22 часа назад
Director, Enterprise Vulnerability & Exposure Management (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Director, Enterprise Vulnerability & Exposure Management (Cybersecurity): Operationalizing and driving a global CTEM program across Danaher's enterprise attack surface with an accent on risk-based prioritization, governance, validation, and executive reporting. Focus on designing exposure prioritization using asset criticality, exploitability, exposure paths, controls, and business impact, while mobilizing remediation across infrastructure, cloud, application, and third-party owners.
Location: On-site in Krakow, Poland
Company
is a global science and technology company operating across life sciences, diagnostics, and biotechnology through more than 15 businesses.
What you will do
- Operationalize and drive the global vulnerability and exposure management program across the enterprise attack surface.
- Architect the CTEM operating model covering scoping, discovery, prioritization, validation, and remediation mobilization.
- Design risk-based prioritization using asset criticality, exploitability, exposure paths, security controls, and business impact.
- Define integrations across vulnerability management, attack surface management, cloud posture, offensive testing, and remediation tools.
- Establish remediation SLAs, exception governance, service ownership, metrics, and executive reporting.
- Coordinate remediation owners across infrastructure, cloud, application, and third-party environments.
Requirements
- 14+ years of cybersecurity experience focused on vulnerability, exposure, or threat exposure management.
- Experience leading enterprise or global vulnerability or exposure management, CTEM strategy, governance, and remediation across multiple business units.
- Experience with enterprise platforms such as Tenable, Qualys, Rapid7, Wiz, or Defender.
- Experience applying threat intelligence and asset context to risk-based prioritization.
- Ability to work independently, mobilize remediation across multiple technical ownership groups, and report exposure risk to executive stakeholders.
Nice to have
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field.
- Experience integrating vulnerability management with attack surface management and cloud security posture management.
- CISSP, CISM, or CRISC certification.
Culture & Benefits
- Full-time corporate role hosted by the Cytiva operating company.
- Part of the Information Security organization.
- Reports to the Global Chief Information Security Officer.
- Culture focused on continuous improvement, belonging, and internal career development.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →