Vulnerability & Cloud Security Program Manager

NinjaOne, LLC
United States
2 months ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$180,000.0 - $220,000.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Cloud Computing Security Cloud Engineering Cyber Security DevOps PCI Data Security Standards Software Vulnerability Management Information Technology Nessus CIS Benchmarks Vulnerability Analysis

Job description

The Vulnerability & Cloud Security Program Manager leads the enterprise vulnerability management and cloud security posture management (CSPM) programs, ensuring timely identification, assessment, prioritization, and remediation of risks across on-premise, cloud, and application environments. This role leverages modern cloud security and vulnerability management platforms to monitor, analyze, and strengthen our security posture. You will collaborate closely with engineering, DevOps, and infrastructure teams to reduce risk exposure, support compliance obligations, and advance the organization’s overall security maturity. Location - We are flexible on remote working from home, if you are located in the USA and reside in one of the following states - CA, CO, CT, FL, GA, *IL, KS, ME, MA, MD, NJ, NC, NY, OR, TN, TX, VA, and WA. We have physical offices in Austin, TX and Tampa, FL, if you prefer a hybrid option. What You’ll Be Doing

  • Lead and operate the full vulnerability management and CSPM lifecycle, ensuring timely discovery, assessment, prioritization, and remediation.

  • Administer and optimize our vulnerability management and CSPM platforms, including policies, integrations, reporting, and automation.

  • Monitor cloud and infrastructure environments to identify misconfigurations, excessive permissions, and compliance drift, primarily in AWS.

  • Partner with engineering and DevOps teams to drive remediation efforts, facilitate triage discussions, and provide technical guidance on complex issues.

  • Align security practices with frameworks such as FedRAMP, NIST CSF, ISO 27001, and CIS Controls.

  • Track and report key KPIs and risk metrics to leadership, including SLA compliance and vulnerability trends.

  • Automate detection, remediation workflows, and tool integrations to enhance efficiency and expand security capabilities

  • Other duties as needed

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience.

  • 5+ years of experience in vulnerability management and at least 2+ years in cloud security.

  • Hands-on experience with CSPM tools, vulnerability detection platforms, and automation (Wiz, AWS Inspector, Nessus, OpenSCAP preferred).

  • Strong understanding of AWS security best practices and cloud-native architectures.

  • Familiarity with vulnerability scoring systems like CVSS and risk-based prioritization.

  • Excellent communication, collaboration, and stakeholder management skills.

  • Security certifications such as CISSP, AWS Security Specialty, or GIAC Cloud Security are a plus.

  • Preferred knowledge of regulatory and compliance frameworks such as PCI DSS, HIPAA, SOX, FedRAMP.

Benefits & conditions

4.04.0 out of 5 stars Remote $180,000 - $220,000 a year - Full-time, Pulled from the full job description

  • 401(k)
  • Health insurance
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Life insurance
  • Unlimited paid time off, We are a collaborative, kind, and curious community. We honor your flexibility needs with full-time work that is hybrid remote. We have you covered with our comprehensive benefits package, which includes medical, dental, and vision insurance. We help you prepare for your financial future with our 401(k) plan. We prioritize your work-life balance with our unlimited PTO. We reward your work with opportunity for growth and advancement. Additional Information This position is NOT eligible for Visa sponsorship. Due to federal government security requirements associated with our FedRAMP-authorized environment, candidates must be U.S. citizens or lawful permanent residents.

  • Due to operational policies, NinjaOne is unable to hire for this role within the city limits of Chicago. We will consider all qualified candidates who reside outside of the city proper or are willing to self-relocate.

Starting pay for the successful applicant depends on a variety of job-related factors, including but not limited to location, market demands, experience, job-related knowledge, and skills. The benefits available for this position include medical, dental, vision, 401(k) plan, life insurance coverage and PTO. For roles based in California, Colorado, Maryland, New Jersey, or Washington the base salary hiring range for this position is$180,000 to $220,000 per year. For roles based in New York, the base salary hiring range for this position is $180,000 to $220,000 per year. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, marital status, veteran status, or any other status protected by applicable law. We are committed to providing an inclusive and diverse work environment.

About the company

NinjaOne automates the hardest parts of IT to deliver visibility, security, and control over all endpoints for more than 40,000 customers. The NinjaOne automated endpoint management platform is proven to increase productivity, reduce security risk, and lower costs for IT teams and managed service providers. NinjaOne is obsessed with customer success and provides free and unlimited onboarding, training, and support. NinjaOne is #1 on G2 in endpoint management, patch management, remote monitoring and management, and mobile device management.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

5:30 min

Identifying non-coding software vulnerabilities and organizational risks

Tino Sokic · World Congress 2023

Videos

See all

Related articles

See all