Vulnerability Management, Manager
Core
Design, define, and implement security requirements and processes for secure development and operation of cloud-based and on-premises applications, focusing on vulnerability management and remediation.
Role type
Manager, Vulnerability Management & Application Security
Builds
Secure cloud and on-premises application infrastructure and CI/CD pipelines
Domain
Cloud Security / Application Security / DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Vulnerability assessment and remediation, Threat modeling, Secure architectural design review, Patch management, CI/CD pipeline security, Penetration testing, Risk-based vulnerability prioritization, Cloud security (AWS/Azure/GCP), Container security, Secure coding practices
Preferred skills
Kubernetes, Docker, Terraform, Serverless functions, SAST/SCA/IaC/DAST/IAST tools, OWASP/SAMM/ASVS/NIST standards, Vendor management for security tools
Technologies
Terraform, Kubernetes, Serverless functions, Jenkins, AWS, Azure, GCP, GitHub, TFS, SAST, SCA, IaC, DAST, IAST
Responsibilities
Implement and enforce vulnerability management tools and processes in CI/CD pipelines, Conduct threat modeling and data flow diagrams with engineering teams, Manage manual and automated vulnerability management for priority issues including zero-days, Develop and maintain patch management processes and schedules, Advise developers on secure coding and vulnerability mitigation strategies, Lead vulnerability management projects and collaborate with vendors on new security tools
Seniority
Manager, hands-on IC with team leadership