Vulnerability & Exposure Management Engineer
Datavant
Datavant is the data collaboration platform trusted for healthcare. Guided by our mission to make the world’s health data secure, accessible and actionable, we provide critical data solutions for organizations across the healthcare ecosystem - including providers, health plans, researchers, and life sciences companies. From fulfilling a single patient’s request for their medical records to powering the AI revolution in healthcare, Datavanters are building the future of how data is connected and used to improve health.
By joining Datavant today, you’re stepping onto a driven and highly collaborative team that is passionate about creating transformative change in healthcare.
What We’re Looking For
A security engineer to help build and operate an engineering-driven vulnerability and exposure management program, focused on turning vulnerability data into actionable signals embedded in modern engineering workflows. This role emphasizes automation, practical risk reduction, and hands-on execution across application, cloud, and infrastructure environments. It is not primarily a ticket-tracking or audit-administration role, but a technical role contributing to scalable solutions.
What You Will Do
- Contribute to the design, implementation, and operation of Datavant’s vulnerability and exposure management capabilities, with a focus on reducing real exploit risk.
- Build and enhance automation and workflows that ingest, normalize, and prioritize vulnerability signals across multiple sources.
- Develop and improve engineer-facing dashboards and integrations that help teams understand and act on vulnerability risk.
- Work with product and engineering teams to assess vulnerability findings, explain exploitability and impact, and support practical remediation or mitigation approaches.
- Help embed vulnerability signals into existing engineering workflows (CI/CD, PRs, backlogs) to improve visibility and adoption.
- Support validation of remediation efforts to ensure exposure is meaningfully reduced.
- Assist in translating compliance and control requirements into scalable technical implementations.
- Support FedRAMP and other assessments by validating technical evidence and remediation outcomes.
- Execute technical projects that improve vulnerability visibility, prioritization, and risk reduction.
- Contribute to improving processes, tooling, and automation within the vulnerability management program.
What You Need to Succeed
- Solid technical experience in vulnerability management and application security, with hands-on exposure to assessing and prioritizing vulnerability findings.
- Demonstrated ability to build or automate technical workflows using scripting or programming languages such as Python or Go.
- Experience working with application, cloud, or container security in AWS and/or Azure environments.
- Working knowledge of security controls and compliance frameworks (e.g., NIST, CIS, FedRAMP), with the ability to apply requirements in practical engineering contexts.
- Ability to reason about exploitability, exposure, and impact beyond severity scores.
- Experience collaborating with engineering teams to support remediation efforts.
- Clear communication skills and ability to explain technical risk to varied audiences.
- Ability to operate effectively in fast-paced environments with evolving priorities.
- Foundational understanding of how vulnerability management fits within broader security and engineering functions.
- Experience with commercial security tooling (e.g., SAST, SCA, cloud security platforms) and ability to interpret tool outputs critically.
What Helps You Stand Out
- Experience building custom scripts, automations, or lightweight data pipelines to improve vulnerability visibility or prioritization.
- Exposure to highly regulated environments (e.g., healthcare, FedRAMP Moderate/High) and participation in technical audit preparation.
- Experience integrating vulnerability tooling into CI/CD pipelines or engineering workflows.
- Familiarity with cloud security platforms (e.g., Wiz) or security data tooling (e.g., Snowflake, Sigma).
- Experience using AI-assisted development tools (e.g., Claude Code) to accelerate security automation or analysis.
We are committed to building a diverse team of Datavanters who are all responsible for stewarding a high-performance culture in which all Datavanters belong and thrive. We are proud to be an Equal Employment Opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity, religion, national origin, disability, veteran status, or other legally protected status.
At Datavant our total rewards strategy powers a high-growth, high-performance, health technology company that rewards our employees for transforming health care through creating industry-defining data logistics products and services.
The range posted is for a given job title, which can include multiple levels. Individual rates for the same job title may differ based on their level, responsibilities, skills, and experience for a specific job.
To ensure the safety of patients and staff, many of our clients require post-offer health screenings and proof and/or completion of various vaccinations such as the flu shot, Tdap, COVID-19, etc. Any requests to be exempted from these requirements will be reviewed by Datavant Human Resources and determined on a case-by-case basis. Depending on the state in which you will be working, exemptions may be available on the basis of disability, medical contraindications to the vaccine or any of its components, pregnancy or pregnancy-related medical conditions, and/or religion.
This job is not eligible for employment sponsorship.
Datavant is committed to a work environment free from job discrimination. We are proud to be an Equal Employment Opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity, religion, national origin, disability, veteran status, or other legally protected status. To learn more about our commitment, please review our EEO Commitment Statement here. Know Your Rights, explore the resources available through the EEOC for more information regarding your legal rights and protections. In addition, Datavant does not and will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay.
At the end of this application, you will find a set of voluntary demographic questions. If you choose to respond, your answers will be anonymous and will help us identify areas for improvement in our recruitment process. (We can only see aggregate responses, not individual ones. In fact, we aren’t even able to see whether you’ve responded.) Responding is entirely optional and will not affect your application or hiring process in any way.
Datavant is committed to working with and providing reasonable accommodations to individuals with physical and mental disabilities. If you need an accommodation while seeking employment, please request it here, by selecting the ‘Interview Accommodation Request’ category. You will need your requisition ID when submitting your request, you can find instructions for locating it here. Requests for reasonable accommodations will be reviewed on a case-by-case basis.
For more information about how we collect and use your data, please review our Privacy Policy.