Security Engineer Sr. at Blue Cross and Blue Shield of Minnesota in Eagan, MN
- Company: Blue Cross and Blue Shield of Minnesota
- Location: Eagan, MN
- Posted: Sep 24, 2026
- Type: Full-time
- Salary: $102,400.00 - $138,300.00 - $174,200.00 Annual
- Experience: 5+ years
Overview
The Senior Security Engineer supports the organization's security program by reducing enterprise exposure through effective vulnerability management, exposure management, and engineering of security scanning capabilities. This role helps identify, validate, prioritize, and drive remediation of vulne…
Job description
- The Senior Security Engineer supports the organization's security program by reducing enterprise exposure through effective vulnerability management, exposure management, and engineering of security scanning capabilities. This role helps identify, validate, prioritize, and drive remediation of vulnerabilities, misconfigurations, and control gaps across technology and business environments. The position implements, monitors, and improves vulnerability scanning tools, security controls, and related processes that protect organizational assets and support compliance, risk management, and operational objectives. The role partners with stakeholders across the enterprise to improve asset and scan coverage, translate security findings into actionable remediation guidance, and strengthen the organization's overall security posture through measurable risk reduction.
Responsibilities
- Own the CTEM lifecycle scoping, discovery, prioritization, validation, and mobilization — across cloud, on-prem, and hybrid environments, aligning practices to the CTEM framework.
- Administer and optimize vulnerability scanning platforms (e.g., Tenable, Qualys, Rapid7,), including scan policy design, credential scanning, agent deployment, and coverage gap analysis.
- Integrate scanning and exposure data into ticketing, SIEM, CMDB, and GRC platforms to automate workflows and reduce manual triage.
- Monitor vulnerability and exposure management activity, analyze scanner findings and threat intelligence, and support timely investigation, remediation, exception review, and validation of risk reduction efforts.
- Conduct security assessments, control reviews, and scan coverage reviews to evaluate effectiveness, identify improvement opportunities, reduce false positives, and validate remediation outcomes.
- Partner with business, infrastructure, cloud, application, and technology stakeholders to document findings, develop remediation plans, and implement solutions that reduce exploitable risk across the enterprise.
- Provide guidance and consultation on vulnerability remediation, exposure management practices, scanning standards, risk prioritization, and security control expectations.
- Develop and maintain vulnerability management procedures, scanning standards, remediation guidance, dashboards, reports, and technical documentation that support consistent program execution.
- Participate in risk assessments, audits, and continuous improvement initiatives by supplying vulnerability evidence, monitoring remediation progress, and recommending enhancements to tools, workflows, and reporting.
- Performs additional responsibilities consistent with the scope and level of the role, as assigned
Requirements
- 5+ years of related IT Security professional experience.
- Bachelor’s degree; in lieu of a degree, an additional two years of relevant experience beyond the qualifications listed above may be accepted.
- Experience building or maturing a CTEM/vulnerability management program from the ground up.
- Experience administering or supporting vulnerability scanning, assessment, endpoint, cloud security, or exposure management technologies.
- Knowledge of security standards, frameworks, regulatory requirements, vulnerability remediation lifecycles, and scan validation practices.
- Ability to communicate complex topics clearly and concisely, actively listen to anticipate stakeholder needs, and align others to drive informed decisions.
- Ability to analyze complex information, evaluate options, and work cross-functionally to drive resolution and prevent recurrence.
- Ability to effectively organize work, balance competing priorities, and manage time across complex assignments and competing deadlines.
- Microsoft Certified Azure Fundamentals (AZ-900) - Microsoft
- Certified Cloud Security Professional (CCSP) - International Information System Security Certification Consortium (ISC2)
- Certified Information Systems Security Professional (CISSP) - International Information System Security Certification Consortium (ISC2)
- Amazon AWS Cloud Practitioner - Amazon
Skills
Required
- Communication
- Active listening
- Stakeholder alignment
- Analytical thinking
- Cross-functional collaboration
- Organization
- Time management
- CTEM framework
- SIEM
- CMDB
- GRC platforms
- Cloud security
Benefits
- $102,400.00 - $138,300.00 - $174,200.00 Annual
- Pay is based on several factors which vary based on position, including skills, ability, and knowledge the selected individual is bringing to the specific job.
- Medical, dental, and vision insurance
- Life insurance
- 401k
- Paid Time Off (PTO)
- Volunteer Paid Time Off (VPTO)
- And more
- To discover more about what we have to offer, please review our benefits page.
About Blue Cross and Blue Shield of Minnesota
At Blue Cross and Blue Shield of Minnesota, we are committed to paving the way for everyone to achieve their healthiest life. We are looking for dedicated and motivated individuals who share our vision of transforming healthcare. As a Blue Cross associate, you are joining a culture that is built on values of succeeding together, finding a better way, and doing the right thing. If you are ready to make a difference, join us.