Company Description
Work with Us. Change the World.
At AECOM, we're delivering a better world. Whether improving your commute, keeping the lights on, providing access to clean water, or transforming skylines, our work helps people and communities thrive. We are the world's trusted infrastructure consulting firm, partnering with clients to solve the world’s most complex challenges and build legacies for future generations.
There has never been a better time to be at AECOM. With accelerating infrastructure investment worldwide, our services are in great demand. We invite you to bring your bold ideas and big dreams and become part of a global team of over 50,000 planners, designers, engineers, scientists, digital innovators, program and construction managers and other professionals delivering projects that create a positive and tangible impact around the world.
We're one global team driven by our common purpose to deliver a better world. Join us.
Job Description
We are seeking a skilled and motivated professional to join the Qualys support function within the Cybersecurity Engineering team, with an initial focus on reporting and External Attack Surface Management (EASM). This role supports the operation and optimization of the Qualys platform—particularly EASM, CyberSecurity Asset Management (CSAM), and VMDR—to provide accurate visibility, actionable insights, and high-quality reporting that enable effective vulnerability remediation across the enterprise.
While the specific Qualys modules supported by this role may evolve over time, enterprise reporting and risk visibility remain core to the position. This is a senior individual contributor role, requiring deep technical expertise, sound judgment, and the ability to operate independently while influencing outcomes across Cybersecurity, IT, and Executive stakeholders.
This position will offer some flexibility for hybrid work schedules to include both in-office presence and telecommute/virtual work to be based in either Houston or Dallas, TX.
Key Responsibilities:
- Serve as a subject-matter expert for Qualys reporting and risk visibility, providing guidance and support to Cybersecurity, IT Infrastructure, and Executive stakeholders.
- Partner with infrastructure, cloud, and application teams to support remediation efforts by providing accurate data, context, and reporting from the Qualys platform.
- Develop, maintain, and deliver clear, audience-specific reports and dashboards for IT Infrastructure teams, Software Governance, Cybersecurity teams, IT leadership, and Executive leadership.
- Support and optimize Qualys EASM and CSAM to provide accurate visibility into the organization’s external attack surface, including identifying, analyzing, and helping prioritize externally exposed vulnerabilities and risks to enable effective remediation.
- Support and maintain Qualys integrations with ServiceNow to enable accurate vulnerability intake, workflow routing, remediation tracking, and reporting.
- Serve as secondary support for Qualys platform operations, backing up another Cybersecurity Engineering resource and assisting with VMDR configuration, integrations, upgrades, and troubleshooting.
- Expand Qualys reporting and risk-visibility capabilities over time to support additional modules (e.g., TotalCloud, TotalAppSec, and Software Composition Analysis (SCA)) as organizational needs and platform maturity evolve.
- Drive continuous improvements to processes, environments, and overall security posture, ensuring operational efficiency and risk reduction.
Qualifications
Minimum Requirements:
- Bachelor’s degree (BA/BS) and at least 6 years of experience in cybersecurity, IT security, or a related field or demonstrated equivalency of experience and/or education
- Hands-on experience supporting Qualys in an enterprise environment, specifically EASM, CSAM, and VMDR.
- Strong experience with vulnerability data analysis, reporting, and remediation support.
- Demonstrated ability to translate technical data into clear, actionable insights for varied audiences.
- Strong analytical, problem-solving, and communication skills.
- Ability to work independently while collaborating effectively across cross-functional teams.
Preferred Qualifications
- Qualys certifications (e.g., Qualys EASM Specialist, Qualys VMDR Specialist).
- Experience with, or demonstrated interest in expanding into, additional Qualys modules such as TotalCloud, TotalAppSec, or SCA.
- Direct experience supporting IT infrastructure teams (e.g., server, network, cloud, or platform operations), enabling effective collaboration and practical, context-aware support.
- Broader cybersecurity experience outside of vulnerability management (e.g., network security, security architecture, cloud security, or security operations).
- Experience integrating Qualys with ServiceNow (e.g., vulnerability intake, ticket creation, workflow automation, or reporting).
- Industry certifications such a