Sr. Security Engineer, Vulnerability Management at Highmark Health
Denver, CO
$102,700–$164,600from the description
Jul 28, 2026
Denver, CO
Jul 29, 2026
What this job asks for AI summary
A senior-level cybersecurity engineering role at Highmark Health (enGen) focused on enterprise vulnerability management and secure configuration management. The position involves designing and implementing security controls across cloud, on-premises, endpoint, network, and containerized environments, driving automation and orchestration to improve threat visibility and remediation, and mentoring junior staff. Candidates must be US citizens due to contractual access requirements.
Senior level · 7+ years · Pittsburgh, PA · Bachelor's required · Full-time
Posted 9 times — it's one opening, so apply once.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 1 people in the Pittsburgh, PA area plausibly meet what this posting asks for (information security analysts). range 1–1
Applicant volume Light — Few people clear these requirements, so an application that does clear them gets looked at. Worth applying to even if you miss a nice-to-have.
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $105,909 (middle half $83,067–$132,910). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 29, 2026. It is a model, not a headcount.
Why we read it this way (9)
The role title is 'Cybersecurity Engineer' with no explicit seniority level in the title; however, the posting frames it as a 'lead Security Engineer' role requiring 7 years of required experience and 10 years preferred — consistent with a Senior-level individual contributor.
The alt SOC (15-1252 Software Developers) is noted because the posting places significant emphasis on scripting, automation, orchestration, system integrations, and API development, which lean toward engineering/development work; however, the primary day-to-day focus on vulnerability management, configuration management, and security controls analysis makes 15-1212 the better fit.
The required experience section lists 7-year minimums across multiple parallel domains (Information Security, OS/Software Administration, IPS/firewalls/endpoint/SIEM, etc.); the overall years minimum is set to 7 as the hard floor stated in the Required section.
The preferred experience section calls out 10 years in Information Security and 5+ years in Vulnerability/Secure Configuration Management engineering — these are preferred, not required gates.
NIST 800-53 is listed in the Skills section as 'NIST 800-83' which appears to be a typo in the posting; extracted as NIST 800-53 (the standard cybersecurity framework).
The posting states 'CANDIDATE MUST BE US Citizen' due to contractual/access requirements — this is a hard citizenship gate, not a security clearance; the clearance requirement is set to None as no formal US government clearance level is specified.
The pay range ($102,700–$164,600/year) is stated as base pay and explicitly notes it does not reflect geographic differentials.
Location is inferred as Pittsburgh, PA based on Highmark Health's headquarters; the posting does not explicitly state a city.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Secure Configuration Management.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.