Job Location : New York, NY/ New Jersey, NJ (Onsite/Hybrid from Day 1)Job Description We are seeking an experienced
Vulnerability Management SME / Product Analyst to serve as the domain expert and product liaison for vulnerability management modernization initiatives. This role will drive the translation of vulnerability management requirements into platform capabilities, workflows, prioritization models, reporting, and remediation processes. The ideal candidate will possess strong
cybersecurity expertise, product analysis skills, and experience with enterprise vulnerability management platforms.
Key Responsibilities - Assess and enhance existing vulnerability management processes, workflows, platform capabilities, and operational effectiveness.
- Define and document requirements for vulnerability ingestion, deduplication, classification, prioritization, remediation tracking, exception management, reporting, and analytics.
- Develop and maintain vulnerability taxonomy and classification frameworks.
- Implement risk-based vulnerability prioritization using CVSS, KEV, EPSS, threat intelligence, asset criticality, exposure, and compensating controls.
- Facilitate workshops with security teams, application owners, infrastructure teams, and business stakeholders to gather requirements and drive alignment.
- Create and manage epics, user stories, process flows, acceptance criteria, and product backlogs.
- Validate scoring models, platform outputs, dashboards, reports, and remediation workflows.
- Define and monitor vulnerability SLAs, aging metrics, remediation KPIs, and risk-reduction measures.
- Support enterprise remediation campaigns and coordinate with technology and security teams to drive closure of vulnerabilities.
- Partner with cross-functional teams to improve vulnerability management capabilities and governance.
Required Qualifications - 8+ years of experience in Vulnerability Management, Cybersecurity, or Product Analysis roles.
- Strong understanding of vulnerability lifecycle management, including discovery, validation, prioritization, remediation, and exception handling.
- Deep knowledge of:
- CVE, CVSS, CWE, CPE
- KEV and EPSS
- Risk-Based Vulnerability Management
- Vulnerability Taxonomies and Prioritization Models
- Hands-on experience with vulnerability management tools such as:
- ServiceNow Vulnerability Response
- Qualys
- Tenable
- Rapid7
- Strong experience in requirements gathering, product analysis, workshop facilitation, and stakeholder management.
- Experience working with application, infrastructure, cloud, and security teams in large enterprise environments.
- Excellent communication, analytical, and problem-solving skills.
Preferred Qualifications - CISSP and/or CISM certification.
- Product Owner or Agile certification.
- Experience with Threat Intelligence and Cyber Risk Management programs.
- Experience managing large-scale remediation campaigns.
- Knowledge of Agile Product Management methodologies.
- Exposure to Data Platforms and security analytics solutions.
Required Skills - Vulnerability Management
- Product Analysis
- Requirements Gathering
- Workshop Facilitation
- Risk-Based Vulnerability Management
- CVE, CVSS, KEV, EPSS
- ServiceNow Vulnerability Response
- Qualys, Tenable, Rapid7
- Cybersecurity Risk Assessment
- Stakeholder Management
- Agile Product Management
The base compensation range for this role in the posted location is:80786-92271
Capgemini provides compensation range information in accordance with applicable national, state, provincial, and local pay transparency laws. The base compensation range listed for this position reflects the minimum and maximum target compensation Capgemini, in good faith, believes it may pay for the role at the time of this posting. This range may be subject to change as permitted by law.
The actual compensation offered to any candidate may fall outside of the posted range and will be determined based on multiple factors legally permitted in the applicable jurisdiction.
These may include, but are not limited to: Geographic location, Education and qualifications, Certifications and licenses, Relevant experience and skills, Seniority and performance, Market and business consideration, Internal pay equity.
It is not typical for candidates to be hired at or near the top of the posted compensation range.
In addition to base salary, this role may be eligible for additional compensation such as variable incentives, bonuses, or commissions, depending on the position and applicable laws.
Capgemini offers a comprehensive, non-negotiable benefits package to all regular, full-time employees. In the U.S. and Canada, available benefits are determined by local policy and eligibility and may include:
- Paid time off based on employee grade (A-F), defined by policy: Vacation: 12-25 days, depending on grade, Company paid holidays, Personal Days, Sick Leave
- Medical, dental, and vision coverage (or provincial healthcare coordination in Canada)
- Retirement savings plans (e.g., 401(k) in the U.S., RRSP in Canada)
- Life and disability insurance
- Employee assistance programs
- Other benefits as provided by local policy and eligibility