> Markdown version of [/jobs/ext/190180-manager-cloud-infrastructure-vulnerability-usds](https://www.wearedevelopers.com/jobs/ext/190180-manager-cloud-infrastructure-vulnerability-usds). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Manager, Cloud & Infrastructure Vulnerability - USDS - **Company:** Tiktok Inc. - **Location:** Washington, DC, United States - **Experience:** Experienced - **Salary:** $132,480.0 - $336,960.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), JIRA, Bash Shell, Cloud Computing, Cloud Computing Security, Configuration Management, Cyber Security, Identity and Access Management, Networking Hardware, Python (Programming Language), Microsoft Office, Windows PowerShell, Cloud Services, Ansible, Software Vulnerability Management, Wi-Fi Technology, Mttr, Firewalls (Computer Science), Infrastructure as Code (IaC), RSA Archer Platform, CIS Benchmarks, Terraform, Oracle Cloud Infrastructure, Qualys, Servicenow - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=cfeb7f04a00a17b9 ## About the Role * Experience: 5+ years in Cybersecurity, with at least 3+ years leading a Vulnerability Management or Security Operations team. * Cloud Expertise: Hands-on experience securing Oracle Cloud Infrastructure (OCI); familiarity with OCI VCNs, IAM, and Compute security. (Experience with AWS/Azure/GCP is also acceptable). * Tooling Mastery: Advanced proficiency with Wiz (Cloud Security Posture Management) and Qualys (VMDR/Policy Compliance). * Framework Knowledge: Strong understanding of NIST 800-53, ISO 27001, and CIS Benchmarks as they apply to vulnerability and configuration management. * Technical Skills: Ability to write scripts (Python, Bash, or PowerShell) to automate data export/normalization or interact with security tool APIs., * Certifications: OCI Architect/Security Associate, Qualys Certified Specialist, or Wiz specialized training. Industry standards like CISSP, CCSP, or CISM. * Infrastructure as Code (IaC): Experience reviewing Terraform or Ansible for security misconfigurations before deployment. * Automation: Experience integrating vulnerability data into ITSM tools (ServiceNow, Jira) for automated ticket routing and tracking. * Communication: Proven ability to explain the "so what?" of a vulnerability to non-technical stakeholders and business owners. ## Description About the Team The Validation and Verification (VnV) organization ensures the security and reliability of our products by validating that security controls are implemented correctly, operating effectively, and delivering measurable risk reduction across the enterprise. VnV operates across a continuous security lifecycle: Prevent * Assure * Test * Fix * Prove, ensuring that security posture is not only designed and tested, but continuously validated in real-world conditions. About the Role We are looking for a Vulnerability Management expert to lead the identification, prioritization, and remediation of security flaws across our specialized cloud environments and corporate office infrastructure. This role is at the heart of our defense strategy: you aren't just running scans; you are architecting a risk-based program that secures the very foundation of USDS. You will lead a team of security practitioners to manage the full vulnerability lifecycle, from agent deployment in OCI to securing the physical and digital footprint of our office environments. By leveraging industry-leading tools like Wiz for cloud-native visibility and Qualys for deep asset assessment, you will ensure that our attack surface is minimized and our compliance with ISO 27001 and other standards is absolute. Responsibilities * Program Leadership: Build and scale the Vulnerability Management (VM) function for USDS, covering both Cloud and Office/Corporate Infrastructure. * Cloud-Native Security: Utilize tools like Wiz to perform agentless scanning, analyze the "Security Graph" for toxic combinations, and identify misconfigurations within our Oracle Cloud (and other cloud) tenancies. * Infrastructure Scanning: Manage the deployment and tuning of Qualys (Vulnerability Management, Detection and Response - VMDR) for corporate endpoints, servers, and office network appliances. * Risk-Based Prioritization: Move beyond "critical/high" labels by correlating vulnerability data with threat intelligence and business context to drive the most impactful remediation efforts first. * Cross-Functional Orchestration: Partner with SRE, IT, and Engineering teams to establish patching SLAs, automate remediation workflows, and provide technical guidance on complex "won't-fix" or exception scenarios. * Office Infrastructure Security: Oversee the security posture of office networks, including firewalls, Wi-Fi controllers, and IoT devices, ensuring corporate environments meet USDS-specific hardening standards. * Reporting & Governance: Define and report on key risk metrics (MTTR, scan coverage, patch compliance) for executive leadership and external auditors. * Tooling Optimization: Act as the primary administrator for the Vulnerability Management toolset, ensuring 100% asset visibility and integrating findings into Jira and GRC platforms. ## Related Videos - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Integrate your Cognitive Assistant with 3rd-party DBs and software](https://www.wearedevelopers.com/videos/249-integrate-your-cognitive-assistant-with-3rd-party-dbs-and-software) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)