OverviewThe Sr. Manager, Vulnerability Management leads the enterprise Vulnerability Management function and is accountable for advancing a risk-based program that identifies, prioritizes, validates, and reduces cybersecurity exposure across enterprise and OT environments. This role provides people leadership, program governance, executive reporting, and cross-functional influence to drive remediation accountability with technology teams, vendors, and business stakeholders. This role is expected to translate vulnerability exposure into business risk, guide prioritization decisions based on threat and asset context, and mature the program through continuous improvement, automation, governance, and measurable risk reduction.
Primary Responsibilities- Lead the enterprise vulnerability management program by defining strategy, roadmaps, governance, and a risk-based exposure management operating model aligned with organizational cybersecurity and risk objectives.
- Drive accountability for vulnerability identification, prioritization, remediation, exception management, risk acceptance, escalation, and validation processes across the enterprise.
- Establish and maintain vulnerability management policies, standards, metrics, and service level objectives (SLOs/SLAs), ensuring compliance with internal security requirements and industry best practices.
- Partners with technology teams, business stakeholders, and third-party vendors to coordinate remediation efforts, reduce cyber risk, and strengthen enterprise security governance.
- Develop executive reporting, dashboards, metrics, and risk insights that communicate vulnerability exposure, remediation progress, program effectiveness, emerging threats, and business impact to support strategic decision-making.
- Lead the evaluation, implementation, and optimization of vulnerability management, threat detection, continuous monitoring, and automation capabilities to improve operational efficiency and program maturity.
- Serve as a senior vulnerability management leader, advising on risk-based decision making, program maturity, remediation governance, and emerging threat exposure.
- Manage cross-functional security initiatives and operational projects, ensuring successful delivery of program objectives, resource alignment, and stakeholder engagement.
- Build, develop, and lead a high-performing team through recruiting, coaching, mentoring, performance management, succession planning, and ongoing professional development.
- Establish team objectives, operational priorities, workforce plans, and long-term strategies that enable the vulnerability management program to scale with business growth and evolving security requirements.
- Manage program budgets, vendor relationships, and strategic partnerships to maximize the effectiveness and value of vulnerability management investments.
- Support major incident response and operational readiness by providing vulnerability intelligence, exposure context, remediation guidance, and leadership support as required.
- Advance a risk-based exposure management program by leveraging threat intelligence, asset criticality, business impact, and exploitability data to prioritize remediation and reduce enterprise cyber risk.
Preferred Qualifications- Master's Degree
- Active CISSP or other relevant security-related certification
- Scripting and/or programming skills to support automation, analysis, or process improvement.
Minimum Qualifications- Bachelor's degree in Computer Science, Computer Engineering, Cybersecurity, or a related field, or equivalent combination of education and work experience.
- Minimum 10-12 years of experience in cybersecurity, vulnerability management, infrastructure, cloud, OT, or related technology environments, including at least 5 years leading vulnerability management, exposure management, patch governance, or cyber risk reduction programs and at least
- 3 years of direct people leadership experience managing and developing Information Technology or Information Security professionals.
- Ability to develop and execute strategic initiatives, align security programs with business objectives, and lead organizational change.
- Strong analytical, critical-thinking, problem-solving, and decision-making skills, with the ability to assess risk and drive effective outcomes.
- Strong ability to assess and communicate cyber risk through governance, metrics, executive reporting, and vulnerability management practices that drive remediation accountability, informed decision-making, and continuous program maturity.
- Proven business acumen with experience managing priorities, budgets, resources, and competing organizational demands.
- Demonstrated ability to lead cross-functional programs and projects, including tracking progress, managing risks and dependencies, and driving successful delivery of objectives.
- Ability to influence remediation outcomes across teams that do not directly report into the vulnerability management function.
- Experience leading the use, integration, and optimization of vulnerability management platforms and related security technologies to improve prioritization, remediation workflow, reporting, and program maturity
- Ability to build strong teams through mentorship, talent development, knowledge sharing, and effective communication.
Physical Demands- Physical demands include a considerable amount of time sitting and typing/keyboarding, using a computer (e.g., keyboard, mouse, and monitor), or adding machine
- Physical demands with activity or condition may include walking, bending, reaching, standing, squatting, and stooping
- May require occasional lifting/lowering, pushing, carrying, or pulling up to 20lbs