Vulnerability Management Team Lead

SailPoint Technologies, Inc.

United States

On-site

USD 150,000 - 210,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health and wellness coverage

Job summary

SailPoint is seeking a Vulnerability Management (VM) Team Lead to oversee our VM program from a fully remote position anywhere in the United States. You will manage a growing VM team, drive risk-based prioritization, and partner with Attack Surface Management and VM Architect teams to reduce threat exposure across cloud and on-prem environments.

In this hands-on leadership role, you will establish SLAs, mentor analysts, and guide remediation with IT, DevOps, and Engineering.

Qualifications

  • 5-7+ years in Cybersecurity with 2-3+ years in a leadership or senior operational role focused on Vulnerability Management.
  • Expert-level experience with enterprise vulnerability assessment tools and platforms (Qualys, CrowdStrike, Wiz, Orca).
  • Deep understanding of CVSS, CVE, EPSS, risk vs. severity, and patching for Windows, Mac, Linux, and containers.
  • Strong familiarity with securing modern cloud environments (AWS, Azure, GCP) and corporate infrastructure.
  • Proficiency in scripting for API integration, data analysis, and automation (Python or PowerShell).
  • Experience with regulatory frameworks (NIST, ISO 27001, SOC2, FedRAMP) and vulnerability program maturation.

Responsibilities

  • Lead daily VM operations and mentor a team of Vulnerability Management Analysts, overseeing the end-to-end vulnerability lifecycle.
  • Develop and enforce risk-based prioritization using asset criticality, threat intel, and exploitation trends.
  • Serve as escalation point to drive remediation with IT, DevOps, and engineering teams within SLAs.
  • Identify automation opportunities across data ingestion, ticketing (Jira), and SIEM/SOAR integration to improve efficiency.
  • Produce KPIs and KRIs, dashboards, and executive-facing reports translating technical data for stakeholders.

Skills

Leadership
Vulnerability Management
Team Mentorship
Cloud Security
Risk-based Prioritization
Scripting (Python/PowerShell)

Tools

Qualys
CrowdStrike
Wiz
Orca
Jira
SIEM/SOAR

Job description

SailPoint is seeking a Vulnerability Management (VM) Team Lead to oversee the daily operations of our VM program. As a critical member of our Cybersecurity organization, you will play a crucial role in protecting our systems and data by leading a team dedicated to the continuous discovery, accurate assessment, risk-based prioritization, and successful remediation of vulnerabilities across all company assets. This is a hands‑on leadership role for someone who wants to help drive the cultural and technical shift from reactive vulnerability patching to proactive, threat‑informed risk reduction. You will lead a growing threat and vulnerability management team of both emerging and established talent and partner closely with our Attack Surface Management team lead as well as VM Architect. At SailPoint, we value our "4 I's" (Integrity, Individuals, Impact, and Innovation), and we're looking for someone who embodies these principles. By being your authentic self, you will be a positive and influential contributor to our already fantastic work culture. This is a challenging and high‑impact role where you will build strong partnerships with colleagues across IT, DevOps, Security Engineering, and business units. This role is fully remote and can be based anywhere in the United States.

What You'll Do (Core Responsibilities)

Lead Daily VM Operations: Oversee the day-to-day operational activities of a team of Vulnerability Management Analysts. Provide technical guidance, mentorship, and support to elevate the overall skill set of the group. Manage the end-to-end vulnerability lifecycle, ensuring continuous discovery, triage, and assignment of vulnerabilities across cloud and corporate infrastructure.

Drive Risk-Based Prioritization: Develop and enforce a prioritization framework that utilizes risk context beyond standard CVSS scores, factoring in asset criticality, internal threat intelligence, and active exploitation in the wild. Collaborate with the risk team and business leaders to establish risk acceptance criteria and service level objectives (SLOs), ensuring remediation efforts align with the organizational risk appetite.

Lead the Remediation Lifecycle: Serve as an escalation point and subject matter expert to help VM analysts and asset owners (IT, DevOps, Engineering) understand risks, identify dependencies, and facilitate the remediation process. Track remediation progress across business units and ensure compliance with defined SLAs.

Automate and Improve Processes: Drive continuous improvement in the efficiency of vulnerability operations by identifying opportunities for automation across the tech stack (e.g., automating data ingestion, ticketing system integration via Jira, and integrating VM data into SIEM/SOAR).

Reporting & Metrics: Generate operational Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs), such as Mean Time to Remediate (MTTR), Remediation Compliance Rate, and overall vulnerability density. Provide program performance reporting, scorecards, and dashboards for different business units, translating technical data for non-technical stakeholders and executive leadership.

What You'll Need (Must-Have Experience & Skills)

5-7+ years in Cybersecurity, with 2-3+ years in a leadership, team lead, or senior operational role focused specifically on Vulnerability Management.

Expert-level, hands‑on experience with enterprise vulnerability assessment tools and platforms (e.g., Qualys, CrowdStrike, Wiz, Orca, etc.).

Deep technical understanding of vulnerability classification (CVSS, CVE, EPSS), risk vs. severity, and modern patching processes for Windows, Mac, Linux, and containerized environments.

Strong familiarity with securing modern complex cloud environments (AWS, Azure, GCP) and corporate infrastructure.

What Will Set You Apart (Bonus Points)

Demonstrable proficiency in a scripting language (Python or PowerShell strongly preferred) used for API integration, data analysis, and automation.

Experience with regulatory frameworks and compliance requirements (e.g., NIST, ISO 27001, SOC2, FedRAMP).

Background in penetration testing, threat intelligence, or attack surface management.

Experience establishing or maturing a vulnerability management program from the ground up.

Professional certifications such as CISSP, CISM, AWS Leadership Qualities for This Role: Pragmatic & Results‑Oriented: Influence & Collaboration: An Analytical & Investigative Mindset: Clear Communicator: You make informed, risk‑based decisions that balance business priorities with security needs to achieve measurable outcomes. You have a proven ability to build strong, collaborative relationships across diverse technical teams and drive change without direct authority. You possess an innate curiosity and a structured approach to problem‑solving, with a talent for turning ambiguous data into a clear action plan. You can distill complex technical concepts into clear, concise language for a variety of audiences, from junior analysts to senior executives.

The Path to Success (Milestones)

60‑Day Milestones (The "Connecting" Phase): Become fully comfortable with core processes and tools, including reporting, ticketing, and internal workflows. Solidify relationships with key members of the vulnerability management team and begin engaging with stakeholders in Engineering, IT, and Compliance. Begin performing routine vulnerability management tasks, such as validating scans and initiating remediation ticketing, with increasing independence with a keen eye for areas of improvement.

90‑Day Milestones (The "Performance" Phase): Begin overseeing day‑to‑day routine vulnerability management tasks accomplished by your team of analysts with minimal oversight. This includes running team stand‑ups. Act as the initial escalation point for vulnerability analysts, providing mentorship and helping to resolve challenges with remediation teams. Confidently engage with engineering and IT teams to work through remediation problems and ensure operational flow. Demonstrate a deep understanding of our risk‑based approach by prioritizing vulnerabilities.

6‑Month Milestones (The "Leading" Phase): Become a strong, effective team leader who actively identifies and suggests areas for process and documentation improvement. Take the lead on an internal team project, such as revamping vulnerability metrics or automating a reporting process. Identify training gaps for your team members and work with leadership to develop training plans to address those gaps.

12‑Month Milestones (The "Ownership" Phase): Solidly own all day‑to‑day operational tasks and responsibilities for the Vulnerability Management team, running with them from start to finish with minimal supervision. Actively contribute to maturing the team by bringing in new ideas, finding process efficiencies, and mentoring analysts on technical and communication skills. Establish and maintain strong, trusted relationships with cross‑functional partners in Engineering, Compliance, and other departments, effectively working through complex problems together.

Benefits Overview
  • 1. Health and wellness coverage: Medical, dental, and vision insurance
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability Management Team Lead
Vulnerability Management Team Lead

SailPoint Technologies Holdings, Inc. • Northern (KY)

Hybrid
USD 110,000 - 185,000
Health, dental, vision insurance
401(k) with company match
Paid time off
Remote Vulnerability Management Lead - Risk Reduction
Remote Vulnerability Management Lead - Risk Reduction

SailPoint • United States

On-site
USD 110,000 - 185,000
Health insurance
401(k) with company match
Paid time off
+1
Vulnerability Management Lead — Proactive Security
Vulnerability Management Lead — Proactive Security

SailPoint Technologies Holdings, Inc. • Northern (KY)

Hybrid
USD 110,000 - 185,000
Health, dental, vision insurance
401(k) with company match
Paid time off
Remote Vulnerability Management Team Lead
Remote Vulnerability Management Team Lead

SailPoint Technologies, Inc. • United States

On-site
USD 150,000 - 210,000
Health and wellness coverage
Vulnerability Manager
Vulnerability Manager

Search Services • Houston (TX)

Hybrid
USD 110,000 - 170,000
Senior Security Manager - Vulnerability Management
Senior Security Manager - Vulnerability Management

Alter Domus • Chicago (IL)

On-site
USD 140,000 - 190,000
Vulnerability Management Engineer
Vulnerability Management Engineer

WideNet Consulting Group • Seattle (WA)

Hybrid
USD 103,000 - 117,000
Corporate Vice President - Manager of Enterprise Vulnerability & Remediation
Corporate Vice President - Manager of Enterprise Vulnerability & Remediation

New York Life • New York (NY)

On-site
USD 147,500 - 211,000
Vulnerability Management Team Lead
Vulnerability Management Team Lead

GovCIO • Bethesda (MD)

Hybrid
USD 150,000 - 180,000
Senior Security Manager - Vulnerability Management
Senior Security Manager - Vulnerability Management

Alter Domus • Salt Lake City (UT)

On-site
USD 150,000 - 210,000
Professional accreditations
Flexible work arrangements
Generous holidays
+2