Senior Security Manager - Vulnerability Management

Alter Domus

Chicago (IL)

On-site

USD 140,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Alter Domus is seeking a Senior Security Manager, Vulnerability Management to own and mature the enterprise VM program across on-premises, cloud, and hybrid environments. Reporting to the CISO, you will lead a small team, prioritize remediation, and drive risk reduction through governance and executive reporting.

You will collaborate with Infrastructure, Application, and DevOps to ensure timely remediation of high-risk findings, expand scanner coverage, and evolve AI-assisted capabilities to

Qualifications

  • Deep hands-on vulnerability and attack surface management expertise.
  • Experience representing risk to senior stakeholders and translating findings.
  • Proven ability to coach and develop a security team.
  • Familiarity with regulated financial services environments.

Responsibilities

  • Own and mature the end-to-end enterprise Vulnerability Management program across on-prem, cloud, and hybrid environments.
  • Build and lead a small team of VM analysts/engineers and manage delivery against KPIs.
  • Partner with Infrastructure, Application, and DevOps to remediate findings and manage risk acceptance.
  • Identify and reduce attack surface, including shadow IT and internet-facing exposures.

Skills

Leadership
Vulnerability Mgmt
Risk management
Stakeholder comms

Tools

VM Platform

Job description

About Us

As a world leading provider of integrated solutions for the alternative investment industry, Alter Domus (meaning “The Other House” in Latin) is proud to be home to 90% of the top 30 asset managers in the private markets, and more than 6,000 professionals across 24 jurisdictions.

About Us

As a world leading provider of integrated solutions for the alternative investment industry, Alter Domus (meaning “The Other House” in Latin) is proud to be home to 90% of the top 30 asset managers in the private markets, and more than 6,000 professionals across 24 jurisdictions.

With a deep understanding of what it takes to succeed in alternatives, we believe in being different in what we do, how we work, and most importantly in how we enable and develop our people. Invest yourself in the alternative, and join an organization where you progress on merit, where you can speak openly with whoever you are speaking to, and where you will be supported along whichever path you choose to take.

Find out more about life at Alter Domus at careers.alterdomus.com

We are seeking a Senior Security Manager, Vulnerability Management to own and mature Alter Domus’s enterprise vulnerability management program and drive continuous reduction of our attack surface. Reporting to the CISO, you will lead the strategy, tooling, and operating cadence for identifying, prioritizing, and remediating vulnerabilities across infrastructure, cloud, and business applications — while leading a small team and representing the program in governance, audit, and executive reporting forums.

Key Responsibilities
  • Own and continuously mature the end-to-end enterprise Vulnerability Management (VM) program — policy, scanning cadence, risk-based prioritization, and remediation SLAs — across on-premises, cloud, and hybrid environments.
  • Build, lead, and develop a small team of vulnerability management analysts/engineers, setting priorities and managing delivery against program KPIs.
  • Partner with Infrastructure, Application, and DevOps teams to drive timely remediation of critical and high-risk findings; manage formal risk-acceptance and exception processes for items that cannot be remediated on schedule.
  • Identify and reduce the organization’s attack surface, including unmanaged assets, shadow IT, and internet-facing exposures, in partnership with IT and Network teams.
Vulnerability Management Platform Deployment & Operations
  • Own the deployment, configuration, and ongoing administration of the enterprise vulnerability management (VM) scanning and detection–response platform across the enterprise estate.
  • Drive scanner/agent coverage expansion, asset discovery accuracy, and integration of the VM platform with ITSM/ticketing and CMDB tools.
  • Continuously tune scan policies, authentication, and reporting configurations to improve detection accuracy and reduce false positives.
  • Evaluate and recommend enhancements to the VM tooling stack as the threat landscape and business needs evolve.
AI-Augmented Vulnerability Management
  • Leverage AI/ML-driven risk scoring and predictive exploitability signals (beyond static CVSS) to sharpen remediation prioritization and focus analyst effort on the highest-impact exposures.
  • Evaluate and adopt AI-assisted capabilities within the VM platform — automated finding triage, deduplication, and correlation with threat intelligence — to increase remediation velocity and reduce manual analyst workload.
  • Extend vulnerability and attack surface management practices to AI/ML assets in use across the business — models, training data pipelines, and AI-enabled applications — identifying and remediating AI-specific exposures.
  • Partner with Security Governance on emerging AI risk frameworks (e.g., NIST AI RMF, OWASP Top 10 for LLM Applications) where they intersect with vulnerability and configuration management practices.
Governance, Metrics & Reporting
  • Design and maintain executive and operational reporting (KPIs/KRIs, remediation SLA performance, risk trends) for the CISO, technology leadership, and risk committees.
  • Own and keep current the vulnerability management policies, standards, and procedures in line with the evolving threat landscape and regulatory expectations.
  • Present program status, risk posture, and remediation progress at security governance forums and, as needed, executive-level updates.
Audit & Compliance
  • Serve as the primary control owner for vulnerability and configuration management controls during SOC 2 (Type I/II) and related audits (e.g., ISO 27001, client due-diligence reviews).
  • Manage evidence collection, auditor engagement, and remediation tracking for audit findings tied to vulnerability, patch, and configuration management.
  • Support broader information security governance activities, including risk assessments and control testing, as needed.
Preferred Experience & Qualifications

The ideal candidate will bring deep, hands‑on expertise in vulnerability and attack surface management, with demonstrated leadership in regulated financial services environments. Preferred experience includes:

Leadership & General
  • 10+ years of information security experience, including 5+ years leading or managing a vulnerability management or attack surface management function — ideally within financial services or another regulated industry.
  • Proven track record of representing risk and program status to senior stakeholders, translating technical findings into clear business narrative.
  • Proven people‑management experience, with a track record of building, coaching, and developing a small security team.
Technical Skills
  • Hands‑on experience deploying, administering, and optimizing an enterprise vulnerability management (VM) platform at scale.
  • Working knowledge of CIS Benchmarks, CVE/CVSS scoring, and secure configuration and hardening practices across Windows, Linux, cloud (AWS/Azure), and network infrastructure.
  • Experience leading or coordinating vulnerability assessments and penetration testing of business applications, and turning findings into actionable remediation plans.
  • Direct experience as a control owner supporting SOC 2 (Type I/II) or comparable compliance audits (e.g., ISO 27001, NIST CSF).
  • Strong written and verbal communication skills, with the ability to present risk and program metrics to both technical and executive/non‑technical audiences.
AI & Automation
  • Familiarity with AI/ML-driven vulnerability prioritization and risk‑scoring capabilities (e.g., predictive exploitability, threat‑intel correlation) available in modern VM platforms.
  • Familiarity with using or evaluating AI‑powered automation for vulnerability triage, deduplication, or remediation‑guidance generation.
  • Working knowledge of AI/LLM‑specific risk considerations (e.g., OWASP Top 10 for LLM Applications, model and data‑pipeline exposures) as they
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Manager - Vulnerability Management
Senior Security Manager - Vulnerability Management

Alter Domus • Salt Lake City (UT)

On-site
USD 150,000 - 210,000
Professional accreditations
Flexible work arrangements
Generous holidays
+2
Senior Security Manager - Vulnerability Management
Senior Security Manager - Vulnerability Management

Alter Domus • New York (NY)

On-site
USD 180,000 - 240,000
Professional accreditations support
Flexible work arrangements
Generous holidays
+3
Manager, Vulnerability Management
Manager, Vulnerability Management

Vanguard • Malvern

On-site
USD 170,000 - 230,000
Senior Vulnerability Analyst
Senior Vulnerability Analyst

PRI Global • O’Fallon (MO)

On-site
USD 110,000 - 160,000
Corporate Vice President - Head of Enterprise Vulnerability Management
Corporate Vice President - Head of Enterprise Vulnerability Management

New York Life • New York (NY)

On-site
USD 147,000 - 211,000
Senior Vulnerability Management Leader - AI-Driven Security
Senior Vulnerability Management Leader - AI-Driven Security

Alter Domus • Chicago (IL)

On-site
USD 140,000 - 190,000
Security Operations Vice President - Vulnerability Management
Security Operations Vice President - Vulnerability Management

JPMorgan Chase & Co. • Plano (TX)

On-site
USD 90,000 - 110,000
Vulnerability Management Leader, Senior Security
Vulnerability Management Leader, Senior Security

Alter Domus • New York (NY)

On-site
USD 180,000 - 240,000
Professional accreditations support
Flexible work arrangements
Generous holidays
+3
Manager, Vulnerability Management
Manager, Vulnerability Management

Vanguard • Charlotte (NC)

Hybrid
USD 140,000 - 180,000
Hybrid work model
Cybersecurity Engineer - Vulnerability Management
Cybersecurity Engineer - Vulnerability Management

Janestreet • New York (NY)

On-site
USD 100,000 - 130,000