Vulnerability Program Manager

Jobgether

United States

On-site

USD 75,000 - 100,000

Full time

7 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Full-time exempt
Travel opportunities
Growth opportunities
Flexible hours

Job summary

Jobgether is seeking a Vulnerability Program Manager based in the United States. This role owns end-to-end vulnerability management and patching across a diverse client portfolio, establishing standardized processes, reporting, and accountability across environments and delivery teams.

You will combine hands-on cybersecurity operations with program leadership, coordinating remediation with technical teams and client stakeholders to reduce risk and meet compliance expectations.

Qualifications

  • Demonstrated experience managing vulnerability management and patching programs across multiple clients or environments.
  • Hands-on experience with vulnerability management and patching platforms such as InsightVM, ConnectSecu re, NinjaOne, Datto RMM, or equivalent technologies.
  • Working knowledge of PSA and workflow platforms, including ticket configuration and reporting.

Responsibilities

  • Own the end-to-end vulnerability management and patching program for multiple clients.
  • Define standardized service processes including scan frequency, patch cadence, and remediation targets.
  • Coordinate remediation across internal teams and client stakeholders, considering maintenance windows and constraints.
  • Manage exclusions, suppressions, and risk acceptances with proper documentation.
  • Act as escalation point for urgent vulnerability responses, including zero-day threats.

Skills

Vulnerability management
Program leadership
Client engagement
Communication
Cross-team coordination

Education

Security+ certification
GIAC
CISSP

Tools

InsightVM
ConnectSecu re
NinjaOne
Datto RMM
HaloPSA

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Vulnerability Program Manager based in the United States.

This role owns the end-to-end delivery of vulnerability management and patching across a diverse client portfolio.

You will establish consistent standards, processes, reporting, and accountability across multiple environments and delivery teams.

The position combines hands-on cybersecurity operations with program leadership, client engagement, and continuous improvement.

You will work directly with vulnerability management and patching tools while coordinating remediation across technical teams and client stakeholders.

Your work will help organizations reduce cyber risk, meet compliance expectations, and maintain stronger security postures.

The environment is collaborative and fast-paced, requiring strong influence and communication across teams that may not report directly to you.

This is an opportunity to build and mature a scalable security service while making a measurable impact on client outcomes.

Accountabilities
  • Own the end-to-end vulnerability management and patching program, including asset discovery, scanning, risk-based prioritization, remediation tracking, verification, exception management, and reporting.
  • Define and document standardized service processes, including scan frequency, patching cadence, severity-based remediation targets, risk acceptance procedures, and emergency response criteria.
  • Establish clear roles and responsibilities across vulnerability analysts, security engineering, service desk teams, and client stakeholders.
  • Design ticket types, templates, workflows, and reporting processes in PSA tooling to ensure vulnerability and patching activities are consistently documented.
  • Run recurring vulnerability management reviews for assigned clients, maintain prioritized remediation backlogs, and proactively **escalate** stalled or aging findings.
  • Coordinate remediation across internal delivery teams and client personnel, taking change windows, maintenance periods, and operational constraints into account.
  • Manage exclusions, suppressions, and risk acceptances with appropriate documentation, ownership, rationale, and review dates.
  • Act as the escalation point for urgent vulnerability response, including zero-day vulnerabilities and actively exploited threats requiring out-of-cycle remediation.
  • Own client-facing vulnerability reporting, including recurring review materials, aging and trend analysis, and executive-level summaries.
  • Present risk, remediation progress, and program status to technical and non-technical client stakeholders while clearly communicating responsibilities, dependencies, and required actions.
  • Support audits and compliance requirements involving frameworks such as CMMC, PCI DSS, SOC 2, HIPAA, and NCUA examinations.
  • Partner with client success and account teams during onboarding, escalations, renewals, and other client engagements.
  • Maintain the operational health of vulnerability management tooling, including scanner coverage, credentialed scanning, agent deployment, and asset inventory accuracy.
  • Collaborate with security engineering to integrate scanning, ticketing, and patching platforms and reduce manual reporting effort.
  • Identify data-quality issues such as stale assets, duplicate records, and unmanaged endpoints that can affect vulnerability reporting.
  • Define and track metrics including remediation SLA attainment, vulnerability aging, patch compliance, scan coverage, and recurring findings.
  • Use program data to identify systemic issues and drive improvements to processes, tooling, automation, and service delivery.
  • Train and mentor vulnerability analysts and other delivery personnel on standardized processes and contribute to the development of vulnerability management service offerings.
Requirements
  • Demonstrated experience managing vulnerability management and patching programs across multiple clients or environments, preferably within an MSP or MSSP.
  • Hands-on experience with vulnerability management and patching platforms such as InsightVM, ConnectSecure, NinjaOne, Datto RMM, or equivalent technologies.
  • Working knowledge of PSA and workflow platforms, with HaloPSA experience preferred, including ticket configuration and reporting.
  • Practical understanding of risk-based vulnerability prioritization using CVSS, exploit intelligence, asset criticality, and business context rather than relying solely on severity scores.
  • Familiarity with cybersecurity and compliance requirements associated with CMMC, PCI DSS, SOC 2, HIPAA, and NCUA examinations.
  • Strong written and verbal communication skills, including experience leading client meetings and translating technical findings for non-technical audiences.
  • Ability to coordinate and influence work across multiple teams without direct reporting authority.
  • Strong organizational, analytical, and problem-solving skills, with the ability to manage competing priorities and maintain consistent follow-through.
  • Relevant certifications such as Security+, GIAC, CISSP, or vendor-specific credentials are preferred but not required.
  • Comfortable working directly in security tooling and taking a hands-on approach rather than managing program activities solely from a strategic or administrative level.
Benefits
  • Salary: $75,000–$100,000 annually.
  • Full-time, exempt position.
  • Standard business hours with flexibility around month-end close.
  • Innovative cybersecurity and IT solutions supporting financial and regulated industries.
  • Opportunities for professional growth and hands-on exposure to enterprise-level security operations and program execution.
  • Collaborative, people-focused environment that values learning, structure, and shared success.
  • Occasional travel opportunities for client engagement, team integration, and offsite activities.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Vulnerability Management
Manager, Vulnerability Management

Optimum • Norwalk (CT)

On-site
USD 133,000 - 220,000
Vulnerability Management Manager
Vulnerability Management Manager

Considine Search • New York (NY)

On-site
USD 200,000 - 215,000
Corporate Vice President - Head of Enterprise Vulnerability Management
Corporate Vice President - Head of Enterprise Vulnerability Management

New York Life • New York (NY)

On-site
USD 147,000 - 211,000
Vulnerability Management Lead
Vulnerability Management Lead

K2United, LLC. • Washington

On-site
USD 130,000 - 170,000
Vulnerability Management Lead
Vulnerability Management Lead

K2Share LLC • Washington

On-site
USD 120,000 - 180,000
Senior Vulnerability Analyst
Senior Vulnerability Analyst

PRI Global • O’Fallon (MO)

On-site
USD 110,000 - 160,000
Vulnerability & Cloud Security Program Manager
Vulnerability & Cloud Security Program Manager

NinjaOne • United States

Hybrid
USD 180,000 - 220,000
Medical, dental, and vision insurance
401(k) plan
Life insurance coverage
+1
Vulnerability & Cloud Security Program Manager
Vulnerability & Cloud Security Program Manager

NinjaOne • Town of Florida (NY)

Hybrid
USD 180,000 - 220,000
Medical, dental, vision insurance
401(k) plan
Unlimited PTO
Vulnerability & Cloud Security Program Manager
Vulnerability & Cloud Security Program Manager

NinjaOne • California (MO)

Hybrid
USD 180,000 - 220,000
Medical, dental, and vision insurance
401(k) plan
Life insurance coverage
+2
Vulnerability & Cloud Security Program Manager
Vulnerability & Cloud Security Program Manager

NinjaOne • Connecticut

Hybrid
USD 180,000 - 220,000
Medical, dental, and vision insurance
401(k) plan
Unlimited PTO