
Vulnerability Manager
Posted Sep 11

Posted Sep 11
This is a fully remote position, open to applicants in Canada, +1 more country.
β’ Design and manage the complete product vulnerability management process, which encompasses intake, triage, risk assessment, assignment, SLA tracking, exception handling, and closure verification.
β’ Take ownership of vulnerability management for FedRAMP 20x, ensuring continuous monitoring, machine-readable evidence, Key Security Indicator reporting, and POA&M lifecycle management.
β’ Establish vulnerability management practices for new products and services, including scan coverage, onboarding, SLAs, and reporting.
β’ Evaluate and prioritize vulnerability risk based on exploitability, exposure, asset criticality, and compensating controls.
β’ Facilitate remediation efforts with product engineering teams, escalate overdue Critical and High findings, and document time-bound risk acceptances.
β’ Automate processes related to triage, deduplication, enrichment, summarization, reporting, workflow, and evidence collection using scripting, workflow tools, and AI-assisted analysis.
β’ Define requirements for integrations involving scanners, ticketing systems, asset inventory, and dashboards; collaborate with Security Engineering during delivery and validate results.
β’ Manage program metrics including SLA attainment, mean time to remediate, vulnerability aging, backlog trends, scan and asset coverage, and exception volume.
β’ Present metrics to security and engineering leadership on a regular basis.
β’ Maintain up-to-date visibility into critical product exposure and outstanding vulnerabilities.
β’ Lead rapid response initiatives for actively exploited and zero-day vulnerabilities, including exposure assessment, mitigation tracking, and communication with stakeholders.
β’ Over 5 years of experience in vulnerability management, product security, or security operations, with direct responsibility for a vulnerability management process.
β’ Proven experience in designing and managing vulnerability management processes within a regulated or audited environment, maintaining them through assessment cycles.
β’ Familiarity with FedRAMP and NIST SP 800-53, covering aspects such as vulnerability scanning, flaw remediation, continuous monitoring, configuration management, and POA&M management.
β’ Hands-on experience with enterprise vulnerability and exposure management platforms, cloud security posture tools, container scanning, and software composition analysis.
β’ Practical automation skills, including proficiency in Python or equivalent scripting, workflow and reporting tools, and AI assistance.
β’ Capability to write technical requirements and collaborate with security engineering throughout the design, delivery, and acceptance phases.
β’ Understanding of CVSS, CISA Known Exploited Vulnerabilities (KEV), EPSS, and risk-based prioritization.
β’ Familiarity with cloud services, preferably AWS, as well as containers, Kubernetes, CI/CD, web applications, and APIs.
β’ Ability to drive remediation efforts across engineering teams without direct authority.
β’ Strong written and verbal communication skills to engage with engineers, executives, auditors, and customers.
β’ Must be based in North America.
β’ Flexibility, trust, and a culture of continual learning.
β’ Comprehensive employee care and support.
β’ Commitment to diversity and inclusion.
Vanderlande
Vanderlande
Vanderlande
Vanderlande
Get handpicked remote jobs straight to your inbox weekly.