Director, Vulnerability Management

Mwiah

Northern (KY)

Hybrid

USD 180,000 - 250,000

Full time

9 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Competitive compensation
Comprehensive benefits package
Career development & mentorship

Job summary

Cencora is seeking a Director of Vulnerability Management to lead our enterprise vulnerability program. You will shape strategy, architecture, and an end-to-end operating model across cloud, on-prem, endpoints, applications, and containers.

This hands-on leader will drive remediation decisions, governance, and performance metrics with cross-functional teams and executives. Ideal candidates possess a Bachelor's degree in a cybersecurity-related field, 8+ years in cybersecurity with 5+ years in

Qualifications

  • Experience leading enterprise vulnerability or exposure management programs.
  • Hands-on expertise with enterprise vulnerability management tools such as Tenable, Qualys, Rapid7 or Wiz.
  • Fluency in vulnerability scoring and prioritization frameworks (CVSS, EPSS, KEV, SSVC).

Responsibilities

  • Own the end-to-end vulnerability management strategy, roadmap, and operating model.
  • Define risk-based remediation SLAs by asset criticality and exposure.
  • Lead cross-functional collaboration with security, IT, and engineering teams to reduce unscanned assets and aging exposures.
  • Drive MTTR improvements and track KPIs/ KRIs for executive reporting.
  • Lead response for zero-day and critical vulnerabilities with rapid assessments and containment guidance.

Skills

Vulnerability management
Leadership
Threat intelligence
CVSS/EPSS prioritization
Cloud security
SAST/DAST/SCA
Container security

Education

Bachelor’s degree in Cybersecurity/Computer Science/Information Systems
Master’s degree in related field (preferred)

Tools

Tenable
Tableau/Qualys/Rapid7/Wiz

Job description

## Director, Vulnerability ManagementPostuler: Carrollton, TX: Conshohocken, PA: Temps Plein: Publié aujourd'hui: Date de fin : 16 octobre 2026 (Il reste plus de 30 jours pour postuler): R2613748Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today!# **Job Details****JOB SUMMARY** The Director of Vulnerability Management is the technical leader and owner of Cencora's vulnerability management program. This role sets the strategy, architecture, and operating model for how the organization discovers, prioritizes, and drives remediation of vulnerabilities across cloud, on-premise, endpoint, application, container, and third-party hosted environments. This hands-on technical leadership position leads the design of vulnerability scanning, reviewing detection logic, managing scan data, and defending remediation decisions across engineering teams and executive stakeholders. **RESPONSIBILITIES:*** Own the strategy and continual development of the end-to-end vulnerability management program, including strategy, roadmap, operating model, policy, standards, and success metrics.* Define and maintain risk-based remediation SLAs by asset criticality, exposure, and severity.* Mature beyond reactive scanning towards continuous, risk-based exposure management, including attack surface management and validation of remediation effectiveness.* Establish governance forums to review exposure trends, aging findings, systemic root causes, and escalations.* Oversee comprehensive and accurate asset coverage by integrating scanning with CMDB, cloud inventories, and other asset discovery sources to reduce unscanned and unknown assets.* Lead refinement of prioritization models to combine CVSS scoring with threat intelligence and exploitability signals, asset criticality, and compensating controls.* Partner with penetration testing, red team, threat intelligence, and countermeasures teams to correlate findings and validate control effectiveness.* Drive measurable reduction in mean time to remediate and aging critical exposures, working with IT operations, infrastructure, application, and cloud engineering teams.* Lead technical response for zero-day and emerging critical vulnerabilities, including rapid impact assessments, containment guidance, and executive communication.* Identify and address systemic root causes such as patch tooling gaps, unsupported software, base image drift, and legacy platform debt.* Define and report KPIs and KRIs to executive leadership, translating technical exposure into business and financial risk.* Recruit, develop, mentor, and retain a team of vulnerability management analysts, building technical depth and clear career paths.* Set technical standards, review the team's work product, and cultivate a culture of data quality and continuous improvement. **EDUCATION & QUALIFICATIONS:*** Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or equivalent work experience* 8+ years of progressive experience in cybersecurity, with at least 5 years in vulnerability management, security engineering, offensive security, or infrastructure security.* Experience leading technical teams with demonstrated success building or substantially maturing a vulnerability or exposure management program at enterprise scale.* Hands-on expertise with enterprise vulnerability management tenable (Table, Qualys, Rapid7, Wiz, etc).* Strong working knowledge of operating system internals, networking, patch and configuration management, and enterprise identity across Windows, Linux, and MacOS.* Demonstrated Experience security public cloud environments and container technologies, including cloud-native vulnerability and posture management.* Fluency in vulnerability scoring and prioritization frameworks (CVSS , EPSS, CISA KEV, SSVC).* Experience with application and software supply chain security concepts, including SAST, DAST, SCA, and SBOM.* Familiarity with relevant security and risk frameworks (NIST CSF, ISO 27001, MITRE ATT&CK, etc).* Excellent written and verbal communication skills with proven ability to influence engineering teams without direct authority and to brief executive audiences credibly. **PREFERRED CERTIFICATIONS:*** GIAC GEVA - Enterprise Vulnerability Assessor* GIAC GPEN - Penetration Tester* CISSP - Certified Information Systems Security Professional* CISM - Certified Information Security ManagerBachelor's degree in cybersecurity, information technology, computer science, information systems, business administration, or a related field, or equivalent experience required.Master's degree in cybersecurity, information technology, computer science, information systems, business administration, or a related field, or equivalent experience preferred.10+ years of experience in cybersecurity, information security, security operations, IT risk, or a related field required.5+ years of experience in a managerial capacity required.Certification in cybersecurity, information security, or a related field required. Examples may include Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or equivalent role relevant certification required.Certified Cloud Security Professional (CCSP), Certified Ethical Hacker (CEH), or equivalent certification preferred.# ******What Cencora offers******We provide compensation, benefits, and resources that enable a highly inclusive culture and support our team members’ ability to live with purpose every day. In addition to traditional offerings like medical, dental, and vision care, we also provide a comprehensive suite of benefits that focus on the physical, emotional, financial, and social aspects of wellness. This encompasses support for working families, which may include backup dependent care, adoption assistance, infertility coverage, family building support, behavioral health solutions, paid parental leave, and paid caregiver leave. To encourage your personal growth, we also offer a variety of training programs, professional development resources, and opportunities to participate in mentorship programs, employee resource groups, volunteer activities, and much more. For details, visit https://www.virtualfairhub.com/cencoraTemps Plein
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Vulnerability Management
Director, Vulnerability Management

World Courier • Carrollton (TX), Northern (KY)

Hybrid
USD 180,000 - 260,000
Medical insurance
Dental insurance
Vision care
+1
Engineer III, Vulnerability Management
Engineer III, Vulnerability Management

Cencora • Philadelphia

On-site
USD 120,000 - 180,000
Engineer III, Vulnerability Management
Engineer III, Vulnerability Management

Micro Technologies • Philadelphia

On-site
USD 120,000 - 160,000
Senior Director of Cloud Security
Senior Director of Cloud Security

Cencora • Arizona

On-site
USD 142,000 - 283,000
Medical, dental, and vision care
Parental leave
Mentorship programs
+1
Engineer III, Vulnerability Management
Engineer III, Vulnerability Management

American Health Packaging • Philadelphia

Hybrid
USD 120,000 - 180,000
Senior Director of Cloud Security
Senior Director of Cloud Security

Cencora • Philadelphia

On-site
USD 170,000 - 283,000
Medical benefits
Training programs
Mentorship and career development
Senior Director of Cyber Defense Architecture & Engineering
Senior Director of Cyber Defense Architecture & Engineering

Cencora • Dallas (TX)

On-site
USD 142,000 - 283,000
Senior Director of Cyber Defense Architecture & Engineering
Senior Director of Cyber Defense Architecture & Engineering

Cencora • Arizona

On-site
USD 142,000 - 283,000
Senior Director of Cyber Defense Architecture & Engineering
Senior Director of Cyber Defense Architecture & Engineering

RXinsider LTD. • Town of Texas (WI)

On-site
USD 142,000 - 283,000
Senior Director of Cyber Defense Architecture & Engineering
Senior Director of Cyber Defense Architecture & Engineering

Cencora • Pennsylvania

On-site
USD 142,000 - 283,000