
Vulnerability Program Manager
Posted Aug 21

Posted Aug 21
This is a fully remote position, open to applicants in United States.
• Take ownership of the complete vulnerability management and patching program, which encompasses asset discovery, scanning, prioritization, remediation tracking, verification, and reporting.
• Define and document the frequency of scans, cadence for patches, targets for remediation, criteria for exception handling, and conditions for emergency out-of-band work.
• Establish and uphold a program RACI involving Vulnerability Analysts, security engineering, service desk, and clients.
• Specify HaloPSA ticket types, templates, and workflows for patching, remediation, and evidence of scans.
• Conduct regular vulnerability management cycles and client review meetings.
• Maintain a prioritized backlog for remediation and escalate any stalled items.
• Coordinate remediation efforts among NetCov delivery teams and client personnel during change windows and maintenance periods.
• Manage exclusions, suppressions, and risk acceptances with proper documentation including reasons, responsible parties, and review dates.
• Act as the escalation point for zero-day vulnerabilities and those actively being exploited that necessitate out-of-cycle patching.
• Oversee client-facing vulnerability reports, aging and trend analyses, and executive summaries.
• Present the program's status to client stakeholders and interpret scan results into understandable risk and progress updates.
• Manage client expectations regarding project scope, timelines, and responsibilities.
• Assist with client audit and compliance evidence requests.
• Collaborate with Client Success and account teams during onboarding, escalations, and renewals.
• Take charge of vulnerability management tooling configuration, scanner coverage, credentialed scanning, agent deployment, and ensuring accuracy in asset inventory.
• Integrate scanning, ticketing, and patching systems with security engineering.
• Enhance data quality by resolving issues with stale assets, duplicate records, and unmanaged endpoints.
• Identify opportunities for automation in reporting, ticket creation, and validation of remediation.
• Define and report on metrics such as remediation SLA achievement, vulnerability aging, patch compliance, scan coverage, and recurring findings.
• Suggest process and tool modifications to address systemic challenges.
• Train and mentor Vulnerability Analysts and delivery staff.
• Contribute to defining and packaging NetCov vulnerability management services.
• Perform additional duties as assigned.
• Proven experience managing vulnerability and patching processes in a multi-client or multi-environment setting, preferably within an MSP or MSSP.
• Hands-on expertise with vulnerability management and patching tools such as InsightVM, ConnectSecure, NinjaOne, Datto RMM, or similar platforms.
• Familiarity with PSA and workflow tools; HaloPSA is preferred, including ticket design and reporting functionalities.
• Practical knowledge of risk-based prioritization methods, including CVSS, exploit intelligence, and business context.
• Awareness of CMMC, PCI DSS, SOC 2, HIPAA, and NCUA examination requirements.
• Strong written and verbal communication abilities, with experience leading client meetings and presenting technical findings to non-technical audiences.
• Capacity to drive initiatives across teams without direct authority.
• Relevant certifications such as Security+, GIAC, CISSP, or vendor-specific credentials are preferred but not mandatory.
• This is a full-time, exempt position.
• Standard business hours with flexibility around month-end close.
• Some travel may be required for client engagement, team integration, and offsite events.
• Opportunities for professional growth and hands-on experience with enterprise-level project execution.
• A supportive, people-first collaborative culture.
• Standard business hours with flexibility around month-end close.
• Occasional travel for client engagement, team integration, and offsite gatherings.
Mercor
Mercor
General Dynamics Information Technology
Stripe
Get handpicked remote jobs straight to your inbox weekly.