Vulnerability Engineer
Southern Company
- Location
- Atlanta, GA, United States
- Work model
- On-Site
- Level
- Mid
- Posted
- Aug 26, 2026
Skills
About this role
Endpoint Security & Vulnerability Management Engineer Please note: As per current corporate policy, this position may require you to be in the office up to four (4) days per week and/or as additionally required based on business needs, onboarding, operational support, or leadership direction 3 years of experience in workplace support, desktop support, service desk, endpoint operations, EWS, systems administration, application support, vulnerability remediation support, or related enterprise technology disciplines JOB SUMMARY This Endpoint Security & Vulnerability Management Engineer position supports Digital Workplace Planning & Service Management and is focused on reducing enterprise cyber risk through vulnerability remediation, software lifecycle management, endpoint security controls, automation, reporting, and operational modernization The most qualified candidates will bring strong organizational skills, clear communication, customer-focused support experience, and a demonstrated ability to coordinate work across technical teams. Prior vulnerability management, endpoint security, scripting, or advanced endpoint engineering experience is helpful but may be developed through internal training, mentoring, and hands-on project work The Endpoint Security & Vulnerability Management Engineer works closely with Cyber Security, Infrastructure, Endpoint Engineering, Service Management, application owners, vendors, and support teams to improve software currency and compliance, accelerate remediation efforts, support secure delivery of endpoint technologies, and strengthen operational efficiency while maintaining a positive end-user experience This position supports application control, application allowlisting, endpoint privilege management, software lifecycle health, patching support, automation, dashboards, operational documentation, and continuous improvement across the enterprise endpoint environment JOB REQUIREMENTS Education: Bachelor's degree in information technology, Computer Science, Engineering, Cybersecurity, or a related discipline preferred Military experience, equivalent education, technical training, certifications, and relevant hands-on experience will be considered Knowledge, Skills and Abilities: A minimum of 3 years of experience in workplace support, desktop support, service desk, endpoint operations, EWS, systems administration, application support, vulnerability remediation support, or related enterprise technology disciplines. Certifications, formal technical training, and prior vulnerability management experience are preferred but not required for qualified internal candidates who demonstrate strong ownership, communication, organization, collaboration, troubleshooting, and willingness to learn. The selected candidate may be developed through an internal training plan focused on endpoint security, vulnerability management, automation, reporting, and enterprise remediation practices. Experience supporting Microsoft Windows endpoints, users, applications, or endpoint-related incidents in an enterprise support environment Familiarity with Microsoft Intune, MECM/SCCM, Microsoft Configuration Manager, software deployment tools, device management consoles, or comparable endpoint support platforms preferred Basic understanding of vulnerability management, patching, remediation tracking, compliance follow-up, ticket management, or operational risk reduction preferred; deeper vulnerability management skills may be developed through training Ability to support vulnerability remediation execution by organizing work, tracking actions, following up with stakeholders, validating outcomes, and escalating blockers as needed Ability to partner effectively with Cyber Security, Infrastructure, Endpoint Engineering, Service Management, vendors, application owners, Workplace Support, Desktop Support, Service Desk, and EWS teams to coordinate remediation plans and operational follow-through Exposure to endpoint security concepts