SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 152,000 - 185,000 / annual
Datavant is seeking a Vulnerability & Exposure Management Engineer to build and operate an engineering-driven vulnerability and exposure management program. This is a hands-on technical role focused on turning vulnerability data into actionable signals embedded in modern engineering workflows, emphasizing automation, practical risk reduction, and scalable solutions rather than ticket-tracking or audit administration.
Key responsibilities include:
- Design, implement, and operate vulnerability and exposure management capabilities with focus on reducing real exploit risk
- Build automation and workflows that ingest, normalize, and prioritize vulnerability signals across multiple sources
- Develop engineer-facing dashboards and integrations to help teams understand and act on vulnerability risk
- Work with product and engineering teams to assess findings, explain exploitability and impact, and support remediation
- Embed vulnerability signals into existing engineering workflows (CI/CD, PRs, backlogs) to improve visibility and adoption
- Validate remediation efforts to ensure exposure is meaningfully reduced
- Translate compliance and control requirements (FedRAMP, NIST, CIS) into scalable technical implementations
- Support FedRAMP and other assessments by validating technical evidence
- Execute technical projects improving vulnerability visibility, prioritization, and risk reduction
Required qualifications:
- Solid technical experience in vulnerability management and application security with hands-on exposure assessment and prioritization
- Demonstrated ability to build or automate technical workflows using Python, Go, or similar languages
- Experience with application, cloud, or container security in AWS and/or Azure
- Working knowledge of security controls and compliance frameworks (NIST, CIS, FedRAMP)
- Ability to reason about exploitability, exposure, and impact beyond severity scores
- Experience collaborating with engineering teams on remediation
- Clear communication skills for varied audiences
- Foundational understanding of vulnerability management within broader security and engineering functions
- Experience with commercial security tooling (SAST, SCA, cloud security platforms)
Desirable experience includes custom scripts and automation for vulnerability visibility, exposure to regulated environments (healthcare, FedRAMP), CI/CD pipeline integration, cloud security platforms (Wiz), security data tooling (Snowflake, Sigma), and AI-assisted development tools (Claude Code).
Datavant is a healthcare data collaboration platform trusted by providers, health plans, researchers, and life sciences companies. The company is committed to building a diverse, high-performance team.