Назад
Company hidden
6 дней назад

TVM Program Lead (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
TVM Program Lead (Cybersecurity): Leading and maturing the organization’s threat and vulnerability management program with an accent on vulnerability assessment, risk prioritization, application security, and governance. Focus on integrating SAST/DAST and security controls into the SDLC, guiding remediation, developing risk metrics, and coordinating incident response and threat hunting.

Location: OK, United States (Hybrid)

Company

hirify.global is a large not-for-profit healthcare system focused on improving patient health and supporting its caregivers.

What you will do

  • Lead and mature the organization’s threat and vulnerability management program, including vulnerability assessments, scanning, governance, risk registers, and remediation tracking.
  • Analyze vulnerability data, prioritize risks by impact and exploitability, and provide remediation guidance to technology teams.
  • Develop cybersecurity strategies, policies, procedures, roadmaps, metrics, and executive-level risk reports.
  • Drive application security across the SDLC through secure coding practices, CI/CD security automation, SAST/DAST assessments, threat modeling, code reviews, and penetration testing.
  • Lead teams conducting threat hunting, incident response, risk mitigation, and continuous security improvement.
  • Collaborate with IT, software development, DevOps, vendors, and senior stakeholders on security initiatives, compliance, awareness training, and emergency response.

Requirements

  • Bachelor’s degree in Computer Science, Information Technology, or a related field with 5 years of relevant experience; equivalent experience may be accepted.
  • At least 5 years of vulnerability management experience and 5 years in a security-related role.
  • Strong knowledge of vulnerability management, risk assessment, cybersecurity frameworks, standards, regulatory requirements, and common exploitation techniques.
  • Experience with incident response, stakeholder management, security infrastructure, documentation, metrics, and tool roadmaps.
  • Proven leadership, facilitation, communication, analytical, decision-making, and team mentoring skills.
  • Ability to work in a hybrid role based in OK, United States.

Nice to have

  • Healthcare industry experience, threat hunting, threat modeling, and application security experience.
  • Knowledge of SAST, DAST, RASP, WAF, OWASP Top Ten, and secure coding practices.
  • Programming or scripting experience with Java, C#, Python, or JavaScript.
  • Experience with Microsoft Power BI, data visualization tools, or relevant certifications such as CISSP or CISM.

Culture & Benefits

  • Front-loaded paid time off.
  • Medical benefits through the hirify.global network.
  • Financial assistance for continued education.
  • 24/7 health support.
  • Equal opportunity and affirmative action employment practices.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →