Logo
Western Digital

Senior management engineer

Western Digital, Milpitas, California, United States, 95035


Company Description

At Western Digital, we are on a mission to unlock the potential of data so people, companies and organizations everywhere can create what’s next. To fulfill our vision, we are always on the lookout for potential team members who share our passion for solving problems to empower others. When you join Western Digital, you join a legacy more than 50 years in the making. Across our Western Digital, SanDisk, SanDisk Professional, WD and WD_BLACK brands, we have brought some of the most storied advancements in memory and data storage technology to market—and our best, most innovative work is yet to come. From energizing gaming platforms, to enabling systems to make cities safer and cars smarter and more connected, to powering the data centers behind many of the world’s biggest companies and public cloud, Western Digital is fueling a brighter, smarter future. Here’s how you can help. Job Description

We are seeking a highly skilled and experienced Senior Vulnerability Management Engineer to spearhead our vulnerability assessment, remediation, and attack surface reduction efforts. This position involves leading the identification, assessment, and mitigation of vulnerabilities across various platforms, networks, and applications, with a focus on reducing the organization's attack surface. The ideal candidate will have deep understanding of Enterprise IT and Engineering landscape and a proven track record in vulnerability management, with in-depth expertise in identifying, prioritizing, and mitigating vulnerabilities across complex enterprise environments. ESSENTIAL DUTIES AND RESPONSIBILITIES: Lead Vulnerability Management:

Take ownership of the vulnerability management lifecycle, including identification, assessment, prioritization, remediation, and reporting of security vulnerabilities. Oversee regular vulnerability scans, penetration tests, and security assessments to identify weaknesses in systems, networks, and applications. Attack Surface Reduction:

Analyze and map the organization’s attack surface, identifying potential entry points and areas of exposure. Develop and implement strategies to reduce the attack surface across all digital assets, ensuring proactive defense against emerging threats. Continuously monitor changes to the IT environment to ensure the attack surface remains minimized. Collaboration & Mentorship:

Work closely with cross-functional teams, including IT, DevOps, and security operations, to integrate vulnerability management practices into development and operational processes. Provide mentorship and training to junior security team members. Stakeholder Communication:

Effectively communicate vulnerability management activities, findings, and risk mitigation strategies to technical and non-technical stakeholders, including senior leadership. Critical Decision-Making:

Make informed, critical decisions in high-pressure situations, ensuring the protection of the organization’s infrastructure and data. Governance & Continuous Improvement:

Stay current with the latest vulnerability management tools, technologies, and methodologies, and continuously improve the organization’s vulnerability management program. Ensure that vulnerability and attack surface management processes comply with industry standards, regulations, and organizational policies. Automation and Tooling:

Evaluate and implement tools and technologies to automate vulnerability scanning, risk assessment, and remediation tracking. Develop and maintain scripts, tools, and processes to streamline and enhance the effectiveness of the vulnerability management program. Qualifications

Required Skills: Deep understanding of vulnerability management tools (e.g., Nessus, Qualys, Tenable), systems architecture, and security technologies. Extensive experience in vulnerability assessment and management within large-scale, complex IT environments. Working with large ecosystems with a number of security related tools such as Asset Management, Vulnerability Scanners (Nessus, Qualys), Endpoint Protection (CrowdStrike, Defender), SIEM etc. Proficiency in scripting languages (e.g., Golang, Python, Bash, PowerShell) and experience with automation tools. Relevant certifications such as CISSP, CISM, or CEH are preferred. Preferred Skills: Exceptional communication skills, with the ability to translate technical issues into business risks for stakeholders. Ability to make critical decisions under pressure and in complex situations. High level of integrity, professionalism, and attention to detail. Prior experience in a global, large-scale manufacturing environment is a plus. Additional Information

Western Digital is committed to providing equal opportunities to all applicants and employees and will not discriminate against any applicant or employee based on their race, color, ancestry, religion, sex, gender, age, national origin, sexual orientation, medical condition, marital status, physical disability, mental disability, genetic information, or other legally protected characteristics. We also prohibit harassment of any individual on any of the characteristics listed above. Our non-discrimination policy applies to all aspects of employment. Western Digital thrives on the power and potential of diversity. As a global company, we believe the most effective way to embrace the diversity of our customers and communities is to mirror it from within. We believe the fusion of various perspectives results in the best outcomes for our employees, our company, our customers, and the world around us. We are committed to an inclusive environment where every individual can thrive through a sense of belonging, respect and contribution. Western Digital is committed to offering opportunities to applicants with disabilities and ensuring all candidates can successfully navigate our careers website and our hiring process. Please contact us at jobs.accommodations@wdc.com to advise us of your accommodation request. Based on our experience, we anticipate that the application deadline will be

03/11/2025 , although we reserve the right to close the application process sooner if we hire an applicant for this position before the application deadline. #LI-RT1 Compensation & Benefits Details An employee’s pay position within the salary range may be based on several factors including relevant education, qualifications, certifications, experience, skills, ability, knowledge of the job, performance, contribution, results, geographic location, shift, internal and external equity, and business and organizational needs. The salary range is what we believe to be the range of possible compensation for this role at the time of this posting and may ultimately pay more or less than the posted range. This range may be modified in the future. You will be eligible to participate in Western Digital’s Short-Term Incentive (STI) Plan, which provides incentive awards based on Company and individual performance. Depending on your role and performance, you may be eligible for our annual Long-Term Incentive (LTI) program. Please note that not all roles are eligible to participate in the LTI program. We offer a comprehensive package of benefits including paid vacation time, paid sick leave, medical/dental/vision insurance, life, accident and disability insurance, tax-advantaged flexible spending and health savings accounts, employee assistance program, and other voluntary benefit programs.

#J-18808-Ljbffr