Director, Vulnerability Management
Core
Technical leader and owner of the end-to-end vulnerability management program, driving strategy, architecture, and remediation across cloud, on-premise, endpoint, application, and container environments.
Role type
Director, Vulnerability Management (Technical Leader)
Builds
Enterprise vulnerability management program, risk-based remediation SLAs, attack surface management, and governance forums.
Domain
Cybersecurity, Cloud Security, Infrastructure Security
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Vulnerability management strategy, risk-based prioritization, asset discovery and inventory management, cloud security, container security, security frameworks (NIST, ISO), supply chain security (SBOM, SCA), executive communication, team leadership
Preferred skills
Penetration testing, threat intelligence correlation, zero-day response, patch management, legacy platform modernization
Technologies
Tenable, Qualys, Rapid7, Wiz, CMDB, Linux, Windows, MacOS, SAST, DAST, MITRE ATT&CK
Responsibilities
Own the strategy and roadmap of the vulnerability management program; Define risk-based remediation SLAs; Mature exposure management beyond reactive scanning; Establish governance forums for exposure trends; Oversee asset coverage integration with CMDB and cloud inventories; Lead refinement of prioritization models using CVSS and threat intelligence; Partner with red team and threat intelligence teams; Drive reduction in mean time to remediate; Lead technical response for zero-day vulnerabilities; Identify systemic root causes like patch tooling gaps; Define and report KPIs/KRIs to executive leadership; Recruit and mentor vulnerability management analysts.
Seniority
Director, hands-on technical leadership with team management