Boehringer Ingelheim logo
Boehringer Ingelheim · Life sciences

Principal Systems Engineer 1 1

Boehringer Ingelheim Phil, NA Posted Sep 22, 2026
Location
Phil, NA
Workplace
On-site / per employer
Posted
Sep 22, 2026

About this role

The Position Join Boehringer Ingelheim's Cyber Intelligence & Security Operations Center (CISOC) as a Network Vulnerability Management Engineer. In this role, you will serve as the technical owner and subject matter expert for the organization's network vulnerability management platform, ensuring effective identification, assessment, reporting, and remediation of infrastructure vulnerabilities across the enterprise. You will combine platform ownership responsibilities with hands-on technical analysis, working closely with infrastructure teams, System Leads, remediation teams, and service management stakeholders to strengthen BI's security posture through continuous improvement of vulnerability management processes and technologies.

Duties & Responsibilities As a member of the Cyber Intelligence & Security Operations Center (CISOC) team, the role will be responsible for technical ownership, operation and continuous improvement of network vulnerability management. The system mainly supports internal network vulnerability scanning and the reporting of identified vulnerabilities. The engineer will combine platform ownership with hands-on technical vulnerability analysis.

Key responsibilities: System Lead role, including service roadmap, lifecycle, configuration standards, access governance, documentation and continuous improvement. Administer and maintain the vulnerability-management platform, including scanners, scanning scope, schedules, asset inventory, tags, authentication and scan quality. Plan and monitor regular internal network vulnerability scans and investigate coverage gaps, failed scans, authentication issues and unexpected results.

Analyse vulnerability findings in technical depth and validate whether detections are true positives or false positives, documenting clear evidence and rationale. Assess vulnerability severity, exploitability, exposure and business context to support prioritisation and escalation decisions. Drive the vulnerability reporting process, ensuring findings are correctly enriched, assigned, tracked and communicated to System Leads and remediation teams.

Coordinate rescans and verification activities to confirm remediation or support exception and false-positive decisions. Develop and maintain Python automation for platform administration, data processing, quality checks, enrichment, reporting and workflow improvement. Collaborate with ITSM stakeholders to improve vulnerability-ticket creation, assignment, lifecycle, integrations and reporting.

Act as technical escalation point for vulnerability-management issues and coordinate vendor support cases when required. Follow BI processes and maintain the required operational, compliance and audit documentation. Requirements: An ideal candidate will have Strong hands-on experience in infrastructure or network vulnerability management and technical vulnerability assessment.

Practical experience with Qualys VMDR, Qualys Vulnerability Management or a comparable enterprise vulnerability-scanning platform. Ability to investigate findings and prove false positives or true positives using technical evidence, including service, version, configuration and network analysis. Solid knowledge of TCP/IP, operating systems, network services, authentication, asset discovery, vulnerability identifiers and remediation principles.

Python experience for automation, API integration, data analysis and reporting. Experience managing a security platform as System Lead, service owner or senior technical administrator is highly desirable. ServiceNow Vulnerability Response, SecOps or general ServiceNow knowledge is highly valuable but not mandatory.

Strong analytical, troubleshooting, documentation and problem-solving skills. Excellent spoken and written English and experience working in an international, multicultural environment. Relevant security certifications are desirable but not mandatory.

Originally posted by Boehringer Ingelheim. View original posting

Principal Systems Engineer 1 1 at Boehringer Ingelheim | BioCareerAI