
Vulnerability Manager
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Develop, implement, and continually enhance the enterprise vulnerability management program.
• Establish and uphold vulnerability management policies, standards, procedures, and governance processes.
• Define remediation priorities based on risk, taking into account asset criticality, exploitability, threat intelligence, and business impact.
• Lead vulnerability review sessions and remediation governance discussions.
• Create vulnerability management roadmaps and initiatives for improving maturity.
• Oversee vulnerability scanning across servers, workstations, network devices, cloud platforms, containers, applications, and databases.
• Validate and triage identified vulnerabilities to minimize false positives.
• Evaluate vulnerability severity using CVSS, threat intelligence, exploit availability, and environmental considerations.
• Monitor emerging threats, zero-day vulnerabilities, and relevant security advisories.
• Coordinate remediation efforts with IT Operations, Infrastructure, Engineering, Cloud, and Development teams.
• Establish timelines for remediation and service-level objectives.
• Track remediation progress against set metrics.
• Manage exception handling processes and risk acceptance workflows.
• Escalate critical vulnerabilities and overdue remediation items to leadership.
• Manage vulnerability scanning and management platforms, including Tenable, Microsoft Defender Vulnerability Management, and Wiz.
• Ensure effective scanning coverage, tuning, maintenance, and integration.
• Develop executive dashboards and operational reports.
• Report on vulnerability trends, the effectiveness of remediation, and progress in reducing exposure.
• Track and report on KPIs and KRIs.
• Support enterprise risk management initiatives.
• Assess vulnerabilities within the context of business risk.
• Facilitate risk-based decisions concerning remediation versus risk acceptance.
• Align vulnerability management activities with regulatory and security frameworks.
• Incorporate both internal and external threat intelligence into vulnerability prioritization.
• Monitor the CISA Known Exploited Vulnerabilities catalog and other threat intelligence sources.
• Prioritize remediation efforts based on current exploitation trends.
• Mentor and guide junior professional contributor staff.
• Collaborate across functions to address complex organizational challenges and implement changes.
• Bachelor’s Degree directly related to the position or an equivalent qualification is preferred.
• A minimum of five years of experience is required.
• At least three years of supervisory or leadership experience is necessary.
• Ability to organize and manage multiple priorities simultaneously.
• Ability to work independently or as part of a team.
• Excellent interpersonal communication skills are essential.
• Ability to handle confidential matters with discretion.
• Outstanding verbal and written communication skills.
• Highly organized and detail-oriented.
• Ability to thrive in a fast-paced, metrics-driven environment.
• Proficiency in Microsoft Office Suite, including Word, Excel, Wiki, collaborative cloud-based programs, and third-party software applications.
• Ability to adhere to process protocols and apply established procedures in a timely manner.
• Capability to operate standard office equipment and keyboards.
• Ability to accurately interpret sounds and associated meanings at interpersonal conversation volume.
• Willingness to travel 5% or less.
• Commitment to upholding company values.
• Medical insurance.
• Dental insurance.
• Vision insurance.
• Life insurance.
• AD&D insurance.
• LTD insurance.
• 401(k) with employer match.
• Pleasant work environment.
• Competitive compensation.
AbbVie
Seed Health
CAPTRUST
Get handpicked remote jobs straight to your inbox weekly.