Senior Manager, Vulnerability Assessment

NielsenIQ

$120K — $150K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-8 years in Application Security or Cloud Engineering roles, with 3+ years in management or leadership.
  • Expertise in AWS security governance and incident mitigation in cloud environments.
  • Strong knowledge of CI/CD processes, containerization, and security tools integration (SAST/DAST/SCA).
  • Advanced skills in security automation tooling design.
  • Familiarity with AI-enhanced security technologies like LLM-driven remediation tools.
  • Bachelor's degree in Computer Science, Cybersecurity, or related fields, or equivalent experience.
  • Proven experience as a Staff or Principal Software Engineer or DevOps Specialist before moving to security management.
  • Strong collaboration abilities with engineering and platform teams, influencing through partnership rather than authority.

Responsibilities

  • Lead and mentor an Application Security engineering team, prioritizing professional development and team alignment with goals.
  • Develop and implement a modern Application and Pipeline Security strategy, focusing on an AI-driven DevSecOps approach.
  • Collaborate with Platform Engineering to establish cloud security baselines and Policy-as-Code guardrails.
  • Oversee application penetration testing, ensuring timely remediation of identified vulnerabilities.
  • Set observability and compliance standards throughout the development lifecycle, including safeguards for the supply chain.
  • Implement prioritization protocols to address existing security vulnerabilities effectively.
  • Enhance scanning processes (SAST, DAST, SCA) to reduce false positives and provide actionable insights.
  • Design automated response systems in AWS to manage threats swiftly.

Benefits

  • Comprehensive health and wellness plans.
  • 401(k) with company match.
  • Generous paid time off policy.
  • Potential company-provided vehicle based on role.
  • Discretionary incentive/bonus eligibility.
Full Job Description
Job Description

Nielsen is seeking a proactive Senior Manager within the Product Security organization to drive and expand our cloud and application security initiatives. This role requires a balance of operational discipline, high-agency, and technical vision.

You will lead a group of skilled engineers and collaborate with development teams to transition our security framework toward a modern, automated, AI-driven DevSecOps model. You will be accountable for team performance, defining security policies, and ensuring compliance, while adapting departmental plans to address operational challenges. Additionally, you will provide subject matter guidance to employees and colleagues operating within policy guidelines with moderate managerial oversight.

Work Style & Mindset
  • You prioritize business enablement over rigid perfectionism. You know how to make calculated risk trade-offs, focus on the 20% of risks that cause 80% of the impact, and keep engineering teams moving forward.
  • You treat engineering teams as internal customers. You measure success not by how many vulnerabilities you find, but by how easily developers can fix them with minimal friction.
  • You possess the grit and diplomatic skills to drive cultural change. You comfortably navigate organizational inertia and win buy-in for AI automation through small, high-impact victories.
  • You stay ahead of emerging tech trends, continuously evaluating how AI, cloud-native patterns, and modern tooling can simplify security operations.
  • You maintain a steady, analytical composure during high-severity events or pipeline blockers, focusing on automated prevention and root-cause solutions.

Responsibilities
  • Lead and mentor a high-performing Application Security engineering team, fostering professional development and aligning team priorities with organizational goals and operational challenges.
  • Drive a forward-thinking Application and Pipeline Security strategy that transitions operations to an autonomous, AI-driven DevSecOps model, pioneering agentic security workflows for automated remediation while establishing robust architectural guardrails and validation standards for secure AI-assisted development.
  • Partner collaboratively with Platform Engineering to define cloud security baselines and Policy-as-Code (PaC) guardrails.
  • Oversee application penetration testing initiatives ensuring findings are triaged, fed into pipeline guardrails, and remediated within SLA.
  • Establish comprehensive observability and regulatory standards across the development lifecycle, including supply chain safeguards (SBOM), automated CI/CD security gates, and risk-approval protocols to drive rapid, friction-free remediation and ensure high-confidence visibility.
  • Implement structured prioritization protocols to effectively resolve existing security vulnerabilities across application environments and cloud infrastructures.
  • Refine and calibrate scanning telemetry (SAST, DAST, SCA, IaC) to minimize false positives and enhance the delivery of high-confidence, actionable intelligence.
  • Design automated response triggers within AWS ecosystems utilizing native orchestration tools for rapid isolation and runtime threat containment.
  • Cultivate an environment where security is seamlessly embedded into native development workflows, including IDEs and CI/CD pipelines.
  • Architect and report on critical performance indicators, such as Mean Time to Remediate (MTTR) and Auto-Fix Acceptance Rates, to demonstrate program efficacy.


Qualifications

  • Minimum of 5-8 years of experience in specialized roles across Application Security or Cloud Engineering, including at least 3 years in a management or leadership capacity.
  • Demonstrated proficiency in designing AWS security governance and deploying automated incident mitigation within large-scale cloud ecosystems.
  • Comprehensive technical mastery of CI/CD orchestration, containerization safeguards, and the integration of SAST/DAST/SCA solutions within developer-centric workflows.
  • Advanced automation capabilities with the ability to architect security tooling.
  • Familiarity with emerging AI-enhanced security technologies, such as LLM-driven remediation tools and automated code-fixing platforms.
  • Bachelor's degree in a technical field like Computer Science or Cybersecurity, or equivalent professional background.
  • Substantial professional history serving as a Staff or Principal Software Engineer, or DevOps Specialist, preceding a career move into security management.
  • Demonstrated track record of building strong, collaborative partnerships with software engineering and platform teams without relying on dogmatic authority.
  • Possession of elite certifications such as AWS Certified Security - Specialty or AWS Solutions Architect - Professional.


Additional Information

Core Competencies
  • Lead product security efforts, define policies, and ensure compliance across development teams.
  • Manages professional associates and/or supervisors
  • Is accountable for the performance and results of a team
  • Adapts departmental plans and priorities to address resources and operational challenges
  • Decisions are guided by policies, resources and local business operating procedures. Receives moderate guidance from manager
  • Provides subject matter guidance to employees, colleagues and/or customers
  • Manages professional employees (P1, P2, P3) and leads team. Adapts plans to meet resource and operational challenges.
  • Integrates industry best practices in own area to the achieve of objectives
  • Identifies and resolves moderately complex business problems
  • Manages a generally homogeneous team; adapts plans and sets priorities to meet service and/or operational challenges
  • Guides, influences and persuades others internally and/or externally
  • Requires in-depth conceptual and practical knowledge in own areas and knowledge of other areas
  • Impacts the level of service and the team's ability to meet quality, volume and timeliness of objectives.
  • Guided by department policies, resource requirements, budgets and the business plan
  • 5-8 years with overseeing background
  • Bachelor's degree or equivalent experience


Holistic Rewards: We are committed to an inclusive benefits package that supports our employees and their families. This includes comprehensive health and wellness plans, a 401(k) with a Nielsen company match, and a generous paid time off policy. Depending on the role, additional benefits may include a company-provided vehicle and/or discretionary incentive/bonus eligibility.

Compensation Transparency: The posted base salary range is a reasonable estimate that may be adjusted based on the final work location of the selected employee. Individual pay within the range is determined by factors such as experience, training, geography, certifications, and business needs. Beyond base salary, this role may be eligible for bonuses, equity, or other incentives

Similar Jobs

More Jobs at NielsenIQ

More Information Technology Jobs

Find similar Senior Manager, Vulnerability Assessment jobs: