Manager, Vulnerability Management

Vanguard
Dallas, TX, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours

Tech stack

Artificial Intelligence Amazon Web Services Microsoft Azure Cloud Computing Security Databases Software Vulnerability Management Working Model 2D Cyber Threat Analysis Tenable Nessus Devsecops

Job description

Experteer Overview In this role you will lead a Vulnerability Management team within a hybrid/multi-cloud environment to reduce Vanguard’s attack surface. You’ll drive CTEM, AI-enabled automation, and scalable guardrails, partnering across security and engineering to balance risk reduction with operational efficiency. You’ll shape the program, evolve processes, and deliver measurable security improvements at scale. This is a chance to lead a growing function and influence risk posture in a mission-driven, collaborative culture. Compensation / Benefits * Evolve and lead the Vulnerability Management program, integrating VulnOps concepts and AI-enabled operations. * Manage and develop a high-performing team capable of monitoring on-prem and multi-cloud assets for vulnerabilities and config weaknesses. * Collaborate with SOC, Cyber Threat Intelligence, Red/Blue teams, PatchOps, and other stakeholders to refine prioritization and remediation strategies. * Oversee false-positive investigations, risk-acceptance requests, and risk-rating adjustments. * Coordinate hardening of OS, database, and telecom infrastructure to ensure standards compliance. * Shape remediation SLAs, policies, and guardrails to enforce secure configurations. * Develop metrics, KPIs, and OKRs to measure program effectiveness. * Coordinate with engineering platform teams to tune scanning tools for better visibility and security alignment. * Drive continuous process improvement and automation to fuse data from different sources and streamline remediation ownership. * Provide industry expertise on emerging security practices and standards. Tasks * Minimum 6 years in cybersecurity domains (vulnerability management, DevSecOps, cloud security, or related) * At least 2 years managing vulnerabilities at scale * Excellent leadership and people-management track record * Strong understanding of CVSS, exploitability, and risk-based prioritization * Experience with AWS, Azure, or GCP and cloud security principles * Understanding of CI/CD pipelines and AI-assisted code development * Undergraduate degree in a related field (or equivalent) * Analytical and problem-solving skills with ability to mitigate complex risks * Excellent communication and collaboration skills across levels of an organization Key requirements * hybrid working model * mission-driven culture

Requirements

Overview risk-acceptance requests, and risk-rating adjustments. * Coordinate hardening of OS, database, and telecom infrastructure to ensure standards compliance. * Shape remediation SLAs, policies, and guardrails to enforce secure configurations. * Develop metrics, KPIs, and OKRs to measure program effectiveness. * Coordinate with engineering platform teams to tune scanning tools for better visibility and security alignment. * Drive continuous process improvement and automation to fuse data from different sources and streamline remediation ownership. * Provide industry expertise on emerging security practices and standards. Tasks * Minimum 6 years in cybersecurity domains (vulnerability management, DevSecOps, cloud security, or related) * At least 2 years managing vulnerabilities at scale * Excellent leadership and people-management track record * Strong understanding of CVSS, exploitability, and risk-based prioritization * Experience with AWS, Azure, or GCP and cloud security aaaaaaaa to * Understanding of CI/CD pipelines and AI-assisted code development * Undergraduate degree in a related field (or equivalent) * Analytical and problem-solving skills with ability to mitigate complex risks * Excellent communication and collaboration skills across levels of an organization Key requirements * hybrid working model * mission-driven culture

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:06 min

Collaborating on risk appetite and CVE remediation strategies

Marcus Ross Marcus Ross · WWC Europe 2026

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

2:55 min

Prioritizing system vulnerabilities and enhancing automated security posture

Raz Cohen · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · WWC 2022

Videos

See all

Related articles

See all