174 Vulnerability Management jobs in the United States
Director, Vulnerability Management
Posted 1 day ago
Job Viewed
Job Description
**Who We Are.**
When we say, "the stuff dreams are made of," we're not just referring to the world of wizards, dragons and superheroes, or even to the wonders of Planet Earth. Behind WBD's vast portfolio of iconic content and beloved brands, are the _storytellers_ bringing our characters to life, the _creators_ bringing them to your living rooms and the _dreamers_ creating what's next.
From brilliant creatives, to technology trailblazers, across the globe, WBD offers career defining opportunities, thoughtfully curated benefits, and the tools to explore and grow into your best selves. Here you are supported, here you are celebrated, here you can thrive.
***Must work a hybrid schedule (3 days onsite) out of our Atlanta office.***
**THE JOB**
The **Director, Vulnerability Management** is a key leadership role within the Global Information & Content Security (GICS) team. This role leads and matures WBD's enterprise-wide vulnerability management Center of Excellence ( CoE ) program, covering cloud, on-premises infrastructure, and application environments. The Director is responsible for directing the identification, classification, reporting, and remediation of vulnerabilities, ensuring alignment with WBD's broader cybersecurity strategy.
This position requires deep collaboration across cloud engineering, IT infrastructure, application development, and third-party service providers to effectively reduce the organization's risk exposure. The Director will work closely with GICS and business unit leaders to ensure strategic and tactical vulnerability risk mitigation efforts align with enterprise goals.
**VULNERABILITY OVERSIGHT**
+ Lead WBD's program for managing vulnerabilities across on-prem infrastructure, cloud and applications ; guiding the process from finding vulnerabilities, to mitigating risk .
+ Manage WBD's M S SP to make sure scans are thorough and results are prioritized by how risky they are; assist and direct the process of resolving vulnerabilities and report on the status; and verify that the actions taken to fix them are working.
+ Drive vulnerability remediation with asset owners inline with established risk mitigation SLA's .
+ Incorporate vulnerability risk into the broader GICS risk oversight framework, continuously evaluating the risk associated with the state of remediation SLA compliance.
+ Oversee vulnerability scanning activities across the enterprise, including automated, authenticated, and manual assessments.
+ Define and apply risk-based classification standards for vulnerabilities using CVSS and contextual asset/business impact.
+ Maintain dashboards and reporting for vulnerability risk metrics.
+ Establish SLAs for remediation, drive accountability, and verify remediation effectiveness.
+ Integrate vulnerability management into broader risk oversight and GICS governance.
+ Collaborate with DevSecOps , product engineering, and infrastructure teams to embed remediation into operational workflows.
**STRATEGIC LEADERSHIP**
+ Translate vulnerability risk insights into strategic decisions and enterprise-wide policies.
+ Communicate effectively with senior leadership and executive stakeholders.
+ Contribute to the design of cybersecurity strategies by advising on risk reduction priorities related to vulnerability trends.
+ Develop metrics to track vulnerability closure rates, aged vulnerabilities, and SLA compliance.
+ Drive initiatives that reduce recurring vulnerabilities through root cause analysis.
**BUSINESS PARTNERSHIP & ENABLEMENT**
+ Engage with application, cloud, and infrastructure teams to promote remediation ownership.
+ Foster collaboration across business units to ensure alignment between risk mitigation and delivery priorities.
+ Support high-visibility business initiatives (e.g., product launches, M&A, live events) by proactively identifying and managing vulnerability risk.
+ Provide guidance on secure configuration and preventive controls to limit future vulnerabilities.
**The Essentials**
+ 12+ years of cybersecurity experience, with 5+ years in vulnerability management
+ Strong expertise across cloud (AWS, Azure, GCP), on-premise , and application environments
+ Experience with tools such as Tenable, Wiz , Brinqa , PowerBi and native cloud scanning technologies
+ Strong knowledge of risk frameworks (e.g., NIST, ISO, CVSS)
+ Bachelor's degree in Computer Science , Engineering, or related field
+ Excellent analytical, communication, and stakeholder engagement skills
+ Bachelor's degree in related field, such as Business, IT, Computer Science
+ Knowledge of IP network infrastructure (firewalls, intrusion detection/prevention), access control, data encryption and on-prem and cloud security
+ Excellent communication skills, including the ability to communicate effectively in English, both written and verbal
+ Ability to present complex topics in clear, non-technical language
+ Ability to work collaboratively within team and across business and technology functions
+ Detail-oriented individual with critical thinking, analytical, and problem-solving skills
+ Demonstrated ability to be proactive and take ownership of and solve problems
+ Ability to handle multiple assignments concurrently within an iterative environment
+ Deep capability in applying risk principles to the business environment. Ability to clearly articulate risk concepts and results to business leaders and navigate collaborative and informed decision making.
+ Can effectively connect with both technical and non-technical staff. Ability to translate sophisticated technical concepts into plain English and present them in a way that decision-makers can understand.
+ Positive influencing skills both verbally and through the preparation of written materials in order to build relationships, influence and negotiate.
+ Strong project management and delegation skills in prioritizing and reprioritizing projects of various size and complexity across multiple functional groups and departments.
**The Nice to Haves**
+ One or more of the following certifications: CISSP, CRISC, CISA
+ 5+ years of prior experience in a related field (media, entertainment, business development or streaming services industry experience a plus)
+ Familiarity with streaming and similar products /services
+ Experience working in a national or global company
**How We Get Things Done.**
This last bit is probably the most important! Here at WBD, our guiding principles are the core values by which we operate and are central to how we get things done. You can find them at along with some insights from the team on what they mean and how they show up in their day to day. We hope they resonate with you and look forward to discussing them during your interview.
**Championing Inclusion at WBD**
Warner Bros. Discovery embraces the opportunity to build a workforce that reflects a wide array of perspectives, backgrounds and experiences. Being an equal opportunity employer means that we take seriously our responsibility to consider qualified candidates on the basis of merit, without regard to race, color, religion, national origin, gender, sexual orientation, gender identity or expression, age, mental or physical disability, and genetic information, marital status, citizenship status, military status, protected veteran status or any other category protected by law.
If you're a qualified candidate with a disability and you require adjustments or accommodations during the job application and/or recruitment process, please visit our accessibility page ( for instructions to submit your request.
In compliance with local law, we are disclosing the compensation, or a range thereof, for roles in locations where legally required. Actual salaries will vary based on several factors, including but not limited to external market data, internal equity, location, skill set, experience, and/or performance. Base pay is just one component of Warner Bros. Discovery's total compensation package for employees. Pay Range: $177,170.00 - $329,030.00 salary per year. Other rewards may include annual bonuses, short- and long-term incentives, and program-specific awards. In addition, Warner Bros. Discovery provides a variety of benefits to employees, including health insurance coverage, an employee wellness program, life and disability insurance, a retirement savings plan, paid holidays and sick time and vacation.
Director, Vulnerability Management

Posted 1 day ago
Job Viewed
Job Description
**Who We Are.**
When we say, "the stuff dreams are made of," we're not just referring to the world of wizards, dragons and superheroes, or even to the wonders of Planet Earth. Behind WBD's vast portfolio of iconic content and beloved brands, are the _storytellers_ bringing our characters to life, the _creators_ bringing them to your living rooms and the _dreamers_ creating what's next.
From brilliant creatives, to technology trailblazers, across the globe, WBD offers career defining opportunities, thoughtfully curated benefits, and the tools to explore and grow into your best selves. Here you are supported, here you are celebrated, here you can thrive.
***Must work a hybrid schedule (3 days onsite) out of our Atlanta office.***
**THE JOB**
The **Director, Vulnerability Management** is a key leadership role within the Global Information & Content Security (GICS) team. This role leads and matures WBD's enterprise-wide vulnerability management Center of Excellence ( CoE ) program, covering cloud, on-premises infrastructure, and application environments. The Director is responsible for directing the identification, classification, reporting, and remediation of vulnerabilities, ensuring alignment with WBD's broader cybersecurity strategy.
This position requires deep collaboration across cloud engineering, IT infrastructure, application development, and third-party service providers to effectively reduce the organization's risk exposure. The Director will work closely with GICS and business unit leaders to ensure strategic and tactical vulnerability risk mitigation efforts align with enterprise goals.
**VULNERABILITY OVERSIGHT**
+ Lead WBD's program for managing vulnerabilities across on-prem infrastructure, cloud and applications ; guiding the process from finding vulnerabilities, to mitigating risk .
+ Manage WBD's M S SP to make sure scans are thorough and results are prioritized by how risky they are; assist and direct the process of resolving vulnerabilities and report on the status; and verify that the actions taken to fix them are working.
+ Drive vulnerability remediation with asset owners inline with established risk mitigation SLA's .
+ Incorporate vulnerability risk into the broader GICS risk oversight framework, continuously evaluating the risk associated with the state of remediation SLA compliance.
+ Oversee vulnerability scanning activities across the enterprise, including automated, authenticated, and manual assessments.
+ Define and apply risk-based classification standards for vulnerabilities using CVSS and contextual asset/business impact.
+ Maintain dashboards and reporting for vulnerability risk metrics.
+ Establish SLAs for remediation, drive accountability, and verify remediation effectiveness.
+ Integrate vulnerability management into broader risk oversight and GICS governance.
+ Collaborate with DevSecOps , product engineering, and infrastructure teams to embed remediation into operational workflows.
**STRATEGIC LEADERSHIP**
+ Translate vulnerability risk insights into strategic decisions and enterprise-wide policies.
+ Communicate effectively with senior leadership and executive stakeholders.
+ Contribute to the design of cybersecurity strategies by advising on risk reduction priorities related to vulnerability trends.
+ Develop metrics to track vulnerability closure rates, aged vulnerabilities, and SLA compliance.
+ Drive initiatives that reduce recurring vulnerabilities through root cause analysis.
**BUSINESS PARTNERSHIP & ENABLEMENT**
+ Engage with application, cloud, and infrastructure teams to promote remediation ownership.
+ Foster collaboration across business units to ensure alignment between risk mitigation and delivery priorities.
+ Support high-visibility business initiatives (e.g., product launches, M&A, live events) by proactively identifying and managing vulnerability risk.
+ Provide guidance on secure configuration and preventive controls to limit future vulnerabilities.
**The Essentials**
+ 12+ years of cybersecurity experience, with 5+ years in vulnerability management
+ Strong expertise across cloud (AWS, Azure, GCP), on-premise , and application environments
+ Experience with tools such as Tenable, Wiz , Brinqa , PowerBi and native cloud scanning technologies
+ Strong knowledge of risk frameworks (e.g., NIST, ISO, CVSS)
+ Bachelor's degree in Computer Science , Engineering, or related field
+ Excellent analytical, communication, and stakeholder engagement skills
+ Bachelor's degree in related field, such as Business, IT, Computer Science
+ Knowledge of IP network infrastructure (firewalls, intrusion detection/prevention), access control, data encryption and on-prem and cloud security
+ Excellent communication skills, including the ability to communicate effectively in English, both written and verbal
+ Ability to present complex topics in clear, non-technical language
+ Ability to work collaboratively within team and across business and technology functions
+ Detail-oriented individual with critical thinking, analytical, and problem-solving skills
+ Demonstrated ability to be proactive and take ownership of and solve problems
+ Ability to handle multiple assignments concurrently within an iterative environment
+ Deep capability in applying risk principles to the business environment. Ability to clearly articulate risk concepts and results to business leaders and navigate collaborative and informed decision making.
+ Can effectively connect with both technical and non-technical staff. Ability to translate sophisticated technical concepts into plain English and present them in a way that decision-makers can understand.
+ Positive influencing skills both verbally and through the preparation of written materials in order to build relationships, influence and negotiate.
+ Strong project management and delegation skills in prioritizing and reprioritizing projects of various size and complexity across multiple functional groups and departments.
**The Nice to Haves**
+ One or more of the following certifications: CISSP, CRISC, CISA
+ 5+ years of prior experience in a related field (media, entertainment, business development or streaming services industry experience a plus)
+ Familiarity with streaming and similar products /services
+ Experience working in a national or global company
**How We Get Things Done.**
This last bit is probably the most important! Here at WBD, our guiding principles are the core values by which we operate and are central to how we get things done. You can find them at along with some insights from the team on what they mean and how they show up in their day to day. We hope they resonate with you and look forward to discussing them during your interview.
**Championing Inclusion at WBD**
Warner Bros. Discovery embraces the opportunity to build a workforce that reflects a wide array of perspectives, backgrounds and experiences. Being an equal opportunity employer means that we take seriously our responsibility to consider qualified candidates on the basis of merit, without regard to race, color, religion, national origin, gender, sexual orientation, gender identity or expression, age, mental or physical disability, and genetic information, marital status, citizenship status, military status, protected veteran status or any other category protected by law.
If you're a qualified candidate with a disability and you require adjustments or accommodations during the job application and/or recruitment process, please visit our accessibility page ( for instructions to submit your request.
In compliance with local law, we are disclosing the compensation, or a range thereof, for roles in locations where legally required. Actual salaries will vary based on several factors, including but not limited to external market data, internal equity, location, skill set, experience, and/or performance. Base pay is just one component of Warner Bros. Discovery's total compensation package for employees. Pay Range: $177,170.00 - $329,030.00 salary per year. Other rewards may include annual bonuses, short- and long-term incentives, and program-specific awards. In addition, Warner Bros. Discovery provides a variety of benefits to employees, including health insurance coverage, an employee wellness program, life and disability insurance, a retirement savings plan, paid holidays and sick time and vacation.
Director, Vulnerability Management
Posted 1 day ago
Job Viewed
Job Description
**Who We Are.**
When we say, "the stuff dreams are made of," we're not just referring to the world of wizards, dragons and superheroes, or even to the wonders of Planet Earth. Behind WBD's vast portfolio of iconic content and beloved brands, are the _storytellers_ bringing our characters to life, the _creators_ bringing them to your living rooms and the _dreamers_ creating what's next.
From brilliant creatives, to technology trailblazers, across the globe, WBD offers career defining opportunities, thoughtfully curated benefits, and the tools to explore and grow into your best selves. Here you are supported, here you are celebrated, here you can thrive.
***Must work a hybrid schedule (3 days onsite) out of our Atlanta office.***
**THE JOB**
The **Director, Vulnerability Management** is a key leadership role within the Global Information & Content Security (GICS) team. This role leads and matures WBD's enterprise-wide vulnerability management Center of Excellence ( CoE ) program, covering cloud, on-premises infrastructure, and application environments. The Director is responsible for directing the identification, classification, reporting, and remediation of vulnerabilities, ensuring alignment with WBD's broader cybersecurity strategy.
This position requires deep collaboration across cloud engineering, IT infrastructure, application development, and third-party service providers to effectively reduce the organization's risk exposure. The Director will work closely with GICS and business unit leaders to ensure strategic and tactical vulnerability risk mitigation efforts align with enterprise goals.
**VULNERABILITY OVERSIGHT**
+ Lead WBD's program for managing vulnerabilities across on-prem infrastructure, cloud and applications ; guiding the process from finding vulnerabilities, to mitigating risk .
+ Manage WBD's M S SP to make sure scans are thorough and results are prioritized by how risky they are; assist and direct the process of resolving vulnerabilities and report on the status; and verify that the actions taken to fix them are working.
+ Drive vulnerability remediation with asset owners inline with established risk mitigation SLA's .
+ Incorporate vulnerability risk into the broader GICS risk oversight framework, continuously evaluating the risk associated with the state of remediation SLA compliance.
+ Oversee vulnerability scanning activities across the enterprise, including automated, authenticated, and manual assessments.
+ Define and apply risk-based classification standards for vulnerabilities using CVSS and contextual asset/business impact.
+ Maintain dashboards and reporting for vulnerability risk metrics.
+ Establish SLAs for remediation, drive accountability, and verify remediation effectiveness.
+ Integrate vulnerability management into broader risk oversight and GICS governance.
+ Collaborate with DevSecOps , product engineering, and infrastructure teams to embed remediation into operational workflows.
**STRATEGIC LEADERSHIP**
+ Translate vulnerability risk insights into strategic decisions and enterprise-wide policies.
+ Communicate effectively with senior leadership and executive stakeholders.
+ Contribute to the design of cybersecurity strategies by advising on risk reduction priorities related to vulnerability trends.
+ Develop metrics to track vulnerability closure rates, aged vulnerabilities, and SLA compliance.
+ Drive initiatives that reduce recurring vulnerabilities through root cause analysis.
**BUSINESS PARTNERSHIP & ENABLEMENT**
+ Engage with application, cloud, and infrastructure teams to promote remediation ownership.
+ Foster collaboration across business units to ensure alignment between risk mitigation and delivery priorities.
+ Support high-visibility business initiatives (e.g., product launches, M&A, live events) by proactively identifying and managing vulnerability risk.
+ Provide guidance on secure configuration and preventive controls to limit future vulnerabilities.
**The Essentials**
+ 12+ years of cybersecurity experience, with 5+ years in vulnerability management
+ Strong expertise across cloud (AWS, Azure, GCP), on-premise , and application environments
+ Experience with tools such as Tenable, Wiz , Brinqa , PowerBi and native cloud scanning technologies
+ Strong knowledge of risk frameworks (e.g., NIST, ISO, CVSS)
+ Bachelor's degree in Computer Science , Engineering, or related field
+ Excellent analytical, communication, and stakeholder engagement skills
+ Bachelor's degree in related field, such as Business, IT, Computer Science
+ Knowledge of IP network infrastructure (firewalls, intrusion detection/prevention), access control, data encryption and on-prem and cloud security
+ Excellent communication skills, including the ability to communicate effectively in English, both written and verbal
+ Ability to present complex topics in clear, non-technical language
+ Ability to work collaboratively within team and across business and technology functions
+ Detail-oriented individual with critical thinking, analytical, and problem-solving skills
+ Demonstrated ability to be proactive and take ownership of and solve problems
+ Ability to handle multiple assignments concurrently within an iterative environment
+ Deep capability in applying risk principles to the business environment. Ability to clearly articulate risk concepts and results to business leaders and navigate collaborative and informed decision making.
+ Can effectively connect with both technical and non-technical staff. Ability to translate sophisticated technical concepts into plain English and present them in a way that decision-makers can understand.
+ Positive influencing skills both verbally and through the preparation of written materials in order to build relationships, influence and negotiate.
+ Strong project management and delegation skills in prioritizing and reprioritizing projects of various size and complexity across multiple functional groups and departments.
**The Nice to Haves**
+ One or more of the following certifications: CISSP, CRISC, CISA
+ 5+ years of prior experience in a related field (media, entertainment, business development or streaming services industry experience a plus)
+ Familiarity with streaming and similar products /services
+ Experience working in a national or global company
**How We Get Things Done.**
This last bit is probably the most important! Here at WBD, our guiding principles are the core values by which we operate and are central to how we get things done. You can find them at along with some insights from the team on what they mean and how they show up in their day to day. We hope they resonate with you and look forward to discussing them during your interview.
**Championing Inclusion at WBD**
Warner Bros. Discovery embraces the opportunity to build a workforce that reflects a wide array of perspectives, backgrounds and experiences. Being an equal opportunity employer means that we take seriously our responsibility to consider qualified candidates on the basis of merit, without regard to race, color, religion, national origin, gender, sexual orientation, gender identity or expression, age, mental or physical disability, and genetic information, marital status, citizenship status, military status, protected veteran status or any other category protected by law.
If you're a qualified candidate with a disability and you require adjustments or accommodations during the job application and/or recruitment process, please visit our accessibility page ( for instructions to submit your request.
In compliance with local law, we are disclosing the compensation, or a range thereof, for roles in locations where legally required. Actual salaries will vary based on several factors, including but not limited to external market data, internal equity, location, skill set, experience, and/or performance. Base pay is just one component of Warner Bros. Discovery's total compensation package for employees. Pay Range: $177,170.00 - $329,030.00 salary per year. Other rewards may include annual bonuses, short- and long-term incentives, and program-specific awards. In addition, Warner Bros. Discovery provides a variety of benefits to employees, including health insurance coverage, an employee wellness program, life and disability insurance, a retirement savings plan, paid holidays and sick time and vacation.
Manager Vulnerability Management
Posted 3 days ago
Job Viewed
Job Description
Manager, Vulnerability Management
Hybrid work arrangement required: 4 days on-site, 1 remote in one of our organizational hubs including: Johnston, RI - Phoenix, AZ - Westwood OR Medford, MA - Plano, TX - Iselin, NJ - Pittsburgh, PA - Franklin, TN - Cleveland OR Columbus, OH - Chicago, IL
We are currently seeking a highly motivated, detail oriented, and customer focused individual to play a key role on the team. In this role on the Cyber Defense - Infrastructure Vulnerability Management Team, you will be responsible for performing vulnerability and compliance scanning and analysis to aid Citizens in assessing the enterprise vulnerability posture and reducing the attack surface.
Working closely with business lines and infrastructure teams, you will directly contribute to the effort to identify, track, and remediate the open vulnerabilities (technical Vulnerabilities or build compliance deviations) on systems that store, process, or display Citizen's data. In this role, it is critical that you must understand technology operations as well as security operations, with a keen understanding of the concept of mitigating and compensating controls is required.
Responsibilities (but not limited to):
+ Actively looking for ways to improve the processes around the program to provide a best of breed, world class service
+ Communicating security issues to a wide variety of internal and external "customers" to include technical teams, executives, risk groups, vendors and regulators
+ Maintaining a deep understanding of current threat, vulnerabilities, attacks, countermeasures and how to respond effectively to them while providing training to the rest of the team on these items
+ Developing meaningful metrics to reflect the true posture of the environment allowing the organization to make educated decisions based on risk
+ Improving the capabilities and maturity of the Citizens Vulnerability Management Program by identifying appropriate technologies, policies, communication channels, organizational structures and relationships with third parties
Required Experience and Skills:
+ 8+ years of progressive security industry experience, including 2+ years in a leadership or management role.
+ 5 years of progressive security industry experience
+ 1-2 years of experience with with QualysGuard Vulnerability Scanner including its API, Vulnerability Management (VM), Policy Compliance (PC), CloudView, AssetView, Cloud Agent, and other modules highly preferred
+ 1-2 years of experience with other vulnerability management solutions such as Tenable, Rapid7, and others is acceptable with the understanding that you will be expected to be a domain expert with this Qualys in 3-6 months.
+ Recall level of understanding of CVSS, CVE, CWE, CPE, CCE, CWE, OVAL, SCAP and other standards
+ Experience developing applications, automation scripts, or other solutions in at least one modern language (Python, Powershell, Java, C/C++, Go, etc)
+ Expert understanding of various operating systems (Window, UNIX, Linux, AIX, etc.) with an emphasis on vulnerability assessment and hardening. Subject matter expertise in at least one of the operating systems is required
+ Practical knowledge of security hardening, configuration management, change control/problem management, exception management and security baselines (e.g. CIS Baselines, NIST, vendor security technical implementation guides, etc.)
+ Practical knowledge of Cloud (AWS, Azure, etc.) and how to secure them
+ Associate level knowledge of networking fundamentals
+ Experience fostering and maintaining relationships with key stakeholders and business partners
+ Self-motivation with the ability to work under minimal supervision is a must
+ Ability to demonstrate manual testing experience including all of OWASP Top 10
+ Demonstrated experience with common penetration testing and vulnerability assessment tools such as nmap, Wireshark, Nessus, NeXpose, Kali, Metasploit, AppScan, WebInspect, Burp Suite Professional, Acunetix, Arachni, w3af, NTOSpider, ZAP Proxy, IronWASP is a plus
Preferred Education and Certifications:
+ One or more relevant security certifications (GEVA, GCIH, GCIA, OSCP, GPEN, GXPN, GWAPT, GWEB, GCIA, GSNA, LPT, Security +, CISSP, CISM, CISA)
+ Bachelor's Degree or equivalent combination of experience
Hours & Work Schedule:
Hours & Work Schedule: M-F
Hours per Week: 40
Pay Transparency
The salary range for this position is $175,000-$205,000 per year plus an opportunity to earn an annual discretionary bonus. Actual pay is based on various factors including but not limited to the work location, and relevant skills and experience.
We offer competitive pay, comprehensive medical, dental and vision coverage, retirement benefits, maternity/paternity leave, flexible work arrangements, education reimbursement, wellness programs and more. Note, Citizens' paid time off policy exceeds the mandatory, paid sick or paid time-away policy of very local and state jurisdiction in the United States. For an overview of our benefits, visit .
#LI-Citizens1
Some job boards have started using jobseeker-reported data to estimate salary ranges for roles. If you apply and qualify for this role, a recruiter will discuss accurate pay guidance.
Equal Employment Opportunity
Citizens, its parent, subsidiaries, and related companies (Citizens) provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to age, ancestry, color, citizenship, physical or mental disability, perceived disability or history or record of a disability, ethnicity, gender, gender identity or expression, genetic information, genetic characteristic, marital or domestic partner status, victim of domestic violence, family status/parenthood, medical condition, military or veteran status, national origin, pregnancy/childbirth/lactation, colleague's or a dependent's reproductive health decision making, race, religion, sex, sexual orientation, or any other category protected by federal, state and/or local laws. At Citizens, we are committed to fostering an inclusive culture that enables all colleagues to bring their best selves to work every day and everyone is expected to be treated with respect and professionalism. Employment decisions are based solely on merit, qualifications, performance and capability.
Why Work for Us
At Citizens, you'll find a customer-centric culture built around helping our customers and giving back to our local communities. When you join our team, you are part of a supportive and collaborative workforce, with access to training and tools to accelerate your potential and maximize your career growth
Background Check
Any offer of employment is conditioned upon the candidate successfully passing a background check, which may include initial credit, motor vehicle record, public record, prior employment verification, and criminal background checks. Results of the background check are individually reviewed based upon legal requirements imposed by our regulators and with consideration of the nature and gravity of the background history and the job offered. Any offer of employment will include further information.
Vulnerability Management Intern Cybersecurity
Posted today
Job Viewed
Job Description
Building trusted markets powered by our people.
At Cboe Global Markets, we inspire our people to solve complex challenges together because what we do matters. We provide the financial infrastructure that powers the global economy. As a leading provider of market infrastructure and tradable products, Cboe delivers cutting-edge trading, clearing and investment solutions to market participants around the world.
Cboe interns work with a variety of staff across multiple departments and have the opportunity to put their skills to work in their field of interest, while learning about Exchange technology and operations through our robust Options Institute courses.
The three main foundational pillars of our internship program are: develop, educate and network. We want to ensure each of our interns receive a real-world working experience that encourages academic, professional and personal growth.
Candidates should be versatile, eager and able to work in a fast-paced, time-sensitive financial and technical environment. Our interns will have the flexibility of working 2 days remotely, and 3 days in office per week at one of our state-of-the-art offices in Chicago, Kansas City, and New York City. To be eligible for this internship, applicants must be enrolled in a university or college program and should not be scheduled to graduate before December of the internship year. Our internship program runs from June to August and you will wrap up your internship with a final presentation and retreat.
The Vulnerability Management Intern position will provide exposure to the various functions, tools, and activities focusing on reducing Cboe's attack surface by way of vulnerability management.
Help us identify and patch all the things!
Your responsibilities and learning objectives will be: As part of a strong, dynamic, global security team, the Vulnerability Management Intern will have the opportunity to learn and contribute via a range of opportunities that provide real-world, hands-on cybersecurity experience.
You will gain experience with patchable network vulnerabilities, application security (appsec) vulnerabilities, operating system vulnerabilities, cloud security vulnerabilities, commercial vulnerability scanning tools, segmented network architectures, systems management automation for both Windows and Linux, and IP address management. You will be introduced to metrics reporting and associated technologies in the context of a global organization. You will interact with members of the entire Global Information Security Team along with Network Engineering, Cloud, Windows Engineering and Linux Engineering teams to identify, report, and help solve problems. Specific duties may vary based on the experience of the selected candidate, but typical duties within the VMT would include:
- Act on vulnerability findings, spearheading technical communication to resolving teams professionally and accurately
- Assist with day-to-day operational tasks, such as scan result review, IP asset configuration management (CMDB) accuracy improvement, scan issue resolution, and reporting of vulnerabilities to system owners from scan results leveraging a ticketing system
- Remain aware of breaking vulnerability news stories by leveraging various threat intelligence feeds
- Document/improve vulnerability management procedures
- Identify and act upon automation opportunities that could include API programming and leveraging AI and LLM tooling available in-house
- Collaborate with vulnerability management teammates in other time zones. This does include a small number of meetings off-hours, typically in the evening
- Perform additional duties and assignments as requested
The ideal candidate:
- Is currently enrolled in a Bachelor's or Master's program in Information Security, Cyber Security, Computer Science, Engineering or equivalent exposure and experience related to these fields and should not be scheduled to graduate before December of the internship year.
- Understands security vulnerabilities in software and systems and comprehends the potential impact if they are left unaddressed
- Should be eager to learn quickly and able to communicate clearly and professionally in English.
- Has base knowledge of security concepts, versed in TCP/IP, common ports/services, and overall networking concepts such as routing, switching and firewalls.
- Is able to perform basic administrative tasks on both Linux and Windows based systems.
- In addition, should have working knowledge of Microsoft Office products including Excel, Word and PowerPoint.
You'll really stand out with:
- Experience in Python and/or PowerShell automating tasks leveraging calls to REST or Graph API's.
- Hands on experience doing patching and remediation in a corporate environment to enable authoritative communication with remediation teams
- Familiarity with vulnerability scanners such as Nexpose, Qualys, or Tenable, or Cloud Security Posture Management tooling
- Experience automating with Excel, PowerAutomate, Sigma, or Snowflake
Benefits and Perks:
- Competitive compensation
- Flexible, hybrid work environment, 3 days in office, 2 days remote, per week.
- 2:1 401(k) match, up to 8% match immediately upon hire.
Some of our employees' favorite benefits and perks include:
- Daily complimentary in-office lunch from local restaurants
- Endless free coffee and snacks to fuel your workday
- Monthly in office networking events and happy hours
- Associate Resource Groups (ARGs) and affinity groups for support and community building
More About Cboe Global Markets:
We're reimagining the future of the workplace by focusing on what matters most, our people. Our journey is an inclusive one. We're investing deeply in leadership programs and career development initiatives that ensure everyone has an equal chance to succeed. We celebrate the diversity in our communities, inside and out, with equity, inclusion and belonging.
We work with purpose, solving problems with ingenuity, collaboration, and a lot of passion. We're an engaged and excited team connecting markets across borders and embracing growth in all its forms to achieve incredible outcomes.
Equal Employment Opportunity:
We're proud to be an equal opportunity employer - and celebrate our employees' differences, including race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, and Veteran status.
Our pay range for interns is determined by function and education level. The national new hire base pay range for this job in the United States is $25.00 - $36.00 per hour. This range represents the minimum and maximum base pay target for new hires working in the position full time. Within the range, individual pay is determined by years of education completed. In addition to base pay, eligibility for our total rewards program may include benefits such as 401(k) with a generous company match and paid sick time. Your recruiter will provide more details about the total compensation package during the hiring process.
Manager of Vulnerability Management
Posted today
Job Viewed
Job Description
Job Summary:
As the Manager of Vulnerability Management you will paly a key role in the success of the vulnerability and configuration management program by identifying security risks, prioritizing actions based on intelligence-driven processes, and proactively responding to emerging threats. This role will be the face of the program and will oversee a managed service provider that performs the day-to-day functions of the vulnerability and configuration management program.
Responsibilities:
-
Provide oversight and direction to managed service provider to work on vulnerability and configuration scans, analysis, and reporting to support the organization.
-
Develop strategy for a risk-based vulnerability management program for the organization.
-
Collaborate closely with cross-functional teams to facilitate the timely remediation of vulnerabilities and misconfigurations, with a strong focus on effectiveness and risk management.
-
Partner with Cyber Threat Intelligence, the Cybersecurity Incident Response team, and technology remediation groups to deliver shared outcomes that measurably improve our efficacy to detect and remediate vulnerabilities.
-
Determine tools and resources needed to support the organization's need to identify and prioritize vulnerability and configuration deficiencies.
-
Establish organization secure configuration standards across operating systems, applications, and devices
Ideal Candidates Will Have Experience:
-
Managing a team or Managed Service Provider
-
Vulnerability and configuration management within healthcare environment
-
Using ServiceNow Vulnerability Response module
-
Contributing or developing polices or standards
BENEFITS
Our benefits are designed to help you live well no matter where you are on your journey. For full details on coverage and eligibility, visit the Baylor Scott & White Benefits Hub to explore our offerings, which may include:
-
Immediate eligibility for health and welfare benefits
-
401(k) savings plan with dollar-for-dollar match up to 5%
-
Tuition Reimbursement
-
PTO accrual beginning Day 1 Note: Benefits may vary based upon position type and/or level
Preferred Certifications:
-
Certified Information Systems Professional (CISSP)
-
Certified Information Security Manager (CISM)
-
CompTIA Advanced Security Practitioner (CASP+)
Preferred Qualifications
-
BS Degree in computer science, computer engineering, software engineering, cybersecurity or related technical degreeor 5 years equivalent technology experience
-
5+ years' experience in information security in an enterprise environment
-
3+ years' experience assessing and implementing vulnerability management tools, vulnerability scan configurations, vulnerability reporting, and vulnerability remediation in an enterprise environment.
-
Knowledge of common software, operating systems vulnerabilities, Unix/Lenux
-
Strong experience with Vulnerability Management Platforms such as Tenable, Qualys, Rapid7, in a large corporate environment.
-
Experience with Center for Internet Security (CIS) benchmarks for secure configurations.
-
Understanding of cybersecurity organizational practices, operations risk management processes, architectural requirements, and vulnerability risk.
-
Experience with controls or frameworks such as NIST 800-53, NIST CSF, CIS, MITRE ATT&CK
-
Strong experience in reading and understanding vulnerability scans
-
Experience creating and running authenticated and unauthenticated scans
-
Knowledge of data communications terminology (e.g., networking protocols, Ethernet, IP, encryption, optical devices, removable media).
-
Knowledge of existing, emerging, and long-range issues related to cyber operations strategy, policy, and organization
Minimum Qualifications
-
EDUCATION - Bachelor's or 11 years of work experience
-
EXPERIENCE - 7 Years of Experience
As a health care system committed to improving the health of those we serve, we are asking our employees to model the same behaviours that we promote to our patients. As of January 1, 2012, Baylor Scott & White Health no longer hires individuals who use nicotine products. We are an equal opportunity employer committed to ensuring a diverse workforce. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.
Vulnerability Management Intern - Cybersecurity
Posted 3 days ago
Job Viewed
Job Description
Building trusted markets — powered by our people.
At Cboe Global Markets, we inspire our people to solve complex challenges together because what we do matters. We provide the financial infrastructure that powers the global economy. As a leading provider of market infrastructure and tradable products, Cboe delivers cutting-edge trading, clearing and investment solutions to market participants around the world.
Cboe interns work with a variety of staff across multiple departments and have the opportunity to put their skills to work in their field of interest, while learning about Exchange technology and operations through our robust Options Institute courses.
The three main foundational pillars of our internship program are: develop, educate and network. We want to ensure each of our interns receive a real-world working experience that encourages academic, professional and personal growth.
Candidates should be versatile, eager and able to work in a fast-paced, time-sensitive financial and technical environment. Our interns will have the flexibility of working 2 days remotely, and 3 days in office per week at one of our state-of-the-art offices in Chicago, Kansas City, and New York City. To be eligible for this internship, applicants must be enrolled in a university or college program and should not be scheduled to graduate before December of the internship year. Our internship program runs from June to August and you will wrap up your internship with a final presentation and retreat. Visit our student page for more information about our internship program!
The Vulnerability Management Team-Cybersecurity is hiring a Vulnerability Management intern.
The Vulnerability Management Intern position will provide exposure to the various functions, tools, and activities focusing on reducing Cboe’s attack surface by way of vulnerability management.
Help us identify and patch all the things!
Your responsibilities and learning objectives will be: As part of a strong, dynamic, global security team, the Vulnerability Management Intern will have the opportunity to learn and contribute via a range of opportunities that provide real-world, hands-on cybersecurity experience.
You will gain experience with patchable network vulnerabilities, application security (appsec) vulnerabilities, operating system vulnerabilities, cloud security vulnerabilities, commercial vulnerability scanning tools, segmented network architectures, systems management automation for both Windows and Linux, and IP address management. You will be introduced to metrics reporting and associated technologies in the context of a global organization. You will interact with members of the entire Global Information Security Team along with Network Engineering, Cloud, Windows Engineering and Linux Engineering teams to identify, report, and help solve problems.
Specific duties may vary based on the experience of the selected candidate, but typical duties within the VMT would include:
- Act on vulnerability findings, spearheading technical communication to resolving teams professionally and accurately
- Assist with day-to-day operational tasks, such as scan result review, IP asset configuration management (CMDB) accuracy improvement, scan issue resolution, and reporting of vulnerabilities to system owners from scan results leveraging a ticketing system
- Remain aware of breaking vulnerability news stories by leveraging various threat intelligence feeds
- Document/improve vulnerability management procedures
- Identify and act upon automation opportunities that could include API programming and leveraging AI and LLM tooling available in-house
- Collaborate with vulnerability management teammates in other times zones. This does include a small number of meetings off-hours, typically in the evening
- Perform additional duties and assignments as requested
The ideal candidate:
- Is currently enrolled in a Bachelor’s or Master’s program in Information Security, Cyber Security, Computer Science, Engineering or equivalent exposure and experience related to these fields and should not be scheduled to graduate before December of the internship year.
- Understands security vulnerabilities in software and systems and comprehends the potential impact if they are left unaddressed
- Should be eager to learn quickly and able to communicate clearly and professionally in English.
- Has base knowledge of security concepts, versed in TCP/IP, common ports/services, and overall networking concepts such as routing, switching and firewalls.
- Is able to perform basic administrative tasks on both Linux and Windows based systems.
- In addition, should have working knowledge of Microsoft Office products including Excel, Word and PowerPoint.
You’ll really stand out with:
- Experience in Python and/or PowerShell automating tasks leveraging calls to REST or Graph API’s.
- Hands on experience doing patching and remediation in a corporate environment to enable authoritative communication with remediation teams
- Familiarity with vulnerability scanners such as Nexpose, Qualys, or Tenable, or Cloud Security Posture Management tooling
- Experience automating with Excel, PowerAutomate, Sigma, or Snowflake
Benefits and Perks
- Competitive compensation
- Flexible, hybrid work environment, 3 days in office, 2 days remote, per week.
- 2:1 401(k) match, up to 8% match immediately upon hire.
Some of our employees’ favorite benefits and perks include:
- Daily complimentary in-office lunch from local restaurants
- Endless free coffee and snacks to fuel your workday
- Monthly in office networking events and happy hours
- Associate Resource Groups (ARGs) and affinity groups for support and community building
More About Cboe Global Markets
We’re reimagining the future of the workplace by focusing on what matters most, our people. Our journey is an inclusive one. We’re investing deeply in leadership programs and career development initiatives that ensure everyone has an equal chance to succeed. We celebrate the diversity in our communities, inside and out, and welcome new perspectives with equity, inclusion and belonging.
We work with purpose, solving problems with ingenuity, collaboration, and a lot of passion. We’re an engaged and excited team connecting markets across borders and embracing growth in all its forms to achieve incredible outcomes.
Learn more about life at Cboe on our website, LinkedIn, and our student page for more information about our internship program!
Equal Employment Opportunity
We're proud to be an equal opportunity employer - and celebrate our employees’ differences, including race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, and Veteran status.
#LI-HL
#Hybrid
Our pay range for interns is determined by function and education level. The national new hire base pay range for this job in the United States is $22.00 - $42.00 per hour. This range represents the minimum and maximum base pay target for new hires working in the position full time.
Within the range, individual pay is determined by years of education completed. In addition to base pay, eligibility for our total rewards program may include benefits such as 401 (k) with a generous company match and paid sick time. Your recruiter will provide more details about the total compensation package during the hiring process
Any communication from Cboe regarding this position will only come from a Cboe recruiter who has a @cboe.com email or via LinkedIn Recruiter. Cboe does not use any otherthird party communication tools for recruiting purposes.
Be The First To Know
About the latest Vulnerability management Jobs in United States !
Vulnerability Management Data Analyst
Posted 3 days ago
Job Viewed
Job Description
Princeton NJ or Berwyn PA or Clifton, NJ or Austin, TX or Atlanta, GA or Sacramento , CA or Boston, MA or Quincy, MA (4 days a week in office)
Full Time
Web Cam Interview
$160-195K/Yr plus Bonus plus Benefit
Role:-
- Recruit an experienced data analyst within its Global Cybersecurity Vulnerability Management team.
- This role involves working with domain experts to develop Client analytics for cybersecurity risk management solutions.
- Analysts apply skill and experience to datasets using SQL and scripting languages to surface meaningful insights and partner with key stakeholders.
- Use your understanding of Security Data Science and Graph Theory to analyse cybersecurity data.
- Work hand in hand with product owners and domain experts from across the Global Cybersecurity organization to develop Client analytics for security and risk management solutions.
- Analyse datasets using SQL and scripting languages to surface meaningful/actionable insights and opportunities to partner teams and other key stakeholders
- Approach problems from first principles, using a variety of statistical and mathematical modeling techniques to research and understand behaviors and interactions
- Build, manage, deploy, and monitor end-to-end analytical solutions to
- Build and share data visualizations and self-serve dashboards for your product team, and support planning, facilitation, and execution of regular communication and coordination across cross-functional teams
- Continually reviewing completeness and accuracy of relevant data platforms
- Maintaining situational awareness, collaborate, influence and lead initiatives across the enterprise
- Work closely with business units to understand people, process, and technology in order to build effective vulnerability management strategies
- The ability to thoroughly evaluate and understand complex data sets
- Knowledge and understanding of vulnerability management and remediation
- Strong organizational, multi-tasking, and prioritizing skills
- Ability to work independently and solve challenging problems
- Knowledge and interest in vulnerability related trends
- Security certification a plus
- Experience within a vulnerability management role
- Ability to work in an environment with a geographically dispersed team
- Bachelor's degree in a quantitative field with a minimum of 8 years of industry experience or PhD in a quantitative technical field with 4+ years of relevant industry experience.
- Direct relevant experience building models and analytics for cybersecurity, insurance, and other data intensive risk management related domains, structuring operational and log data in cloud native analytics environments.
- Demonstrated ability to work as an independent contributor driving research and analyses from conception to implementation with minimal guidance.
- Experience with scripting and data analysis programming languages, such as Python or R and advanced proficiency with SQL and data visualization tools
- Experience with cohort and funnel analyses, population clustering and segmentation techniques, and a deep understanding statistical concepts related to experimental design, selection bias, probability distributions, and Bayesian inference
- Experience answering unstructured questions, driving data-driven solutions, and managing projects and tasks to a conclusion
- Direct experience in the cybersecurity industry building analytics, models and detections (minimum 1-2 years).
- Ability to make difficult decisions in unique situations, present recommendations under pressure to senior leadership and to cross-functional teams that my have conflicting positions
- Demonstrated ability to identify core issues and work with leaders and team members to resolution
- Strong organizational, task switching, and prioritizing skills
- Ability to work independently and solve challenging problems while collaboration with stakeholders
- Advanced presentation skills, both orally and written
- Ability to work well with others and under pressure
- Demonstrated professionalism in approach to communicating ideas and solutions in simple language to team members, senior leaders and business partners
Vulnerability Management Intern - Cybersecurity
Posted 3 days ago
Job Viewed
Job Description
Building trusted markets - powered by our people.
At Cboe Global Markets, we inspire our people to solve complex challenges together because what we do matters. We provide the financial infrastructure that powers the global economy. As a leading provider of market infrastructure and tradable products, Cboe delivers cutting-edge trading, clearing and investment solutions to market participants around the world.
Cboe interns work with a variety of staff across multiple departments and have the opportunity to put their skills to work in their field of interest, while learning about Exchange technology and operations through our robust Options Institute courses.
The three main foundational pillars of our internship program are: develop, educate and network. We want to ensure each of our interns receive a real-world working experience that encourages academic, professional and personal growth.
Candidates should be versatile, eager and able to work in a fast-paced, time-sensitive financial and technical environment. Our interns will have the flexibility of working 2 days remotely, and 3 days in office per week at one of our state-of-the-art offices in Chicago, Kansas City, and New York City. To be eligible for this internship, applicants must be enrolled in a university or college program and should not be scheduled to graduate before December of the internship year. Our internship program runs from June to August and you will wrap up your internship with a final presentation and retreat. Visit our student page for more information about our internship program!
The Vulnerability Management Team-Cybersecurity is hiring a Vulnerability Management intern.
The Vulnerability Management Intern position will provide exposure to the various functions, tools, and activities focusing on reducing Cboe's attack surface by way of vulnerability management.
Help us identify and patch all the things!
Your responsibilities and learning objectives will be: As part of a strong, dynamic, global security team, the Vulnerability Management Intern will have the opportunity to learn and contribute via a range of opportunities that provide real-world, hands-on cybersecurity experience.
You will gain experience with patchable network vulnerabilities, application security (appsec) vulnerabilities, operating system vulnerabilities, cloud security vulnerabilities, commercial vulnerability scanning tools, segmented network architectures, systems management automation for both Windows and Linux, and IP address management. You will be introduced to metrics reporting and associated technologies in the context of a global organization. You will interact with members of the entire Global Information Security Team along with Network Engineering, Cloud, Windows Engineering and Linux Engineering teams to identify, report, and help solve problems.
Specific duties may vary based on the experience of the selected candidate, but typical duties within the VMT would include:
- Act on vulnerability findings, spearheading technical communication to resolving teams professionally and accurately
- Assist with day-to-day operational tasks, such as scan result review, IP asset configuration management (CMDB) accuracy improvement, scan issue resolution, and reporting of vulnerabilities to system owners from scan results leveraging a ticketing system
- Remain aware of breaking vulnerability news stories by leveraging various threat intelligence feeds
- Document/improve vulnerability management procedures
- Identify and act upon automation opportunities that could include API programming and leveraging AI and LLM tooling available in-house
- Collaborate with vulnerability management teammates in other times zones. This does include a small number of meetings off-hours, typically in the evening
- Perform additional duties and assignments as requested
- Is currently enrolled in a Bachelor's or Master's program in Information Security, Cyber Security, Computer Science, Engineering or equivalent exposure and experience related to these fields and should not be scheduled to graduate before December of the internship year.
- Understands security vulnerabilities in software and systems and comprehends the potential impact if they are left unaddressed
- Should be eager to learn quickly and able to communicate clearly and professionally in English.
- Has base knowledge of security concepts, versed in TCP/IP, common ports/services, and overall networking concepts such as routing, switching and firewalls.
- Is able to perform basic administrative tasks on both Linux and Windows based systems.
- In addition, should have working knowledge of Microsoft Office products including Excel, Word and PowerPoint.
- Experience in Python and/or PowerShell automating tasks leveraging calls to REST or Graph API's.
- Hands on experience doing patching and remediation in a corporate environment to enable authoritative communication with remediation teams
- Familiarity with vulnerability scanners such as Nexpose, Qualys, or Tenable, or Cloud Security Posture Management tooling
- Experience automating with Excel, PowerAutomate, Sigma, or Snowflake
- Competitive compensation
- Flexible, hybrid work environment, 3 days in office, 2 days remote, per week.
- 2:1 401(k) match, up to 8% match immediately upon hire.
- Daily complimentary in-office lunch from local restaurants
- Endless free coffee and snacks to fuel your workday
- Monthly in office networking events and happy hours
- Associate Resource Groups (ARGs) and affinity groups for support and community building
More About Cboe Global Markets
We're reimagining the future of the workplace by focusing on what matters most, our people. Our journey is an inclusive one. We're investing deeply in leadership programs and career development initiatives that ensure everyone has an equal chance to succeed. We celebrate the diversity in our communities, inside and out, and welcome new perspectives with equity, inclusion and belonging.
We work with purpose, solving problems with ingenuity, collaboration, and a lot of passion. We're an engaged and excited team connecting markets across borders and embracing growth in all its forms to achieve incredible outcomes.
Learn more about life at Cboe on our website, LinkedIn, and our student page for more information about our internship program!
Equal Employment Opportunity
We're proud to be an equal opportunity employer - and celebrate our employees' differences, including race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, and Veteran status.
#LI-HL
#Hybrid
Our pay range for interns is determined by function and education level. The national new hire base pay range for this job in the United States is $22.00 - $42.00 per hour. This range represents the minimum and maximum base pay target for new hires working in the position full time.
Within the range, individual pay is determined by years of education completed. In addition to base pay, eligibility for our total rewards program may include benefits such as 401 (k) with a generous company match and paid sick time. Your recruiter will provide more details about the total compensation package during the hiring process
Any communication from Cboe regarding this position will only come from a Cboe recruiter who has a @cboe.com email or via LinkedIn Recruiter. Cboe does not use any other third party communication tools for recruiting purposes.
Manager of Vulnerability Management
Posted 9 days ago
Job Viewed
Job Description
At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world's largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine's Top Company Cultures list and ranked among the World's Most Innovative Companies by Fast Company.
We realize people do not fit into neat boxes. We are looking for curious and empathetic individuals who are committed to developing themselves and learning new skills, and we are ready to help you do that. We cannot complete our mission without building a diverse and inclusive team. We hire the best people based on an evaluation of their potential and support them throughout their time at Cloudflare. Come join us!
Available Locations: Lisbon, Portugal or London, UK
Cloudflare is seeking a highly motivated and experienced Manager of Vulnerability Management to lead our efforts in identifying, assessing, prioritising, and remediating security vulnerabilities across our technology landscape. This critical role will be responsible for developing, implementing, and maintaining a robust vulnerability management program that effectively reduces our organisation's risk exposure. The ideal candidate will possess strong technical expertise, excellent leadership skills, and a deep understanding of cybersecurity best practices.
Responsibilities:
- Program Leadership and Strategy:
- Develop, implement, and maintain the organisation's vulnerability management strategy, policies, standards, and procedures.
- Define and track key performance indicators (KPIs) and metrics to measure the effectiveness of the vulnerability management program.
- Stay abreast of the latest vulnerability trends, threats, and industry best practices.
- Contribute to the overall cybersecurity strategy and risk management efforts of the organisation.
- Vulnerability Identification and Assessment:
- Oversee the regular execution of vulnerability scanning activities across various environments (e.g., network, applications, containers, cloud).
- Manage and optimize vulnerability scanning tools and processes to ensure comprehensive and accurate identification of weaknesses.
- Align with asset inventory and system categorisation for effective vulnerability scanning and management.
- Vulnerability Analysis and Prioritisation:
- Lead the analysis of vulnerability scan results.
- Develop and implement a risk-based prioritisation framework for vulnerabilities based on severity, exploitability, asset criticality, and business impact.
- Collaborate with relevant teams to understand the context and potential impact of identified vulnerabilities.
- Remediation and Mitigation:
- Work closely with engineering and other stakeholders to define remediation plans and timelines for identified vulnerabilities.
- Track and monitor the progress of vulnerability remediation efforts, ensuring adherence to established SLAs.
- Facilitate the development and implementation of mitigating controls when immediate remediation is not feasible.
- Provide guidance and support to teams on vulnerability prevention and security best practices.
- Reporting and Communication:
- Develop and deliver clear and concise reports on vulnerability status, trends, remediation progress, and adherence to remediation SLAs to management and relevant stakeholders.
- Communicate effectively with technical and non-technical audiences regarding vulnerability risks and remediation efforts.
- Escalate critical vulnerabilities and remediation roadblocks in a timely manner.
- Team Leadership and Development:
- Build, mentor, and manage a high-performing vulnerability management team.
- Assign tasks, set goals, and provide regular feedback and coaching to team members.
- Foster a collaborative and knowledge-sharing environment within the team.
- Support the professional development and training of team members.
- Tooling and Automation:
- Evaluate, select, and implement vulnerability management tools and technologies.
- Drive automation efforts to streamline vulnerability scanning, analysis, and reporting processes.
- Integrate vulnerability management tools with other security and engineering systems.
- Compliance and Audit:
- Ensure the vulnerability management program aligns with relevant regulatory requirements, industry standards, internal policies and control requirements.
- Support internal and external audits related to vulnerability management practices.
Qualifications:
- Bachelor's degree in Computer Science, Information Security, or a related field.
- Experience in information security, with a significant focus on vulnerability management.
- Proven experience in leading and managing vulnerability assessment and remediation efforts across diverse environments.
- Strong understanding of common vulnerability scoring systems (e.g., CVSS) and risk assessment methodologies.
- Experience with vulnerability scanning tools (e.g., Qualys, Nessus, Rapid7 InsightVM) and Unified Vulnerability & Exposure Management tools (e.g. TruRisk, Brinqa, Nucleus)
- Experience with static and runtime container scanning technologies.
- Familiarity with application security testing tools and techniques (SAST/DAST).
- Knowledge of security frameworks and standards (e.g., NIST, ISO 27001).
- Excellent analytical, problem-solving, and decision-making skills.
- Strong communication (written and verbal) and interpersonal skills, with the ability to effectively collaborate with technical and non-technical teams.
- Proven ability to lead and motivate a team (if applicable).
- Experience with scripting languages (e.g., Python) for automation.
- Experience with threat intelligence platforms and integrating threat data into vulnerability prioritisation.
What Makes Cloudflare Special?
We're not just a highly ambitious, large-scale technology company. We're a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet.
Project Galileo : Since 2014, we've equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare's enterprise customers--at no cost.
Athenian Project : In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, we've provided services to more than 425 local government election websites in 33 states.
1.1.1.1 : We released 1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released. Here's the deal - we don't store client IP addresses never, ever. We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers.
Sound like something you'd like to be a part of? We'd love to hear from you!
This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license.
Cloudflare is proud to be an equal opportunity employer. We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness. All qualified applicants will be considered for employment without regard to their, or any other person's, perceived or actual race, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law. We are an AA/Veterans/Disabled Employer.
Cloudflare provides reasonable accommodations to qualified individuals with disabilities. Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment. If you require a reasonable accommodation to apply for a job, please contact us via e-mail at or via mail at 101 Townsend St. San Francisco, CA 94107.