
Vulnerability Program Manager
Posted Aug 21

Posted Aug 21
This is a fully remote position, open to applicants in United States.
• Take charge of the complete vulnerability management and patching program, encompassing asset discovery, scanning, prioritization, remediation tracking, verification, and reporting.
• Establish and document the frequency of scans, cadence for patching, targets for remediation, exception handling procedures, and criteria for emergency out-of-band work.
• Develop and sustain a program RACI, involving Vulnerability Analysts, security engineering, service desk, and clients.
• Create HaloPSA ticket types, templates, and workflows to ensure consistent operations and evidence documentation.
• Conduct regular vulnerability management reviews for designated clients and maintain prioritized remediation backlogs.
• Facilitate remediation efforts among NetCov delivery teams and client personnel in relation to change windows and maintenance schedules.
• Oversee exclusions, suppressions, and risk acceptances with documented justifications, responsible parties, and review timelines.
• Act as the escalation point for zero-day vulnerabilities and those actively being exploited that necessitate out-of-cycle patching.
• Manage client-facing reports, aging and trend analyses, and executive summaries.
• Communicate program status to client stakeholders and convert scan results into risk assessments, progress updates, and necessary actions for clients.
• Assist clients with requests for audit and compliance evidence.
• Collaborate with Client Success and account teams during onboarding, escalations, and contract renewals.
• Oversee the configuration and health of vulnerability tools, scanner coverage, credentialed scanning, agent deployment, and accuracy of asset inventory.
• Integrate scanning, ticketing, and patching platforms with security engineering efforts.
• Promote data quality enhancements and automation opportunities.
• Define and report on program metrics, including SLA adherence, vulnerability age, patch compliance, scan coverage, and recurring findings.
• Train and mentor Vulnerability Analysts and delivery personnel.
• Contribute to the development of vulnerability management service offerings.
• Perform additional duties as assigned.
• Proven experience managing vulnerability and patching processes in a multi-client or multi-environment context, preferably within an MSP or MSSP.
• Practical expertise with vulnerability management and patching tools such as InsightVM, ConnectSecure, NinjaOne, Datto RMM, or similar platforms.
• Knowledge of PSA and workflow tools; familiarity with HaloPSA is preferred, including ticket design and reporting capabilities.
• Solid understanding of risk-based prioritization, including CVSS, exploit intelligence, and business relevance.
• Awareness of CMMC, PCI DSS, SOC 2, HIPAA, and NCUA examination requirements.
• Excellent written and verbal communication skills, with experience facilitating client meetings and presenting technical insights to non-technical audiences.
• Ability to coordinate efforts across teams without direct authority.
• Relevant certifications such as Security+, GIAC, CISSP, or vendor-specific qualifications are preferred but not mandatory.
• This is a full-time, exempt position.
• Some travel may be required.
• Opportunities for professional growth and practical experience in executing enterprise-level projects.
• A supportive, people-centric collaborative culture.
• Standard business hours with flexibility during month-end closing periods.
• Occasional travel for client interactions, team integration, and offsite events.
Mercor
Mercor
General Dynamics Information Technology
Stripe
Get handpicked remote jobs straight to your inbox weekly.