a Vulnerability Management & Security Engineer to help strengthen our enterprise cybersecurity program. In this role, you will operate and improve vulnerability management capabilities, analyze security risk, coordinate remediation with technical teams, and help reduce exposure across a complex global technology environment.
This is a hands-on technical role with strong cross-functional visibility. You will work closely with Infrastructure, End User Services, Cloud Operations, application teams, and Security Operations to identify, prioritize, communicate, and validate remediation of vulnerabilities that matter most to the business.
What You'll Do
- Operate, administer, and continuously improve enterprise vulnerability management platforms, including Tenable and related technologies.
- Define and maintain vulnerability scanning strategies across servers, workstations, network devices, cloud resources, web applications, and externally exposed assets.
- Analyze vulnerability findings and prioritize remediation using exploitability, threat intelligence, asset criticality, business impact, and risk context.
- Partner with technical teams to drive remediation of critical and high-risk vulnerabilities through verified closure.
- Improve scan coverage, authenticated assessment rates, asset visibility, vulnerability discovery accuracy, and reporting quality.
- Develop dashboards, metrics, and reports that show vulnerability aging, SLA performance, asset coverage, exposure trends, remediation progress, and risk reduction.
- Support exception reviews, compensating-control analysis, escalation activities, and evidence collection for audit-ready vulnerability management practices.
- Contribute to broader cybersecurity engineering initiatives, including endpoint security, identity security, cloud security, Zero Trust, security hardening, threat hunting, and exposure reduction.
What We're Looking For
- Bachelor's degree in cybersecurity, information technology, computer science, or equivalent practical experience.
- 5+ years of cybersecurity, infrastructure, or security engineering experience.
- 3+ years of experience managing or supporting enterprise vulnerability management programs.
- Hands-on experience with Tenable or equivalent vulnerability assessment platforms.
- Experience supporting vulnerability remediation across large, decentralized, or complex technology environments.
- Strong working knowledge of vulnerability scoring, risk-based prioritization, CVSS, CIS Benchmarks, NIST guidance, and industry vulnerability management practices.
- Ability to translate technical security findings into clear remediation guidance and practical business risk context.
- Strong communication, stakeholder engagement, analytical, and problem-solving skills.
Preferred Qualifications
- Cybersecurity certification such as CISSP, GIAC, CySA+, Security+, CVA, or similar.
- Experience in healthcare, medical device, manufacturing, or other regulated environments.
- Experience with vulnerability management platforms, security operations technologies, IT service management or CMDB platforms, cloud security technologies, scripting, APIs, or Infrastructure-as-Code.
- Experience developing dashboards, operational metrics, executive-ready reporting, or audit evidence for cybersecurity programs.
What Success Looks Like in the First 12 Months
- Improve vulnerability scan coverage and reliability across key enterprise asset populations.
- Strengthen risk-based prioritization and remediation tracking for critical and high-risk vulnerabilities.
- Deliver clear reporting that helps technical teams and leadership understand exposure, aging, remediation progress, and risk reduction.
- Build strong working relationships with Security, Infrastructure, Cloud Operations, End User Services, application teams, and other remediation partners.
- Identify opportunities to automate repetitive vulnerability management workflows and improve operational efficiency.
ZOLL Medical does not provide immigration-related sponsorship for this role. Do not apply for this role if you will need ZOLL immigration sponsorship (e.g. H1B, TN, STEM, OPT, etc.) either now or in the future.
ZOLL is a fast-growing company that operates in more than 140 countries around the world. Our employees are inspired by a commitment to make a difference in patients' lives, and our culture values innovation, self-motivation and an entrepreneurial spirit. Join us in our efforts to improve outcomes for underserved patients suffering from critical cardiopulmonary conditions and help save more lives.
The annual salary for this position is:
$108,100.00 to $129,000.00Factors which may affect starting salary include geography, skills, education, experience, and other qualifications of the successful candidate. Details of ZOLL's comprehensive benefits plans can be found at www.zollbenefits.com.
Applications will be accepted on an ongoing basis until this position is filled. For fully remote positions, compensation will comply with all applicable federal, state, and local wage laws, including minimum wage requirements, based on the employee’s primary work location.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, disability, or status as a protected veteran.
ADA: The employer will make reasonable accommodations in compliance with the Americans with Disabilities Act of 1990.