> Markdown version of [/jobs/ext/2283899-vulnerability-management-leader](https://www.wearedevelopers.com/jobs/ext/2283899-vulnerability-management-leader). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Vulnerability Management Leader - **Company:** QNity, Inc. - **Location:** Wilmington, DE, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cloud Computing, Cloud Computing Security, Configuration Management Databases, CompTIA Security+, Cyber Security, Power BI, Software Vulnerability Management, Cyber Threat Analysis, Information Technology, CIS Benchmarks, Servicenow, Vulnerability Analysis - **Published:** August 28, 2026 - **Apply:** https://www.financialjobbank.com/job.asp?id=3367761024&tx=HT8074THV&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field, required. * 8+ years of cybersecurity experience with at least 5 years in Vulnerability Management, Security Operations, Exposure Management, or related disciplines required. * Experience leading enterprise vulnerability management programs. * Strong knowledge of vulnerability prioritization methodologies, threat intelligence, remediation governance, and executive reporting. * Hands-on experience with: * Tenable * Wiz * ServiceNow * Recorded Future * Asset inventory / CMDB / IPAM platforms * Strong communication, stakeholder management, and program leadership skills. * Ability to influence and drive outcomes across multiple teams without direct authority. Other Preferred Qualifications * Experience in cloud security, exposure management, or attack surface management. * Familiarity with NIST CSF, CIS Controls, PCI, ISO 27001, or similar frameworks. * Experience integrating vulnerability management platforms with ITSM and reporting solutions. * Relevant certifications such as CISSP, CISM, CRISC, Security+, or vendor certifications. ## Description The Vulnerability Management Lead is responsible for the strategy, governance, and operation of Qnity's Threat and Vulnerability Management (TVM) program. This role drives the identification, prioritization, remediation, and reporting of vulnerabilities across enterprise environments while leveraging threat intelligence and business context to focus efforts on the risks that matter most. The role partners closely with Cyber Threat Intelligence, Infrastructure, Cloud, Application Support, Compliance, and Service Delivery teams to reduce cyber risk and improve overall security posture. Key Responsibilities Program Leadership * Lead and mature Qnity's Threat and Vulnerability Management program. * Define governance, processes, remediation workflows, metrics, and reporting. * Drive cross-functional accountability for vulnerability remediation. Vulnerability & Exposure Management * Oversee enterprise vulnerability discovery across infrastructure, cloud, applications, and operational technology environments. * Manage vulnerability assessment capabilities utilizing Tenable , Wiz , and related technologies. * Improve asset visibility through CMDB, IPAM, and inventory integrations. Risk-Based Prioritization * Prioritize vulnerabilities using threat intelligence, exploitability, asset criticality, business impact, and exposure context. * Partner with Cyber Threat Intelligence to identify emerging threats, known exploited vulnerabilities, and zero-day risks. * Focus remediation efforts on internet-facing systems, critical assets, and high-risk exposures. Remediation Governance * Drive vulnerability remediation through ServiceNow workflows and escalation processes. * Establish and monitor remediation SLAs, exception management, and risk acceptance processes. * Coordinate emergency response activities for critical and actively exploited vulnerabilities. Metrics & Executive Reporting * Develop dashboards and reporting in Tenable, Wiz, and Power BI. * Track vulnerability aging, remediation performance, SLA compliance, risk exposure, and program maturity. * Provide executive-level reporting and recommendations to leadership. Continuous Improvement * Improve scan coverage, asset ownership, remediation workflows, and program effectiveness. * Identify opportunities for automation, integration, and process optimization. * Maintain alignment with security frameworks, compliance requirements, and industry best practices., * Improved vulnerability visibility and asset coverage. * Reduction in critical and high-risk vulnerabilities. * Achievement of remediation SLA targets. * Effective threat-informed prioritization and response. * Increased remediation accountability across the organization. * Executive visibility into cyber risk and vulnerability trends. * Continuous improvement of the TVM program and supporting technologies. Living the Qnity Values At Qnity, success is measured not only by what we achieve, but how we achieve it. * Customer: Partner with stakeholders to solve business challenges and deliver secure outcomes. * Innovation: Continuously improve processes, technologies, and ways of working. * Speed: Act with urgency and precision to reduce risk and address emerging threats. * People: Build trusted relationships, collaborate across teams, and inspire positive change. Join Qnity and help power the next leap in electronics by building a world-class Threat and Vulnerability Management program that protects the technologies shaping tomorrow. Join our Talent Community (https://careers.qnityelectronics.com/us/en/jointalentcommunity) to stay connected with us! ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Beyond Dashboards: Fixing Text-to-SQL with Semantic RAG](https://www.wearedevelopers.com/videos/2036-beyond-dashboards-fixing-text-to-sql-with-semantic-rag) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)