Security Engineer Sr.
bcbsmn · Eagan, MN · United States · On-site
Pay: USD 102,400 – 138,300 a year
Posted Sep 23, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
About Blue Cross and Blue Shield of Minnesota
At Blue Cross and Blue Shield of Minnesota, we are committed to paving the way for everyone to achieve their healthiest life. We are looking for dedicated and motivated individuals who share our vision of transforming healthcare. As a Blue Cross associate, you are joining a culture that is built on values of succeeding together, finding a better way, and doing the right thing. If you are ready to make a difference, join us.
The Impact You'll Have

The Senior Security Engineer supports the organization's security program by reducing enterprise exposure through effective vulnerability management, exposure management, and engineering of security scanning capabilities. This role helps identify, validate, prioritize, and drive remediation of vulnerabilities, misconfigurations, and control gaps across technology and business environments. The position implements, monitors, and improves vulnerability scanning tools, security controls, and related processes that protect organizational assets and support compliance, risk management, and operational objectives. The role partners with stakeholders across the enterprise to improve asset and scan coverage, translate security findings into actionable remediation guidance, and strengthen the organization's overall security posture through measurable risk reduction.

 What You'll Do
Own the CTEM lifecycle scoping, discovery, prioritization, validation, and mobilization — across cloud, on-prem, and hybrid environments, aligning practices to the CTEM framework.
Administer and optimize vulnerability scanning platforms (e.g., Tenable, Qualys, Rapid7,), including scan policy design, credential scanning, agent deployment, and coverage gap analysis.
Integrate scanning and exposure data into ticketing, SIEM, CMDB, and GRC platforms to automate workflows and reduce manual triage.
Monitor vulnerability and exposure management activity, analyze scanner findings and threat intelligence, and support timely investigation, remediation, exception review, and validation of risk reduction efforts.
Conduct security assessments, control reviews, and scan coverage reviews to evaluate effectiveness, identify improvement opportunities, reduce false positives, and validate remediation outcomes.
Partner with business, infrastructure, cloud, application, and technology stakeholders to document findings, develop remediation plans, and implement solutions that reduce exploitable risk across the enterprise.

 How You'll Do It
Provide guidance and consultation on vulnerability remediation, exposure management practices, scanning standards, risk prioritization, and security control expectations.
Develop and maintain vulnerability management procedures, scanning standards, remediation guidance, dashboards, reports, and technical documentation that support consistent program execution.
Participate in risk assessments, audits, and continuous improvement initiatives by…