Security Engineer Sr.
Hybrid | Eagan, MinnesotaAt Blue Cross and Blue Shield of Minnesota, we are committed to paving the way for everyone to achieve their healthiest life. We are looking for dedicated and motivated individuals who share our vision of transforming healthcare. As a Blue Cross associate, you are joining a culture that is built on values of succeeding together, finding a better way, and doing the right thing. If you are ready to make a difference, join us.
The Impact You Will Have
The Senior Security Engineer supports the organization's security program by reducing enterprise exposure through effective vulnerability management, exposure management, and engineering of security scanning capabilities. This role helps identify, validate, prioritize, and drive remediation of vulnerabilities, misconfigurations, and control gaps across technology and business environments. The position implements, monitors, and improves vulnerability scanning tools, security controls, and related processes that protect organizational assets and support compliance, risk management, and operational objectives. The role partners with stakeholders across the enterprise to improve asset and scan coverage, translate security findings into actionable remediation guidance, and strengthen the organization's overall security posture through measurable risk reduction.
What You’ll Do
- Own the CTEM lifecycle scoping, discovery, prioritization, validation, and mobilization — across cloud, on-prem, and hybrid environments, aligning practices to the CTEM framework.
- Administer and optimize vulnerability scanning platforms (e.g., Tenable, Qualys, Rapid7,), including scan policy design, credential scanning, agent deployment, and coverage gap analysis.
- Integrate scanning and exposure data into ticketing, SIEM, CMDB, and GRC platforms to automate workflows and reduce manual triage.
- Monitor vulnerability and exposure management activity, analyze scanner findings and threat intelligence, and support timely investigation, remediation, exception review, and validation of risk reduction efforts.
- Conduct security assessments, control reviews, and scan coverage reviews to evaluate effectiveness, identify improvement opportunities, reduce false positives, and validate remediation outcomes.
- Partner with business, infrastructure, cloud, application, and technology stakeholders to document findings, develop remediation plans, and implement solutions that reduce exploitable risk across the enterprise.
How You’ll Do It
- Provide guidance and consultation on vulnerability remediation, exposure management practices, scanning standards, risk prioritization, and security control expectations.
- Develop and maintain vulnerability management procedures, scanning standards, remediation guidance, dashboards, reports, and technical documentation that support consistent program execution.
- Participate in risk assessments, audits, and continuous improvement initiatives by supplying vulnerability evidence, monitoring remediation progress, and recommending enhancements to tools, workflows, and reporting.
- Performs additional responsibilities consistent with the scope and level of the role, as assigned
Required Skills & Experience
- 5+ years of related IT Security professional experience.
- Bachelor’s degree; in lieu of a degree, an additional two years of relevant experience beyond the qualifications listed above may be accepted.
Preferred Skills & Experience
- Experience building or maturing a CTEM/vulnerability management program from the ground up.
- Experience administering or supporting vulnerability scanning, assessment, endpoint, cloud security, or exposure management technologies.
- Knowledge of security standards, frameworks, regulatory requirements, vulnerability remediation lifecycles, and scan validation practices.
- Ability to communicate complex topics clearly and concisely, actively listen to anticipate stakeholder needs, and align others to drive informed decisions.
- Ability to analyze complex information, evaluate options, and work cross-functionally to drive resolution and prevent recurrence.
- Ability to effectively organize work, balance competing priorities, and manage time across complex assignments and competing deadlines.
Licensure/Certifications
Preferred -
Microsoft Certified Azure Fundamentals (AZ-900) - Microsoft
Certified Cloud Security Professional (CCSP) - International Information System Security Certification Consortium (ISC2)
Certified Information Systems Security Professional (CISSP) - International Information System Security Certification Consortium (ISC2)
Amazon AWS Cloud Practitioner - Amazon
Role Designation
Hybrid
Anchored in Connection
Our hybrid approach is designed to balance flexibility with meaningful in-person connection and collaboration. We come together in the office two days each week – most teams designate at least one anchor day to ensure team interaction. These in-person moments foster relationships, creativity, and alignment. The rest of the week you are empowered to work remote.
Compensation and Benefits:
Pay Range: $102,400.00 - $138,300.00 - $174,200.00 Annual
Pay is based on several factors which vary based on position, including skills, ability, and knowledge the selected individual is bringing to the specific job.
We offer a comprehensive benefits package which may include:
- Medical, dental, and vision insurance
- Life insurance
- 401k
- Paid Time Off (PTO)
- Volunteer Paid Time Off (VPTO)
- And more
To discover more about what we have to offer, please review our benefits page.
Equal Employment Opportunity StatementAt Blue Cross and Blue Shield of Minnesota, we are committed to paving the way for everyone to achieve their healthiest life. Blue Cross of Minnesota is an Equal Opportunity Employer and maintains an Affirmative Action plan, as required by Minnesota law applicable to state contractors. All qualified applications will receive consideration for employment without regard to, and will not be discriminated against based on any legally protected characteristic.
Individuals with a disability who need a reasonable accommodation in order to apply, please contact us at: talent.acquisition@bluecrossmn.com.
Blue Cross® and Blue Shield® of Minnesota and Blue Plus® are nonprofit independent licensees of the Blue Cross and Blue Shield Association.
Meet Your Talent Advisor
Grant Friemel
Join our Talent Community
Be the first to know when new opportunities become available by joining our Talent Community.
- Security Engineer Sr. Eagan, Minnesota
- Senior AI Engineer Eagan, Minnesota
- Associate Data Engineer Eagan, Minnesota