Description
Key Skills: Vulnerability Management, Cybersecurity, Qualys VMDR, Tenable.io, Linux, Windows, Python, PowerShell, Bash, REST APIs
Good to Have Skills: Security certifications such as Security+, SSCP, CCSP, CySA+, PenTest+, or Cloud+. Experience with AI-assisted prioritization and analytics in vulnerability management processes. Familiarity with penetration testing methodologies and validation of remediation effectiveness. Experience operating within regulated environments and supporting audit evidence for vulnerability management controls. Background in cloud security across AWS, Azure, and GCP. Knowledge of security frameworks and standards such as NIST CSF, ISO 27001, and OWASP Top 10.
Roles & Responsibilities:
- Provide direct technical leadership and day-to-day oversight to Vulnerability Management Analysts, ensuring timely, accurate, and risk-based vulnerability identification and remediation.
- Own and manage vulnerability management operations across infrastructure, applications, and cloud environments, including scanning, validation, prioritization, and remediation tracking.
- Serve as a key execution partner and escalation point for U.S.-based Vulnerability Management leadership, ensuring continuity of operations and alignment with global program objectives.
- Design, optimize, and maintain vulnerability scanning strategies, including scan schedules, asset inventories, tagging, authentication, and policy tuning to maximize coverage and reduce false positives.
- Translate large-scale vulnerability data into actionable risk intelligence through automated analytics, dashboards, and reporting aligned to business impact and risk tolerance.
- Drive risk-based prioritization of vulnerabilities using exploitability, threat intelligence, asset criticality, and compensating controls rather than CVSS scores alone.
- Partner with IT, infrastructure, cloud, and application owners to communicate findings, recommend remediation strategies, and influence timely risk reduction decisions.
- Track remediation progress, ownership, exceptions, and end-of-life risks, ensuring transparency and accountability across the enterprise.
- Develop, maintain, and continuously improve vulnerability management runbooks, playbooks, and workflows to ensure operational consistency, audit readiness, and scalability.
- Lead vulnerability assessments and support penetration testing activities, translating findings into prioritized remediation actions and validating risk reduction.
- Monitor emerging threats, zero-day vulnerabilities, and regulatory changes, integrating lessons learned into improved detection, prevention, and response processes.
- Promote automation, AI-assisted prioritization, and continuous improvement across vulnerability management workflows.
- Mentor and develop vulnerability analysts, strengthening technical depth, risk analysis capability, and stakeholder engagement skills.
- Provide advanced escalation support for complex vulnerability findings, tool issues, and remediation challenges.
Experience Required: 9+ years of experience in cybersecurity, with a strong focus on vulnerability management, security operations, or risk-based security programs. Proven experience leading or acting as a technical lead for vulnerability management or security operations teams in a global enterprise environment.
Education: Bachelor's degree in computer science, Cybersecurity, Information Technology, or equivalent practical experience