Назад
Company hidden
14 дней назад

Vulnerability Manager (Cybersecurity)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Vulnerability Manager (Cybersecurity) (FedRAMP 20x): Operating an end-to-end product vulnerability management program for regulated SaaS products with an accent on risk-based prioritization, remediation governance, and machine-readable compliance evidence. Focus on automating triage and reporting, integrating scanners and security tooling, tracking POA&M and SLA outcomes, and responding to actively exploited and zero-day vulnerabilities across the product portfolio.

Location: Fully remote; must be based in North America

Company

hirify.global provides cybersecurity SaaS solutions focused on identity security, privileged access, and reducing the impact of attacks.

What you will do

  • Design and operate the product vulnerability management process from intake and triage through remediation, exception handling, and closure verification.
  • Own vulnerability management for FedRAMP 20x, including continuous monitoring, machine-readable evidence, Key Security Indicator reporting, and POA&M lifecycle management.
  • Establish vulnerability management for new products and services, including scan coverage, onboarding, SLAs, and reporting.
  • Assess and prioritize risk using exploitability, exposure, asset criticality, compensating controls, CVSS, KEV, and EPSS.
  • Drive remediation with engineering teams, manage escalations and risk acceptances, and report program metrics to security and engineering leadership.
  • Automate triage, deduplication, enrichment, summarization, evidence collection, integrations, and rapid response for actively exploited and zero-day vulnerabilities.

Requirements

  • 5+ years of experience in vulnerability management, product security, or security operations, with direct process ownership.
  • Experience designing and operating vulnerability management in regulated or audited environments.
  • Working knowledge of FedRAMP, NIST SP 800-53, vulnerability scanning, flaw remediation, continuous monitoring, configuration management, and POA&M management.
  • Hands-on experience with vulnerability and exposure management platforms, cloud security posture tooling, container scanning, and software composition analysis.
  • Practical automation skills using Python or equivalent scripting, workflow and reporting tools, and AI assistants.
  • Working knowledge of AWS, containers, Kubernetes, CI/CD, web applications, and APIs, with strong communication skills across engineering, executive, audit, and customer audiences.

Nice to have

  • FedRAMP Moderate or High authorization, continuous monitoring, or FedRAMP 20x experience.
  • Experience building metrics, reporting, or dashboards for executive and audit audiences.
  • Experience with SaaS, identity security, or privileged access management products.
  • Familiarity with agentic or AI-assisted security workflows.
  • Cloud security, GIAC, CISSP, or equivalent certifications.

Culture & Benefits

  • Flexible culture focused on trust, continual learning, inclusion, and professional growth.
  • Remote work environment supporting collaboration across diverse backgrounds.
  • Work on cybersecurity products protecting organizations and their customers from identity-related threats.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →