Cyber Security Lead Specialist
Role details
Job location
Tech stack
Job description
The Cyber Security Lead Specialist for Vulnerability Management provides strategic direction and subject-matter expertise for the enterprise vulnerability management program. This role is responsible for managing security tools and continuously improving applications and infrastructure related to vulnerability management. The specialist will act as a trusted advisor, translating technical risk into actionable business insights for various internal teams., * Oversee the end-to-end vulnerability lifecycle, including asset management, discovery, validation, prioritization, remediation, and closure.
- Monitor threat intelligence sources to proactively assess exposure and recommend mitigation strategies.
- Establish and enforce remediation Service Level Agreements (SLAs) and exception handling processes.
- Partner with system owners and engineering teams to prioritize and remediate vulnerabilities across application, infrastructure, and cloud services.
- Serve as the primary owner and subject matter expert for Qualys VMDR, managing asset discovery, vulnerability scanning, and configuration compliance.
- Own and manage ServiceNow Vulnerability Response (VR) as the system of record for vulnerability tracking and remediation.
- Develop and deliver Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) related to vulnerability exposure and risk reduction.
- Build and present executive-level dashboards and reports using Qualys, ServiceNow, and other integrated data sources.
Requirements
- 5-7+ years of progressive experience in cybersecurity, with a deep specialization in Qualys vulnerability management.
- Demonstrated success owning or leading an enterprise vulnerability management program.
- Proven experience driving remediation outcomes across large, distributed technology environments.
Technical Skills:
- Expert knowledge of vulnerability management frameworks and risk-based prioritization models.
- Extensive hands-on experience with enterprise vulnerability management tools, with Qualys being a mandatory requirement.
- Experience with ServiceNow, particularly the Vulnerability Response (VR) module.
- Strong understanding of infrastructure, cloud, endpoint, and network security architectures.
- Experience with cloud-native security tools, CSPM platforms, and executive reporting tools., * Proven ability to lead cross-functional initiatives.
- Strong analytical skills with the ability to synthesize large datasets into actionable insights.
- Executive-level communication skills, with the ability to influence and advise senior stakeholders.
Preferred Qualifications
- Familiarity with securing AI systems.