> Markdown version of [/jobs/ext/2025993-principal-cloud-security-and-vulnerability](https://www.wearedevelopers.com/jobs/ext/2025993-principal-cloud-security-and-vulnerability). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Cloud Security and Vulnerability - **Company:** THE JUDGE GROUP, INC. - **Location:** Chicago, IL, United States - **Experience:** Expert - **Salary:** $208,000.0 - $270,400.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Cloud Computing Security, Cyber Security, Linux, Information Technology Operations, Windows Servers, Red Hat Enterprise Linux, VMware VSphere, Software Vulnerability Management, Cloud Platform System, Information Technology, Patch Management, Qualys, Security Orchestration, Automation & Response, Servicenow, Vmware - **Published:** August 11, 2026 - **Apply:** https://www.dice.com/job-detail/5e4cd758-1657-43a5-95db-b638a53dcd0d ## About the Role * 10+ years of experience in vulnerability management, patch management, IT operations, or cybersecurity. * Strong background in server, network, and cloud administration with expertise in securing complex hybrid environments. * Proven success leading enterprise remediation efforts and influencing cross-functional teams without direct authority. * Bachelor's degree in Computer Science, Engineering, Information Technology, or equivalent experience. * Industry certifications such as CISSP, ITIL, CCSP or related credentials preferred. ## Description Serve as the technical cloud security leader for enterprise-wide patching and vulnerability management initiatives across hybrid infrastructure environments, including on-premises systems and AWS cloud platforms. Partner closely with infrastructure, platform engineering, and security teams to strengthen the organization's cyber resilience, accelerate remediation efforts, and drive operational excellence., * Lead and coordinate enterprise patch management and vulnerability remediation programs across server, network, and cloud environments, ensuring alignment, accountability, and consistent execution. * Design and enhance workflows, automation strategies, and governance frameworks that improve vulnerability management effectiveness and streamline operations. * Drive integration and optimization of security technologies, including Qualys and ServiceNow Security Vulnerability Response (SVR), to increase visibility, tracking, and remediation efficiency. * Develop and mature patching strategies that support rapid, risk-based vulnerability remediation while maintaining stability in highly available, 24/7 production environments. * Provide technical leadership across both traditional infrastructure and AWS cloud ecosystems, establishing consistent security and patching standards across all platforms. * Identify opportunities for automation, process improvement, and innovation to reduce remediation timelines and strengthen overall operational security posture. * Mentor and collaborate with cross-functional teams, fostering knowledge sharing, continuous learning, and a culture of security-focused operations. Core Expertise: * Vulnerability Management & Risk-Based Remediation * Enterprise Patch Lifecycle Management * Hybrid Infrastructure Security (On-Premises & AWS) * Qualys Vulnerability Management * ServiceNow Security Vulnerability Response (SVR) * CVE Analysis, CVSS Scoring & Prioritization * Zero-Day & Critical Vulnerability Response * Windows Server, Linux (RHEL), VMware/vSphere Administration * Security Automation & Workflow Optimization * Cross-Functional Leadership & Stakeholder Management ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [WebAssembly: The Next Frontier of Cloud Computing](https://www.wearedevelopers.com/videos/972-webassembly-the-next-frontier-of-cloud-computing) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Generating code with Angular schematics](https://www.wearedevelopers.com/videos/129-generating-code-with-angular-schematics) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)