Compensation: $170-210k base
No visa sponsorship and candidates MUST be local
Responsibilities:
Develop and lead the enterprise vulnerability management strategy, roadmap, and program.
Act as delegate sponsor for the Vulnerability Management project as part of the Information Security Transformation program.
Oversee vulnerability scanning, risk assessments, and prioritization processes across infrastructure, applications, containers, and cloud environments and critical third parties.
Manage vulnerability management platforms and ensure optimal configuration, tuning, and coverage.
Partner with Technology, cloud, SecOps, CTI, application teams, and asset owners to drive remediation and track progress.
Provide threat-based prioritization of vulnerabilities using CVSS, threat intelligence, exploitability data, and business context.
Lead the response to high-profile vulnerabilities (e.g., zero-days, critical CVEs) with timely impact analysis and coordinated remediation actions.
Develop and present executive-level reporting on vulnerability trends, KRIs, KPIs, and risk posture.
Maintain compliance with relevant standards and frameworks (e.g., NIST CSF, ISO 27001).
Own governance for exception handling and risk acceptance processes related to un-remediated vulnerabilities.
Lead, mentor, and grow a team of vulnerability analysts, engineers, and program managers.
Qualifications:
Required
Bachelor's degree or higher in Computer Science, Information Security, Engineering, or related field.
10 years of experience in cybersecurity, with at least 5 years in a leadership or management capacity.
Proven experience building or leading a mature vulnerability management program at scale.
Deep understanding of vulnerability scanning technologies, CVSS scoring, and threat modelling.
Strong knowledge of cloud platforms (AWS, Azure), and container security.
Familiarity with compliance frameworks and standards (NIST, ISO, etc.).
Experience managing and mentoring technical teams and working cross-functionally with non-security teams.
Excellent communication and stakeholder engagement skills with the ability to convey complex risk topics to executive audiences.
Preferred
Relevant certifications (e.g., CISSP, CISM, OSCP, or similar).
Experience integrating vulnerability management with SIEM, ticketing, and asset management tools.
Strong understanding of risk management and cyber risk quantification.
APPLY NOW
Loading...