Vulnerability Manager
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Vulnerability Manager based in United States.
This role owns the vulnerability management program end to end, from intake and risk assessment through remediation, reporting, and closure verification.
You will operate the program as a hands-on security leader, designing processes, driving automation, and maintaining an authoritative view of vulnerability risk across the product portfolio.
A key focus will be supporting FedRAMP 20x requirements and establishing vulnerability management capabilities for new products and services as they launch.
You will work closely with Security Engineering and product engineering teams to integrate scanning, asset inventory, ticketing, dashboards, and other security capabilities.
The role requires strong risk judgment, balancing exploitability, exposure, asset criticality, and compensating controls rather than relying solely on vulnerability scores.
You will also lead rapid response to actively exploited and zero-day vulnerabilities while communicating risk clearly to engineers, executives, auditors, and other stakeholders.
This is a fully remote, North America-based position suited to someone who combines security expertise, operational ownership, automation, and strong cross-functional influence.
Accountabilities:
- Design and operate the complete product vulnerability management lifecycle, including intake, triage, risk assessment, assignment, SLA tracking, exception handling, and closure verification.
- Own vulnerability management for FedRAMP 20x, including continuous monitoring, machine-readable evidence, Key Security Indicator reporting, and POA&M management from creation through closure.
- Establish vulnerability management processes for new products and services by defining scan coverage, onboarding assets, setting remediation SLAs, and establishing reporting from the first release.
- Assess and prioritize vulnerability risk using exploitability, exposure, asset criticality, compensating controls, CVSS, and other relevant threat intelligence.
- Drive remediation across product engineering teams by assigning ownership, agreeing timelines, escalating overdue Critical and High findings, and documenting time-bound risk acceptances.
- Automate repetitive vulnerability management activities using scripting, workflow tooling, and AI-assisted analysis for triage, deduplication, enrichment, summarization, and evidence collection.
- Define technical requirements for security platform integrations covering vulnerability scanners, ticketing systems, asset inventories, dashboards, and related capabilities.
- Partner with Security Engineering throughout integration design, delivery, validation, and operational adoption.
- Own and report key program metrics, including SLA attainment, mean time to remediate, vulnerability aging, backlog trends, scan and asset coverage, and exception volumes.
- Maintain an accurate, current view of critical exposure across the product portfolio and serve as the authoritative source for vulnerability status, business impact, and remediation timelines.
- Lead rapid response to actively exploited and zero-day vulnerabilities by assessing exposure, coordinating mitigation, tracking remediation, and communicating with relevant stakeholders.
- 5+ years of experience in vulnerability management, product security, or security operations, with direct ownership of a vulnerability management program.
- Demonstrated experience designing and operating vulnerability management processes within regulated or audited environments and sustaining them through assessment cycles.
- Working knowledge of FedRAMP and NIST SP 800-53, particularly vulnerability scanning, flaw remediation, continuous monitoring, configuration management, and POA&M management.
- Hands-on experience with enterprise vulnerability and exposure management platforms, cloud security posture tools, container scanning, and software composition analysis.
- Practical automation skills using Python or an equivalent scripting language, workflow and reporting tools, and AI assistants to reduce manual triage and reporting effort.
- Ability to write clear technical requirements and collaborate effectively with Security Engineering through design, delivery, testing, and acceptance.
- Strong understanding of CVSS, CISA Known Exploited Vulnerabilities (KEV), EPSS, and risk-based prioritization, with sound judgment when distinguishing high scores from actual exposure.
- Working knowledge of cloud services, preferably AWS, as well as containers, Kubernetes, CI/CD, web applications, and APIs.
- Ability to evaluate security findings, understand technical risk, and assess proposed remediation approaches.
- Strong ability to influence engineering teams and drive remediation without direct authority.
- Clear written and verbal communication skills with engineers, executives, auditors, and customers.
- Direct experience with FedRAMP Moderate or High authorization, continuous monitoring, or FedRAMP 20x is a plus.
- Experience developing metrics, reporting, or dashboards for executive and audit audiences is a plus.
- Experience with SaaS, identity security, or privileged access management products is advantageous.
- Familiarity with agentic or AI-assisted security workflows is a plus.
- Cloud security certifications such as AWS, Azure, or GCP certifications, GIAC, CISSP, or equivalent credentials are advantageous.
- Fully remote work for candidates based in North America.
- Competitive compensation and employee benefits.
- Opportunity to own a security program with significant impact across a broad product portfolio.
- Exposure to regulated cybersecurity environments, including FedRAMP 20x and NIST-aligned practices.
- Hands-on work with vulnerability management, cloud security, containers, Kubernetes, automation, and AI-assisted security workflows.
- Close collaboration with Security Engineering, product engineering, security leadership, auditors, and other technical stakeholders.
- An environment that values flexibility, trust, continual learning, diversity, inclusion, and professional growth.
Requirements:
Benefits:
Skills
As published by lever
Resume/CV, Full name, Email, Phone, Current location, Current company