Vulnerability Manager

Vulnerability Manager

Vollzeit Homeoffice möglich
J
  • Design and operate the product vulnerability management process end to end, including intake, triage, risk assessment, assignment, SLA tracking, exception handling, and closure verification
  • Own vulnerability management for FedRAMP 20x, including continuous monitoring, machine-readable evidence, Key Security Indicator reporting, and POA&M lifecycle management
  • Establish vulnerability management for new products and services, including scan coverage, onboarding, SLAs, and reporting
  • Assess and rank vulnerability risk using exploitability, exposure, asset criticality, and compensating controls
  • Drive remediation with product engineering teams, escape overdue Critical and High findings, and record time-bound risk acceptances
  • Automate triage, deduplication, enrichment, summarization, reporting, workflow, and evidence collection using scripting, workflow tooling, and AI-assisted analysis
  • Define requirements for integrations involving scanners, ticketing, asset inventory, and dashboards; partner with Security Engineering through delivery and validate outcomes
  • Own program metrics including SLA attainment, mean time to remediate, vulnerability aging, backlog trend, scan and asset coverage, and exception volume
  • Report metrics to security and engineering leadership on a fixed cadence
  • Maintain current visibility into critical product exposure and open vulnerabilities
  • Lead rapid response for actively exploited and zero-day vulnerabilities, including exposure assessment, mitigation tracking, and stakeholder communication

Requirements

  • 5+ years in vulnerability management, product security, or security operations, with direct ownership of a vulnerability management process
  • Experience designing and operating vulnerability management processes in a regulated or audited environment and sustaining them through assessment cycles
  • Working knowledge of FedRAMP and NIST SP 800-53, including vulnerability scanning, flaw remediation, continuous monitoring, configuration management, and POA&M management
  • Hands-on experience with enterprise vulnerability and exposure management platforms, cloud security posture tooling, container scanning, and software composition analysis
  • Practical automation skills, including Python or equivalent scripting, workflow and reporting tooling, and AI assistants
  • Ability to write technical requirements and partner with security engineering through design, delivery, and acceptance
  • Understanding of CVSS, CISA Known Exploited Vulnerabilities (KEV), EPSS, and risk-based prioritization
  • Working knowledge of cloud services, AWS preferred, containers, Kubernetes, CI/CD, web applications, and APIs
  • Ability to drive remediation across engineering teams without direct authority
  • Clear written and verbal communication with engineers, executives, auditors, and customers
  • Must be North America based

Core Competencies

Demonstrates expertise in vulnerability management processes, including risk assessment, remediation, and automation. Proficient in leveraging cloud security tools and frameworks such as FedRAMP and NIST SP 800-53 to ensure compliance and effective vulnerability handling.

Highest-signal resume keywords

  • Vulnerability Management Process Ownership
  • FedRAMP Compliance
  • Python Scripting
  • Risk Assessment and Prioritization
  • Cloud Security Posture Management

Hard Skills

  • Vulnerability Management
  • Risk Assessment
  • Automation
  • Scripting
  • Vulnerability Scanning
  • Configuration Management
  • Continuous Monitoring
  • Flaw Remediation
  • Technical Requirements Writing
  • Cloud Security

Soft Skills

  • Clear Communication
  • Collaboration
  • Stakeholder Engagement
  • Problem Solving
  • Leadership

Industry Keywords

  • FedRAMP
  • NIST SP 800-53
  • CVSS
  • CISA Known Exploited Vulnerabilities
  • EPSS
  • CI/CD
  • Kubernetes
  • APIs
  • Web Applications
  • Asset Inventory

Tools & Technologies

  • Enterprise Vulnerability Management Platforms
  • Cloud Security Posture Tools
  • Container Scanning Tools
  • Software Composition Analysis Tools
  • Workflow Tooling

#J-18808-Ljbffr

Vulnerability Manager Arbeitgeber: Jobtailor

Als Front Office Supervisor in unserem dynamischen Team bieten wir Ihnen die Möglichkeit, in einem unterstützenden und freundlichen Arbeitsumfeld zu wachsen. Wir legen großen Wert auf die berufliche Entwicklung unserer Mitarbeiter und bieten regelmäßige Schulungen sowie die Chance, Verantwortung zu übernehmen. Unsere Lage ermöglicht es Ihnen, Teil einer lebendigen Gemeinschaft zu sein, während Sie gleichzeitig die Standards unseres Franchise-Partners einhalten und unseren Gästen einen unvergesslichen Aufenthalt bieten.

J

Kontaktdaten:

Jobtailor Recruiting-Team