> Markdown version of [/jobs/ext/1911867-manager-vulnerability-management](https://www.wearedevelopers.com/jobs/ext/1911867-manager-vulnerability-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Manager, Vulnerability Management - **Company:** Pfizer Inc. - **Location:** New York, NY, United States - **Experience:** Experienced - **Salary:** $116,000.0 - $193,400.0 - **Contract:** Permanent contract - **Skills:** CompTIA Security+, Cyber Security, Digital Assets, Cloud Services, Software Vulnerability Management, Cyber Threat Analysis, Information Technology, Cyber Warfare, Vulnerability Analysis - **Published:** August 4, 2026 - **Apply:** http://hbcu.com/cgi-bin/jobs/searchJobs.cgi?job_id=35170239 ## About the Role * Applicant must have a bachelor's degree in Information Security, Computer Science, Engineering, Information Technology, or a related field with at least 4 years of experience in cybersecurity, with a strong focus on vulnerability management, security operations, or exposure management; OR a master's degree with at least 2 years of experience; OR as associate's degree with 8 years of experience; OR a high school diploma (or equivalent) and 10 years of relevant experience. * Demonstrated responsibility for executing or overseeing vulnerability scanning, assessment, prioritization, and remediation tracking across infrastructure, endpoints, cloud platforms, or applications. * Experience translating vulnerability findings into riskbased remediation guidance for infrastructure, cloud, application, or platform engineering teams. * Prior responsibility for coordinating remediation activities, including tracking ownership, validating fixes, managing exceptions, and escalating blocked or overdue items. * Familiarity with vulnerability severity, exploitability concepts, and compensating controls used to manage risk when immediate remediation is not feasible. * Experience leading analysts or serving as a technical lead responsible for task prioritization, quality assurance, and daytoday delivery. * Strong analytical, organizational, and problemsolving skills. * Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach., * Familiarity with vulnerability management in cloud or hybrid enterprise environments. * Understanding of integrating threat context, exploitability, or attack paths into vulnerability prioritization. * Exposure to operating in regulated or highly controlled environments such as healthcare, life sciences, or manufacturing. * Experience supporting audit, compliance, or regulatory activities related to vulnerability management. * Ability to identify trends and drive process or control improvements over time. * Relevant professional certifications in cybersecurity or vulnerability management (e.g., CISSP, CISM, Security+, etc.) PHYSICAL/MENTAL REQUIREMENTS * No special physical requirements. * Applicants should be capable of working through a personal laptop computer or mobile device for extended periods. NON-STANDARD WORK SCHEDULE, TRAVEL OR ENVIRONMENT REQUIREMENTS * Travel as required by the business (less than 5% domestic and/or international) * Work Location Assignment: Must be able to work in assigned Pfizer office 2-3 days per week, or as needed by the business * This role is NOT remote ## Description Our Global Cyber Defense team is responsible for safeguarding Pfizers digital assets and infrastructure through proactive threat detection, response, and risk mitigation across on-premises, cloud, and hybrid environments. The Manager, Vulnerability Management is responsible for leading the execution of vulnerability management activities to identify, assess, prioritize, and reduce security weaknesses across the enterprise. This role oversees daytoday vulnerability management operations, including scanning, analysis, prioritization, and remediation coordination. The role partners closely with engineering, infrastructure, cloud services, application, and security teams to ensure vulnerabilities are addressed in a timely, riskbased, and compliant manner to reduce overall cyber exposure., * Lead the daytoday execution of the vulnerability management program, ensuring consistent identification, assessment, and prioritization of vulnerabilities across enterprise environments. * Manage and develop a team of vulnerability management analysts, providing technical guidance, prioritization, coaching, and performance feedback. * Oversee vulnerability scanning activities across infrastructure, endpoints, cloud platforms, and applications, ensuring coverage and data quality. * Translate vulnerability findings into clear, actionable remediation guidance for technical owners, aligned to risk, exploitability, and business impact. * Coordinate remediation efforts with Infrastructure, Cloud Services, Engineering, Endpoint Security, and other technology teams to drive timely risk reduction. * Partner with Threat Intelligence, Threat Remediation, and Incident Response teams to incorporate threat context and active exploitation signals into prioritization decisions. * Track remediation progress, validate closure, and identify recurring issues or systemic control gaps requiring escalation or broader corrective action. * Ensure vulnerability management activities align with internal policies, regulatory requirements, and audit expectations. * Maintain reporting and metrics on vulnerability trends, remediation performance, and risk posture for Cyber Defense leadership. * Drive continuous improvement of vulnerability management processes, tooling, and workflows to increase efficiency, accuracy, and impact., Pfizer reports payments and other transfers of value to health care providers as required by federal and state transparency laws and implementing regulations. These laws and regulations require Pfizer to provide government agencies with information such as a health care providers name, address and the type of payments or other value received, generally for public disclosure. Subject to further legal review and statutory or regulatory clarification, which Pfizer intends to pursue, reimbursement of recruiting expenses for licensed physicians may constitute a reportable transfer of value under the federal transparency law commonly known as the Sunshine Act. Therefore, if you are a licensed physician who incurs recruiting expenses as a result of interviewing with Pfizer that we pay or reimburse, your name, address and the amount of payments made currently will be reported to the government. If you have questions regarding this matter, please do not hesitate to contact your Talent Acquisition representative. ## Related Videos - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Tokenization of Everything: Where the Real World Meets Blockchain](https://www.wearedevelopers.com/videos/1035-tokenization-of-everything-where-the-real-world-meets-blockchain) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Run on Bitcoin](https://www.wearedevelopers.com/videos/29-run-on-bitcoin) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Remote Jobs](https://www.wearedevelopers.com/magazine/255-best-paying-remote-jobs)