
Senior Manager, Cybersecurity, CTEM & Vulnerability Intelligence
Posted Sep 14

Posted Sep 14
This is a fully remote position, open to applicants in Michigan.
• Lead the enterprise CTEM and Vulnerability Management program, encompassing its strategy, roadmap, and operational framework.
• Supervise vulnerability scanning and assessment across various domains, including infrastructure, cloud, endpoints, applications, identity, network, and OT environments.
• Oversee the product security vulnerability lifecycle, which includes intake, triage, risk assessment, remediation tracking, SBOM analysis, and coordinated vulnerability disclosure support.
• Prioritize vulnerabilities and exposures by utilizing CVSS, EPSS, CISA KEV, threat intelligence, asset criticality, and business context.
• Direct attack surface management, exposure validation, and breach and attack simulation initiatives.
• Assess emerging vulnerabilities, exploits, and threat intelligence that impact enterprise systems, marketed products, and embedded systems.
• Propel automation for vulnerability discovery, data enhancement, ticketing, remediation workflows, and reporting.
• Assist in cyber incident investigations by providing vulnerability context, exposure analysis, and remediation expertise.
• Collaborate with technical teams to establish risk-based service-level agreements, drive remediation efforts, and monitor plans of action and milestones.
• Develop governance standards, quality assurance processes, and documentation.
• Measure and communicate exposure reduction, remediation performance, validation outcomes, and operational metrics to executive stakeholders.
• Manage vulnerability management, exposure management, or product security vulnerability teams.
• Analyze intricate vulnerability data and exposure telemetry to identify risks and inform responses.
• Convert technical findings, remediation statuses, and risk trends into updates for both technical and executive audiences.
• Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
• At least 10 years of experience in cybersecurity.
• A minimum of 3 years of experience leading vulnerability management, exposure management, or product security vulnerability teams.
• Proven experience managing product vulnerabilities, including triage, coordinated vulnerability disclosure, SBOM analysis, and remediation with product engineering teams.
• Familiarity with Tenable, Qualys, Rapid7, Wiz, ServiceNow Vulnerability Response, or similar vulnerability and exposure management technologies.
• Experience in implementing automation through SOAR platforms, APIs, Python, or PowerShell.
• Preferred: Master's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
• Preferred: CISSP, CISM, GEVA, GPEN, GIAC, Tenable, Qualys, or equivalent professional certification.
• Remote work flexibility.
• Equal opportunity employment.
• No travel required.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.