> Markdown version of [/jobs/ext/1182434-vulnerability-cloud-security-program-manager](https://www.wearedevelopers.com/jobs/ext/1182434-vulnerability-cloud-security-program-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Vulnerability & Cloud Security Program Manager - **Company:** NinjaOne, LLC - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $180,000.0 - $220,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Cloud Computing Security, Cloud Engineering, Cyber Security, DevOps, PCI Data Security Standards, Software Vulnerability Management, Information Technology, Nessus, CIS Benchmarks, Vulnerability Analysis - **Published:** July 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=5bfb4d87a301d5fa ## About the Role * Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience. * 5+ years of experience in vulnerability management and at least 2+ years in cloud security. * Hands-on experience with CSPM tools, vulnerability detection platforms, and automation (Wiz, AWS Inspector, Nessus, OpenSCAP preferred). * Strong understanding of AWS security best practices and cloud-native architectures. * Familiarity with vulnerability scoring systems like CVSS and risk-based prioritization. * Excellent communication, collaboration, and stakeholder management skills. * Security certifications such as CISSP, AWS Security Specialty, or GIAC Cloud Security are a plus. * Preferred knowledge of regulatory and compliance frameworks such as PCI DSS, HIPAA, SOX, FedRAMP. ## Description The Vulnerability & Cloud Security Program Manager leads the enterprise vulnerability management and cloud security posture management (CSPM) programs, ensuring timely identification, assessment, prioritization, and remediation of risks across on-premise, cloud, and application environments. This role leverages modern cloud security and vulnerability management platforms to monitor, analyze, and strengthen our security posture. You will collaborate closely with engineering, DevOps, and infrastructure teams to reduce risk exposure, support compliance obligations, and advance the organization's overall security maturity. Location - We are flexible on remote working from home, if you are located in the USA and reside in one of the following states - CA, CO, CT, FL, GA, *IL, KS, ME, MA, MD, NJ, NC, NY, OR, TN, TX, VA, and WA. We have physical offices in Austin, TX and Tampa, FL, if you prefer a hybrid option. What You'll Be Doing * Lead and operate the full vulnerability management and CSPM lifecycle, ensuring timely discovery, assessment, prioritization, and remediation. * Administer and optimize our vulnerability management and CSPM platforms, including policies, integrations, reporting, and automation. * Monitor cloud and infrastructure environments to identify misconfigurations, excessive permissions, and compliance drift, primarily in AWS. * Partner with engineering and DevOps teams to drive remediation efforts, facilitate triage discussions, and provide technical guidance on complex issues. * Align security practices with frameworks such as FedRAMP, NIST CSF, ISO 27001, and CIS Controls. * Track and report key KPIs and risk metrics to leadership, including SLA compliance and vulnerability trends. * Automate detection, remediation workflows, and tool integrations to enhance efficiency and expand security capabilities * Other duties as needed ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)