Manager Vulnerability Management

JetBlue

Orlando (FL)

Hybrid

USD 150,000 - 210,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

JetBlue is seeking a Cyber Security Manager to lead vulnerability management across hybrid environments, coordinating with architecture, development, and security teams. You will oversee scanning, risk prioritization and remediation efforts, and guide a team of analysts and partners in reducing exposure across platforms.

The role emphasizes risk-driven decision making, collaboration across IT and security disciplines, and driving improvements in processes and metrics.

Qualifications

  • Bachelor's Degree in Computer Science, Cyber Security, Data Analysis, or other relevant discipline, or 4 years of related work experience.
  • 5 years of relevant work experience in Vulnerability Management, Patch Management, IT Platform Engineering or related fields.
  • Knowledge of PCI, ISO 27001 and NIST CSF; cloud security concepts and application security scanning.
  • Experience with penetration testing methodologies and tools.
  • Understanding of container architecture and secure software development concepts.

Responsibilities

  • Continued development, evolution and maintenance of JetBlue’s Vulnerability Management Program, including cloud security tools and external attack surface posture.
  • Collaborate with cross-functional IT, networking and development teams to drive remediation of vulnerabilities and misconfigurations across a hybrid environment.
  • Partner with architecture, engineering and application development teams to maintain visibility into risks in a large-scale cloud environment.
  • Oversee analysts, partners and service providers to ensure regular vulnerability discovery and tracking with metrics and reporting.
  • Coordinate with Threat Intel and Pen Test teams to assess risk for active vulnerabilities and time-sensitive campaigns.
  • Develop the integration and automation strategy to optimize workflows between Vulnerability Management and asset/application teams.
  • Drive evolution of Risk Exception and Risk Acceptance processes related to Vulnerability response.
  • Take a significant role in developing direct reports and Crewmembers.

Skills

Leadership
Communication
Risk management

Education

Bachelor's degree in CS/Cybersecurity/Data Analysis or related
4+ years of related work experience (HS diploma + 4y)

Tools

Tenable
Rapid7
Wiz
Orca
Attack Surface Management
Penetration Testing Tools

Job description

Select how often (in days) to receive an alert:

Long Island City, NY, US, 11101 Washington, DC, US, 20005 Orlando, FL, US, 32827 Salt Lake City, UT, US, 84121

Category: Information Technology

Position Summary

At JetBlue, cyber security is driven by the concepts of Risk Management and Threat-Informed Defense, the study of current threats, actors and techniques to prioritize risks and adapt defenses, controls and resources to those constantly-changing dynamics. The Crewmember in this role is responsible for overseeing, directing and prioritizing activity across a range of risk-reduction efforts with regard to the identification, prioritization, and remediation of vulnerabilities. Beyond traditional infrastructure vulnerabilities, the Manager will be responsible for activities to detect and mitigate cloud and application layer vulnerabilities. This role reports to the Director – Cyber Security who is responsible for Threat Intel, Security Monitoring, Detection & Incident Response, and will work in close concert with those other teams.

  • Continued development, evolution and maintenance of JetBlue’s Vulnerability Management Program, including managing traditional scanning and cloud security tools and overseeing the scanning and discovery process, exposure management and external attack surface posture
  • Manage the team, policies and procedures to support successful compliance with Payment Card (PCI), Sarbanes-Oxley, TSA and other required oversight bodies/frameworks
  • Collaborate with cross-functional teams in IT, networking and other departments to drive remediation of identified vulnerabilities and misconfigurations across a hybrid environment, and to enumerate, monitor and manage exposure across our external attack surface
  • Partner with architecture, engineering and application development teams to establish and maintain comprehensive visibility into potential risks in a large-scale cloud environment
  • Oversee analysts, partners and service providers to ensure regular, rigorous and effective vulnerability discovery and tracking processes, including regular metrics and reporting
  • Clearly articulate and correctly prioritize risk for stakeholder and leadership teams
  • Coordination with our Penetration Testing program to reduce risk throughout JetBlue’s software development, deployment and testing lifecycle to minimize the introduction of vulnerabilities as the environment continues to evolve
  • Coordinate with the Threat Intel and Pen Test teams to ensure immediate assessment of risk for actively-exploited vulnerabilities and live or time-sensitive threat-actor campaigns and activity
  • Understand business requirements, network topology and other factors to make informed decisions around inherent and residual risk, prioritization and resource allocation
  • Develop the integration and automation strategy and manage analysts to optimize workflows between Vulnerability Management and the asset and application teams who address findings
  • Drive continuous evolution and improvement in processes, controls, and the Risk Exception and Risk Acceptance processes as they relate to Vulnerability response
  • Take a significant role in the development of direct reports and other Crewmembers to support their engagement, growth, and goal achievement
  • Other duties as assigned
Minimum Experience and Qualifications
  • Bachelor's Degree in Computer Science, Cyber Security, Data Analysis, or other relevant discipline; OR demonstrated capability to perform job responsibilities and a High School Diploma/GED and at least four (4) years of previous related work experience
  • Five (5) years of relevant work experience in Vulnerability Management, Patch Management, IT Platform Engineering or other related fields
  • Demonstrated knowledge of scanning tools such as Tenable or Rapid7, cloud security platforms such as Wiz or Orca and Attack Surface Management tools and concepts
  • Experience with penetration testing methodologies and tools
  • Familiarity with industry standards and frameworks, such as Payment Card Industry (PCI) Security Standards, ISO 27001 and/or National Institute of Standards and Technology (NIST) Cybersecurity Framework
  • Experience with application security concepts and scanning methodologies such as static code analysis and dynamic application security testing
  • Understanding of application container architecture
  • Leadership and management experience, including leading a team
  • Risk Management knowledge and experience
  • Excellent communication and presentation skills
  • Available for occasional overnight travel (10%)
  • Must pass a ten (10) year background check and pre-employment drug test
  • Legally eligible to work in the country in which the position is located
  • Authorization to work in the US is required. This position is not eligible for visa sponsorship
Preferred Experience and Qualifications
  • Six (6) years of relevant work experience
  • Experience with security testing, Attack Surface Management or red-teaming
  • Strong understanding of the differences in Vulnerability Management across Data Center, Cloud, Containers, Applications etc. is highly desirable
  • Creative problem solver and innovative thinker
  • Past work performing or overseeing additional adjacent disciplines such as Patch Management, Secure Software Development Life Cycle (SSDLC), Pen Testing or Red/Purple Teaming
  • Experience working with AWS, Azure and/or GCP
  • Experience building out Management Metrics and Key Performance Indicators (KPIs)
  • Regular attendance and on time punctuality
  • Potential need to work flexible hours and be available to respond on short-notice
  • Able to maintain a professional appearance
  • When working or traveling on JetBlue flights, and if time permits, all capable crewmembers are asked to assist with light cleaning of aircraft
  • Organizational fit for the JetBlue culture, that is, exhibit the JetBlue values of Safety, Caring, Integrity, Fun and Passion
  • Promote JetBlue’s #1 value of safety as a Safety Ambassador, supporting JetBlue’s Safety Management System (SMS) components, Safety Policy and behavioral standards
  • Identify safety and/or security concerns, issues, incidents or hazards that should be reported and report them whenever possible and by any means necessary including JetBlue’s confidential reporting systems (Aviation Safety Action Program (ASAP) and Safety Action Report (SAR))
  • Responsible for adhering to all applicable laws, regulations (FAA, OSHA, DOT, etc.) and Company policies, procedures and risk controls
  • Uphold JetBlue’s safety performance metric goals and understand how they relate to their duties and responsibilities
  • The use of ChatGPT or any other automated tool during the interview process will disqualify a candidate from being considered for the position.
Equipment:
  • Computer and other office equipment
  • Traditional office environment
Physical Effort:
  • Generally not required, or up to 10 pounds occasionally, 0 pounds frequently. (Sedentary)

#LI-AC1

#LI-Hybrid

JetBlue Airways is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status, or any other legally protected basis.

Nearest Major Market:

Brooklyn

Nearest Secondary Market:

New York City

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Manager Vulnerability Management
Manager Vulnerability Management

JetBlue • New York (NY)

Hybrid
USD 180,000 - 230,000
Junior Analyst, Cloud Eng Compliance (Paisly)
Junior Analyst, Cloud Eng Compliance (Paisly)

JetBlue • Town of Florida (NY)

On-site
USD 52,000 - 78,000
Controller Maintenance
Controller Maintenance

JetBlue • New York (NY)

On-site
USD 106,000 - 130,000
Architect Product Security
Architect Product Security

JetBlue • New York (NY)

On-site
USD 106,000 - 150,000
Hybrid work option
Flight benefits
Healthcare benefits
Analyst System Ops Strategy & Analytics
Analyst System Ops Strategy & Analytics

JetBlue • New York (NY)

On-site
USD 61,000 - 101,000
Senior Analyst Infrastructure
Senior Analyst Infrastructure

JetBlue • New York (NY)

On-site
USD 88,000 - 132,000
Manager Corporate Audit SOX and Controls
Manager Corporate Audit SOX and Controls

JetBlue • New York (NY)

On-site
USD 114,000 - 170,000
Manager Fare Rules and Revenue Integrity
Manager Fare Rules and Revenue Integrity

JetBlue • New York (NY)

On-site
USD 114,000 - 170,000
Coordinator Crew Relations
Coordinator Crew Relations

JetBlue • Boston (MA), Northern (KY)

Hybrid
USD 58,000 - 86,000
Healthcare benefits
401(k) plan and company match
Crewmember stock purchase plan
+1
Senior Analyst Inflight Standards
Senior Analyst Inflight Standards

JetBlue • Orlando (FL)

On-site
USD 90,000 - 130,000