Position SummaryThe Director of Infrastructure Security is responsible for leading the execution, governance, and continuous evolution of the enterprise server and endpoint vulnerability management program in a complex hybrid environment spanning on-prem and cloud infrastructure.
This role is responsible for driving risk identification and reduction aligning to enterprise security objectives in a rapidly changing landscape.
This role requires a combination of technical expertise and people leadership with the ability to translate security objectives to relevant stakeholders.
Key Responsibilities:Configuration and Vulnerability Management (CVM) Program Management- Lead day-to-day operations of the enterprise vulnerability management program supporting servers, endpoints and infrastructure services.
- Partner with infrastructure, cloud, endpoint, application, and product technology teams to drive remediation planning and execution.
- Oversee vulnerability assessment platforms and associated technologies.
- Identify and implement automation opportunities that improve vulnerability discovery, prioritization and reporting.
- Support and execute strategic initiatives that improve vulnerability identification, prioritization, remediation, and reporting capabilities.
• Support and Develop risk-based vulnerability management methodologies incorporating exploitability, threat intelligence, asset criticality, business impact, and exposure factors.
• Drive continuous improvement initiatives that increase effectiveness, automation, operational efficiency, and program maturity.
Leadership and Team Management- Lead and mentor a high performing team of analysts within the CVM program.
- Foster a culture of accountability, collaboration, innovation, and continuous improvement.
- Collaborate and partner with peer leaders within the team to drive cross functional program initiatives
- Build partner relationships with key stakeholders.
Metrics, Reporting & Risk Management- Develop executive dashboards, KPIs, KRIs, and scorecards.
• Present vulnerability trends, remediation performance, and risk posture to senior leadership.
• Translate technical findings into business-focused risk communications.
• Support audits, regulatory assessments, and compliance reviews.
To Succeed in This Role:- Bachelor's degree or equivalent experience
Qualifications:- 8+ years cybersecurity/infrastructure security experience
- 5+ years' experience leading enterprise-scale vulnerability management programs
- Relevant Certifications such as CISSP, CISM etc. or equivalent experience
- Expertise with managing server hosts (Windows, Linux) in a hybrid environment including public cloud platforms. (AWS, Azure, GCP)
- Experience with security platforms such as Qualys, Wiz, CrowdStrike, etc.
- Experience with custom reporting using database platforms/tools and reporting visualization tools such as Grafana or Power BI.
#LI-SD4
#LI-Hybrid