Join VultrVultr is seeking a
Manager of Vulnerability Management to oversee day-to-day operations, owning the infrastructure, processes, and team responsible for identifying, prioritizing, and driving remediation across Vultr's technology stack. This role balances technical depth with organizational influence, ensuring vulnerability management activities are performed effectively while continuously improving the systems that enable them. The Manager of Vulnerability Management will also be responsible for providing mentorship and direction to the team of analysts responsible for vulnerability management work. The ideal candidate brings deep expertise in vulnerability management program composition and direction.
Key Responsibilities- Team Leadership: Manage and mentor a team of skilled analysts, overseeing performance, career development, and daily operational priorities.
- Remediation Leadership: Partner with internal stakeholders to drive completion on complex remediation efforts, negotiate priorities and timelines, escalate blocked remediations, and maintain a risk-based approach to remediation prioritization.
- Continuous Improvement: Identify opportunities for improvement, benchmark program maturity against industry frameworks, solicit feedback from internal stakeholders to improve remediation procedures, and incorporate lessons learned into policies and procedures.
- Audit and Compliance Support: Serve as subject matter expert in internal and external audits, providing remediation evidence and policy attestations, and translate audit findings into actionable remediation plans.
- Vulnerability Management Oversight: Serve as the primary vulnerability management authority during security incidents and security operational engagements.
Minimum Qualifications- Experience: Minimally 5 years of experience in cybersecurity with 3+ years focused on vulnerability management, preferably within an IaaS CSP or technology provider.
- Vulnerability Management: Comprehensive understanding of the vulnerability lifecycle, vulnerability scoring (CVSS, EPSS), remediation procedures and tracking, and common scanning tools (Qualys, Tenable, Rapid7).
- Technical Understanding: General understanding of a wide variety of software and technologies, including Linux distros, hypervisors, container orchestration tooling, network hardware and communications, etc.
- Compliance Frameworks: An understanding of enterprise security standards such as SOC 2, ISO 27001, NIST 800-53, FedRAMP, and GDPR.
- Communication: Ability to translate complex technical security concepts into clear narratives for a variety of technical stakeholders.
- Education: Bachelor's degree or equivalent experience in Computer Science, Cybersecurity, or a related field.
- Operational Mindset: Methodical, detail-oriented self-starter capable of managing multiple priorities under pressure in a fast-paced environment.
Compensation$105,000 - $130,000
Final compensation will vary depending on years of experience, background/skill set, location, and applicable laws.