> Markdown version of [/jobs/ext/2278682-manager-vulnerability-management-and-application-security](https://www.wearedevelopers.com/jobs/ext/2278682-manager-vulnerability-management-and-application-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Manager, Vulnerability Management and Application Security - **Company:** Cornerstone Barricades - **Location:** Bethpage, NY, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Information Systems Security Architecture Professional, Red Team (Cyber Security), Software Vulnerability Management, Software Security, Cyber Threat Analysis, Information Technology, Cybercrime, Tools for Reporting, Devsecops, Vulnerability Analysis - **Published:** August 28, 2026 - **Apply:** https://pseg-1.betterteam.com/manager-vulnerability-management-and-application-security/apply/standard ## About the Role techniques in an evolving artificial intelligence driven world. You must also possess excellent problem-solving and communication skills and proven people management experience., * Bachelor's degree and 8 years of relevant cyber security experience + Candidates without a degree, will need 12 years of cyber experience. * Experience within vulnerability/compliance management, penetration testing, and/or threat hunting. * Ability to present to all levels of management and executive leadership. * Excellent teamwork, facilitation, relationship building, and negotiation skills. * Able to maintain positive working relationships both leading and as part of a team. * Effective time management skills and able to multi-task effectively. * Able to communicate effectively with both technical and non-technical individuals. * Compliance with the Department of Energy's regulation 10 CFR 810 is required. Desired: * Certified Information Systems Security Professional (CISSP), or equivalent. ## Description This position leads Information Security staff in the evaluation of risks and threats, development, implementation, communication, operation, monitoring and maintenance of the IT security policies and procedures to promote secure and uninterrupted operation of all IT systems, applications and infrastructure. In this role, you will be responsible for proactively identifying, prioritizing, and tracking security vulnerabilities across the PSEG's network and systems. You will also be responsible for conducting security assessments, running penetration tests, review Cyber threat intelligence and providing relevant data to parties to action upon. This role will perform red team exercises mimicking adversary practices while leveraging similar tools and techniques. To be successful in this role you must have a broad understanding of information security and experience in application security, DevSecOps (Development, Security, and Operations) vulnerability management, and cyber exploitation, * Cyber Assessment & Vulnerability Management lead is responsible for the overall lifecycle of the Cyber Assessment & Vulnerability Management program. * Inform, advise, and partner with IT, Security, and other business units to help better secure their operations. Identify gaps in current processes, workflows, and design and recommend changes or enhancements as needed. * Participate in Change Management Process, from early Assessment of proposed changes/enhancements, through Vulnerability scanning and recommended remediation before go-live. * Participate in incident response activities as needed. Ensure cross-company processes around threat & vulnerability management are adhered to. This includes tracking SLAs, discovery, and handling of any finding. Maintain situational awareness, identification, tracking, and ensuring action on industry news related to software vulnerabilities, including zero-day vulnerabilities and emergency patching. * Implement and operationalize advanced Vulnerability Management reporting tools. Design, develop and operationalize Vulnerability Management metrics. Design and Implement advanced Vulnerability dashboards. Evaluate performance, perform career development, coaching and counseling and manage compensation for Cyber assessment staff. * Responsible for conducting security assessments & penetration tests. Review Cyber threat intelligence and ensures and provide relevant data to parties within the Cyber Assessment & Vulnerability management teams to action upon. Oversee regular red team exercises to proactively emulate attackers TTP and report back findings so security engineering and operations can improve their defenses. * Create, perform tabletop exercises exercising mimicking adversary practices testing PSEG LI's ability to respond to cyber incidents. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)