14 дней назад
Vulnerability Manager (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Vulnerability Manager (Cybersecurity) (FedRAMP 20x): Operating an end-to-end product vulnerability management program for regulated SaaS products with an accent on risk-based prioritization, remediation governance, and machine-readable compliance evidence. Focus on automating triage and reporting, integrating scanners and security tooling, tracking POA&M and SLA outcomes, and responding to actively exploited and zero-day vulnerabilities across the product portfolio.
Location: Fully remote; must be based in North America
Company
provides cybersecurity SaaS solutions focused on identity security, privileged access, and reducing the impact of attacks.
What you will do
- Design and operate the product vulnerability management process from intake and triage through remediation, exception handling, and closure verification.
- Own vulnerability management for FedRAMP 20x, including continuous monitoring, machine-readable evidence, Key Security Indicator reporting, and POA&M lifecycle management.
- Establish vulnerability management for new products and services, including scan coverage, onboarding, SLAs, and reporting.
- Assess and prioritize risk using exploitability, exposure, asset criticality, compensating controls, CVSS, KEV, and EPSS.
- Drive remediation with engineering teams, manage escalations and risk acceptances, and report program metrics to security and engineering leadership.
- Automate triage, deduplication, enrichment, summarization, evidence collection, integrations, and rapid response for actively exploited and zero-day vulnerabilities.
Requirements
- 5+ years of experience in vulnerability management, product security, or security operations, with direct process ownership.
- Experience designing and operating vulnerability management in regulated or audited environments.
- Working knowledge of FedRAMP, NIST SP 800-53, vulnerability scanning, flaw remediation, continuous monitoring, configuration management, and POA&M management.
- Hands-on experience with vulnerability and exposure management platforms, cloud security posture tooling, container scanning, and software composition analysis.
- Practical automation skills using Python or equivalent scripting, workflow and reporting tools, and AI assistants.
- Working knowledge of AWS, containers, Kubernetes, CI/CD, web applications, and APIs, with strong communication skills across engineering, executive, audit, and customer audiences.
Nice to have
- FedRAMP Moderate or High authorization, continuous monitoring, or FedRAMP 20x experience.
- Experience building metrics, reporting, or dashboards for executive and audit audiences.
- Experience with SaaS, identity security, or privileged access management products.
- Familiarity with agentic or AI-assisted security workflows.
- Cloud security, GIAC, CISSP, or equivalent certifications.
Culture & Benefits
- Flexible culture focused on trust, continual learning, inclusion, and professional growth.
- Remote work environment supporting collaboration across diverse backgrounds.
- Work on cybersecurity products protecting organizations and their customers from identity-related threats.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →