Vulnerability Manager

Jobtailor

Deutschland

Remote

EUR 90.000 - 140.000

Vollzeit

Vor 5 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Eine komplette Bewerbung in einer Minute — maßgeschneiderter Lebenslauf und Anschreiben, versandbereit.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

Jobtailor is seeking a senior vulnerability management professional to lead end-to-end processes for product security. You will own FedRAMP-related activities, drive remediation with engineering teams, and establish onboarding SLAs for new products while continuously monitoring risk, scans, and KPIs.

Ideal candidates bring automation skills, strong communication, and experience with cloud security, containers, and CI/CD.

Qualifikationen

  • Experience owning vulnerability management processes from intake to closure in a regulated or audited environment.
  • Familiarity with FedRAMP and NIST SP 800-53 controls and associated POA&M management.
  • Hands-on with vulnerability scanning, remediation tracking, and continuous monitoring.
  • Experience with cloud security, container tech (Kubernetes), CI/CD, APIs and web apps.
  • Automation skills including Python or equivalent scripting for triage, reporting and enrichment.

Aufgaben

  • Design and operate end-to-end vulnerability management processes including intake, triage, risk assessment, SLA tracking, and closure verification.
  • Own vulnerability management for FedRAMP with continuous monitoring, evidence collection, and POA&M lifecycle.
  • Establish vulnerability management for new products with onboarding SLAs and reporting.
  • Assess and rank vulnerability risk using exploitability, exposure, asset criticality, and controls.
  • Drive remediation with engineering teams, manage overdue critical/high findings, and document risk acceptances.

Kenntnisse

Clear Communication
Collaboration
Leadership
Problem Solving
Risk Assessment

Tools

Enterprise Vulnerability Management Platforms
Cloud Security Posture Tools
Container Scanning Tools
Software Composition Analysis Tools
Workflow Tooling

Jobbeschreibung

  • Design and operate the product vulnerability management process end to end, including intake, triage, risk assessment, assignment, SLA tracking, exception handling, and closure verification
  • Own vulnerability management for FedRAMP 20x, including continuous monitoring, machine-readable evidence, Key Security Indicator reporting, and POA&M lifecycle management
  • Establish vulnerability management for new products and services, including scan coverage, onboarding, SLAs, and reporting
  • Assess and rank vulnerability risk using exploitability, exposure, asset criticality, and compensating controls
  • Drive remediation with product engineering teams, escape overdue Critical and High findings, and record time-bound risk acceptances
  • Automate triage, deduplication, enrichment, summarization, reporting, workflow, and evidence collection using scripting, workflow tooling, and AI-assisted analysis
  • Define requirements for integrations involving scanners, ticketing, asset inventory, and dashboards; partner with Security Engineering through delivery and validate outcomes
  • Own program metrics including SLA attainment, mean time to remediate, vulnerability aging, backlog trend, scan and asset coverage, and exception volume
  • Report metrics to security and engineering leadership on a fixed cadence
  • Maintain current visibility into critical product exposure and open vulnerabilities
  • Lead rapid response for actively exploited and zero-day vulnerabilities, including exposure assessment, mitigation tracking, and stakeholder communication
Requirements
  • 5+ years in vulnerability management, product security, or security operations, with direct ownership of a vulnerability management process
  • Experience designing and operating vulnerability management processes in a regulated or audited environment and sustaining them through assessment cycles
  • Working knowledge of FedRAMP and NIST SP 800-53, including vulnerability scanning, flaw remediation, continuous monitoring, configuration management, and POA&M management
  • Hands-on experience with enterprise vulnerability and exposure management platforms, cloud security posture tooling, container scanning, and software composition analysis
  • Practical automation skills, including Python or equivalent scripting, workflow and reporting tooling, and AI assistants
  • Ability to write technical requirements and partner with security engineering through design, delivery, and acceptance
  • Understanding of CVSS, CISA Known Exploited Vulnerabilities (KEV), EPSS, and risk-based prioritization
  • Working knowledge of cloud services, AWS preferred, containers, Kubernetes, CI/CD, web applications, and APIs
  • Ability to drive remediation across engineering teams without direct authority
  • Clear written and verbal communication with engineers, executives, auditors, and customers
  • Must be North America based
Core Competencies

Demonstrates expertise in vulnerability management processes, including risk assessment, remediation, and automation. Proficient in leveraging cloud security tools and frameworks such as FedRAMP and NIST SP 800-53 to ensure compliance and effective vulnerability handling.

Highest-signal resume keywords
  • Vulnerability Management Process Ownership
  • FedRAMP Compliance
  • Python Scripting
  • Risk Assessment and Prioritization
  • Cloud Security Posture Management
Hard Skills
  • Vulnerability Management
  • Risk Assessment
  • Automation
  • Scripting
  • Vulnerability Scanning
  • Configuration Management
  • Continuous Monitoring
  • Flaw Remediation
  • Technical Requirements Writing
  • Cloud Security
Soft Skills
  • Clear Communication
  • Collaboration
  • Stakeholder Engagement
  • Problem Solving
  • Leadership
Industry Keywords
  • FedRAMP
  • NIST SP 800-53
  • CVSS
  • CISA Known Exploited Vulnerabilities
  • EPSS
  • CI/CD
  • Kubernetes
  • APIs
  • Web Applications
  • Asset Inventory
Tools & Technologies
  • Enterprise Vulnerability Management Platforms
  • Cloud Security Posture Tools
  • Container Scanning Tools
  • Software Composition Analysis Tools
  • Workflow Tooling
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Security Engineer – Vulnerability Management
Security Engineer – Vulnerability Management

Jobtailor • Deutschland

Remote
EUR 70.000 - 110.000
Mid-Level Cybersecurity Analyst
Mid-Level Cybersecurity Analyst

Jobtailor • Deutschland

Remote
EUR 70.000 - 100.000
Director, Enterprise Vulnerability & Exposure Management
Director, Enterprise Vulnerability & Exposure Management

Jobtailor • Deutschland

Remote
EUR 140.000 - 210.000
Lead Security Engineer
Lead Security Engineer

Jobtailor • Deutschland

Remote
EUR 90.000 - 130.000
Vulnerability Management / Incident Response Specialist
Vulnerability Management / Incident Response Specialist

Hhw Group • Deutschland

Vor Ort
EUR 70.000 - 90.000
Senior Information Security Specialist
Senior Information Security Specialist

Jobtailor • Deutschland

Remote
EUR 70.000 - 110.000
Product Security Engineer
Product Security Engineer

Jobtailor • Deutschland

Remote
EUR 90.000 - 130.000
Vulnerability Operations Center Lead
Vulnerability Operations Center Lead

Nebius B.V. • Deutschland

Remote
EUR 90.000 - 120.000
DevSecOps Engineer
DevSecOps Engineer

Jobtailor • Deutschland

Vor Ort
EUR 90.000 - 140.000
IT Security Analyst – Level 1
IT Security Analyst – Level 1

Jobtailor • Deutschland

Vor Ort
EUR 45.000 - 65.000