6 дней назад
TVM Program Lead (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
TVM Program Lead (Cybersecurity): Leading and maturing the organization’s threat and vulnerability management program with an accent on vulnerability assessment, risk prioritization, application security, and governance. Focus on integrating SAST/DAST and security controls into the SDLC, guiding remediation, developing risk metrics, and coordinating incident response and threat hunting.
Location: OK, United States (Hybrid)
Company
is a large not-for-profit healthcare system focused on improving patient health and supporting its caregivers.
What you will do
- Lead and mature the organization’s threat and vulnerability management program, including vulnerability assessments, scanning, governance, risk registers, and remediation tracking.
- Analyze vulnerability data, prioritize risks by impact and exploitability, and provide remediation guidance to technology teams.
- Develop cybersecurity strategies, policies, procedures, roadmaps, metrics, and executive-level risk reports.
- Drive application security across the SDLC through secure coding practices, CI/CD security automation, SAST/DAST assessments, threat modeling, code reviews, and penetration testing.
- Lead teams conducting threat hunting, incident response, risk mitigation, and continuous security improvement.
- Collaborate with IT, software development, DevOps, vendors, and senior stakeholders on security initiatives, compliance, awareness training, and emergency response.
Requirements
- Bachelor’s degree in Computer Science, Information Technology, or a related field with 5 years of relevant experience; equivalent experience may be accepted.
- At least 5 years of vulnerability management experience and 5 years in a security-related role.
- Strong knowledge of vulnerability management, risk assessment, cybersecurity frameworks, standards, regulatory requirements, and common exploitation techniques.
- Experience with incident response, stakeholder management, security infrastructure, documentation, metrics, and tool roadmaps.
- Proven leadership, facilitation, communication, analytical, decision-making, and team mentoring skills.
- Ability to work in a hybrid role based in OK, United States.
Nice to have
- Healthcare industry experience, threat hunting, threat modeling, and application security experience.
- Knowledge of SAST, DAST, RASP, WAF, OWASP Top Ten, and secure coding practices.
- Programming or scripting experience with Java, C#, Python, or JavaScript.
- Experience with Microsoft Power BI, data visualization tools, or relevant certifications such as CISSP or CISM.
Culture & Benefits
- Front-loaded paid time off.
- Medical benefits through the network.
- Financial assistance for continued education.
- 24/7 health support.
- Equal opportunity and affirmative action employment practices.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
10 дней назад
Security Engineer (Cybersecurity)
98 614 - 167 644$
6 дней назад
Senior Lead, Security Engineering and Operations (Cybersecurity)
114 500 - 194 700$
13 дней назад
Director, Cybersecurity – Engineering, Operations and Incident Response
159 665 - 239 497$
7 часов назад
Lead Security Architect (Cybersecurity)
142 300 - 195 700$
10 дней назад
Manager, Vulnerability Operations (Cybersecurity)
124 000 - 155 000$
12 дней назад
Principal, Technology and Cyber Risk Management
108 965 - 185 155$