VIPR & VMDR Expert

Armis

Germany (OH)

Hybrid

USD 150,000 - 210,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Armis seeks a seasoned VIPR/VMDR expert to architect vulnerability lifecycle management and exploit intelligence across customer environments. You will lead detection, prioritization, and remediation, coordinating ITSM processes and cross-functional teams.

You will integrate threat intel with asset context, tune security tools, and develop data-driven risk insights for executives, while delivering dashboards and training for customers and internal staff.

Qualifications

  • 6–10+ years in Vulnerability Management, Threat Intelligence, or Security Detection Engineering.
  • Deep expertise in CVSS, CWE/CVE, NVD, KEV, and exploit prediction (EPSS).
  • Hands-on experience with vulnerability and detection management platforms (Tenable, Qualys, Rapid7, Wiz, Prisma Cloud, ServiceNow VR, Centrix for VMDR).
  • Proven ability to develop automation scripts and data pipelines (Python, PowerShell, Bash, REST APIs, JSON).
  • Familiarity with RBVM and prioritization scoring models.
  • Strong understanding of cloud-native security, container scanning, and hybrid infrastructure (AWS, Azure, GCP).
  • Exceptional data storytelling skills and executive-facing communication.
  • Demonstrated ability to work independently and in teams.

Responsibilities

  • Own end-to-end vulnerability and detection lifecycle from discovery to remediation and reporting.
  • Lead VIPR/VMDR function, integrating threat intel, exploit data, and asset context for decisions.
  • Correlate internal telemetry with external feeds (NVD, KEV, EPSS, etc.) to assess exploitability.
  • Operate and tune VM and detection tools (Tenable, Qualys, Rapid7, Wiz, Prisma Cloud, ServiceNow VR) across environments.
  • Automate vulnerability scoring, detection correlation, and reporting pipelines (Python, PowerShell, REST).
  • Partner with Customer Success and Security teams to track remediation SLAs and MTTR improvements.
  • Build and publish risk dashboards and executive briefings using Splunk, Power BI, Elastic, or VIPR.
  • Develop Armis VPM by aligning exploit intelligence, CVSS/EPSS scores and business criticality.

Skills

Vulnerability Management
Threat Intelligence
Security Detection Engineering
CVSS/EPSS frameworks
Automation scripting
RBVM
Cloud-native security
Data storytelling
Executive communication

Education

Bachelor’s or Master’s degree in Information Security or Computer Science

Tools

Tenable
Qualys
Rapid7
Wiz
Prisma Cloud
ServiceNow VR
Centrix for VMDR

Job description

The VIPR & VMDR Expert serves as an architect,, strategic analyst and technical operator — combining vulnerability lifecycle management with exploit intelligence, detection automation, and cross-functional coordination (ITSM).

You’ll lead how Armis detects, prioritizes, and responds to vulnerabilities across customer environments, infrastructure, SaaS ecosystems, and the Armis platform — ensuring our customers stay ahead of emerging exploits, threats, and exposures.

Key Responsibilities
  • Own the end-to-end vulnerability and detection lifecycle — from discovery, triage, and prioritization through remediation and reporting.
  • Lead the Vulnerability Intelligence, Prioritization & Detection Response (VIPR/VMDR) function, integrating threat intel, exploit data, and asset context to drive data-backed decisions.
  • Correlate internal vulnerability telemetry with external feeds (NVD, CISA KEV, EPSS, Mandiant, Shodan, VulnDB, Centrix for Early Warning) to assess exploitability and exposure.
  • Operate and tune vulnerability and detection tools (e.g., Tenable, Qualys, Rapid7, Wiz, Prisma Cloud, ServiceNow VR) across hybrid customer environments.
  • Automate vulnerability scoring, detection correlation, and reporting pipelines using Python, PowerShell, REST APIs, or automation rules within AMS/VIPR.
  • Partner with Customer Success, Security Engineering, and Cloud Infrastructure teams to track remediation SLAs, exposure metrics, and MTTR improvements.
  • Build and publish risk dashboards, customer-facing reports, and executive briefings using Splunk, Power BI, Elastic, or AMS/VIPR.
  • Develop and maintain the Armis Vulnerability Prioritization Model (VPM) — aligning exploit intelligence, CVSS/EPSS scoring, Armis Proprietary Risk Scoring, and business criticality to guide customer risk posture.
  • Support penetration test remediation, red team findings, and customer security audits.
  • Author weekly vulnerability intelligence reports, zero-day summaries, and leadership briefings for APJ/APAC stakeholders.
  • Collaborate with Product Security and Threat Intelligence teams to integrate vulnerability and detection data into Armis platform insights.
  • Deliver training sessions and enablement workshops for customers, engineers, and analysts on vulnerability trends, tools, and operational best practices.
Qualifications
  • 6–10+ years of experience in Vulnerability Management, Threat Intelligence, or Security Detection Engineering.
  • Deep expertise in CVSS, CWE/CVE, NVD, KEV, and exploit prediction (EPSS) frameworks.
  • Hands-on experience with vulnerability and detection management platforms (Tenable, Qualys, Rapid7, Wiz, Prisma Cloud, ServiceNow VR, Centrix for VMDR).
  • Proven ability to develop automation scripts and data pipelines (Python, PowerShell, Bash, REST APIs, JSON).
  • Familiarity with risk-based vulnerability management (RBVM) and prioritization scoring models.
  • Strong understanding of cloud-native security, container scanning, and hybrid infrastructure (AWS, Azure, GCP).
  • Exceptional data storytelling skills — turning technical findings into actionable executive insights.
  • Demonstrated ability to work independently and as part of a team.
  • Exceptional communication skills across all levels of technical, middle management, and executive leadership personnel.
  • Bachelor’s or Master’s degree in Information Security, Computer Science, or related discipline.
  • Previous experience operating in a "Voice of the Customer" (VoC) technical role directly embedded with Product Engineering pods.
  • A track record of mentoring senior technical staff (TCMs, TAMs, or Solutions Engineers) and developing scalable knowledge-sharing frameworks.
Preferred Experience
  • Prior experience in enterprise SaaS, cybersecurity, or customer-facing technical programs.
  • Familiarity with Armis Centrix™ or similar asset intelligence and exposure management tools.
  • Certifications such as CISSP, GCCC, GCTI, CEH, or CySA+.
  • Experience supporting compliance frameworks (SOC 2, ISO 27001, FedRAMP) in enterprise environments.
  • Strong cross-cultural communication and collaboration skills across global and regional teams (APJ/APAC).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

VIPR & VMDR Expert
VIPR & VMDR Expert

Armis • Town of Poland (NY)

On-site
USD 140,000 - 200,000
VMDR Expert (Vulnerability Management, Detection & Response)
VMDR Expert (Vulnerability Management, Detection & Response)

Armis • Arlington (VA)

On-site
USD 110,000 - 140,000
Application Security & VIPR Expert
Application Security & VIPR Expert

Armis • Town of Poland (NY)

On-site
USD 140,000 - 170,000
Vulnerability & Detection Architect (VIPR/VMDR)
Vulnerability & Detection Architect (VIPR/VMDR)

Armis • Town of Poland (NY)

On-site
USD 140,000 - 200,000
Vulnerability Intelligence & VMDR Lead
Vulnerability Intelligence & VMDR Lead

Armis • Germany (OH)

Hybrid
USD 150,000 - 210,000
Security Operations Vice President - Vulnerability Management
Security Operations Vice President - Vulnerability Management

JPMorgan Chase & Co. • Plano (TX)

On-site
USD 90,000 - 110,000
Manager, Vulnerability Management
Manager, Vulnerability Management

Vanguard • Malvern

On-site
USD 170,000 - 230,000
Vulnerability Analyst — External Attack Surface & VDP
Vulnerability Analyst — External Attack Surface & VDP

Vanguard • Charlotte (NC)

On-site
USD 80,000 - 100,000
Vulnerability Management and Security Engineering
Vulnerability Management and Security Engineering

RennerBrown • New York (NY)

On-site
USD 140,000 - 190,000
Senior Security Manager - Vulnerability Management
Senior Security Manager - Vulnerability Management

Alter Domus • Chicago (IL)

On-site
USD 140,000 - 190,000