Source Job

US 3w PTO

  • Lead the enterprise Vulnerability Management and CDM program, directing scanning and prioritization strategies.
  • Coordinate remediation activities across system owners, engineering teams, and ISSOs to reduce cyber risk.
  • Develop executive metrics, dashboards, and reports to communicate vulnerability posture and operational risk trends.

Vulnerability Management Threat Intelligence

20 jobs similar to Vulnerability Management Lead

Jobs ranked by similarity.

US 3w PTO

  • Analyze enterprise vulnerability data to identify the highest priority cyber exposures across the NIH environment.
  • Correlate vulnerability findings with threat intelligence, exploit availability, and operational risk to improve remediation prioritization.
  • Collaborate with incident responders, penetration testers, and security engineers to refine enterprise risk prioritization.

True Zero Technologies is a veteran-owned small business founded on the principle that enabling people and technology drives quality outcomes. We are a people-first company recognized as a Best Place to Work and on the Inc. 5000 list of fastest-growing companies.

US

  • Oversee the enterprise vulnerability management program, including administering Tenable platforms and conducting regular assessments.
  • Monitor and respond to MDR alerts, investigate security incidents, and coordinate remediation efforts.
  • Review and approve cybersecurity-related change requests, ensuring security risks are communicated and mitigated.

Loenbro is a trusted, long-term construction lifecycle partner serving thousands of customers across the U.S. They have a national presence with a local approach, and build careers grounded in integrity, teamwork, excellence, and purpose.

US

  • Manage the vulnerability management program end-to-end, including scanning and remediation.
  • Collaborate with developers on secure architecture, threat modeling, and code dependency reviews.
  • Oversee bug bounty programs, security tools, incident response, and compliance frameworks.

RainFocus provides an industry-disrupting event management platform for Fortune 500 companies like Adobe, Cisco, and IBM. The company is well-funded, rapidly growing, and fosters a culture of innovation, teamwork, and fun.

United States

  • Lead complex Global Vulnerability Management workstreams to advance Threat Exposure Management capabilities and transition to a Continuous Threat Exposure Management model.
  • Conduct hands-on vulnerability research, technical analysis, and security validation to eliminate false positives, characterize exploitability, and provide actionable remediation guidance.
  • Partner across Information Security and engineering teams to evolve platforms, integrations, and automation for improved discovery, prioritization, and remediation outcomes.

Sony Interactive Entertainment (SIE) is the company behind the PlayStation brand, delivering innovative gaming hardware and network services to over 100 million people worldwide. As a subsidiary of Sony Group Corporation, SIE is a dynamic and entertainment-focused organization that values innovation, excellence, and employee empowerment.

US 3w PTO

  • Lead quality assurance for RMF authorization packages to ensure completeness and readiness for government review.
  • Coordinate with RMF analysts, ISSOs, system owners, and technical stakeholders to validate security documentation and evidence.
  • Mentor team members on documentation standards and best practices while tracking assessment readiness metrics to reduce rework.

True Zero Technologies is a veteran-owned small business that enables people and technology to drive quality outcomes. The company has been named a Best Place to Work multiple times and made the Inc. 5000 list of fastest-growing companies, reflecting its people-first culture and commitment to excellence.

EMEA

  • You'll lead the VIPR & VMDR function, integrating vulnerability intelligence, detection, and response for customers across APJ/APAC.
  • You'll operate and tune vulnerability detection tools like Tenable, Qualys, and Rapid7, and automate pipelines using Python and REST APIs.
  • You'll build risk dashboards and executive briefings, and collaborate with Customer Success and Security Engineering to improve remediation metrics.

ServiceNow is the AI control tower for business reinvention, bringing together AI, data, and workflows to help 85% of the Fortune 500 work smarter. The company fosters an AI-native culture where technology and talent are unstoppable together.

$86,000–$96,000/yr
US

  • Conduct vulnerability assessments using tools like Tenable, Qualys, and Burp to identify security weaknesses.
  • Analyze scan results and produce detailed reports with remediation recommendations.
  • Collaborate with technical teams to ensure timely delivery of assessment results and effective risk reduction.

The company provides cybersecurity services including vulnerability assessment and risk management. It fosters a collaborative remote environment focused on continuous learning and professional growth.

$41–$51/hr
US

  • Own the vulnerability management program, prioritizing and driving a culture of ownership across business units.
  • Drive metrics and program review to transparently communicate performance and accountability.
  • Provide expert leadership to highly visible, multi-faceted projects while coordinating across teams and geographies.

We empower organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity of our customers and trusted alliance of elite hackers with our patented data and AI-powered Security Knowledge Platform. We are based in San Francisco and New Hampshire, supported by General Catalyst and others, and we foster a diverse and inclusive culture.

US

  • Lead bug bounty program strategy and vulnerability management initiatives.
  • Collaborate with engineering and security teams to drive remediation efforts.
  • Conduct code reviews and develop security tooling to improve efficiency.

This company operates a global technology platform. It values security, collaboration, and continuous learning, with a team dedicated to protecting user privacy and safety.

$170,000–$231,000/yr
United States Unlimited PTO 18w maternity 12w paternity

  • Manage a novel vulnerabilities pipeline, owning measurement, disclosure, and reporting of thousands of vulnerabilities weekly.
  • Coordinate across the industry with bodies like the Linux Foundation and CISA, and represent Chainguard externally.
  • Guide industry direction and work with AI model vendors to evolve software supply chain security.

Chainguard is the trusted source for open source, delivering hardened, secure, and production-ready builds of open source software. The company is venture-backed by leading investors and serves Fortune 500 enterprises and global industry leaders.

$120,000–$140,000/yr
US Unlimited PTO

  • Define and enforce security requirements for software products, features, and components.
  • Design, perform, and maintain security analysis on commercial products throughout the product lifecycle.
  • Collaborate with cross-functional teams to perform vulnerability management and implement mitigation strategies.

symplr is revolutionizing healthcare operations with a platform that drives effective, efficient, and connected workflows. The company is remote-first with employees across the US, India, and the Netherlands, and values teamwork, customer focus, and integrity.

$145,000–$160,000/yr
US

  • Design, implement, and maintain enterprise security solutions to strengthen cybersecurity posture and advance Zero Trust maturity.
  • Operate security tools like EDR, SIEM, and vulnerability scanners, integrating security into CI/CD pipelines.
  • Build dashboards to measure security performance and Zero Trust maturity metrics.

Valiant Solutions is a security-focused IT solutions provider serving public clients nationwide. Named one of the fastest-growing privately held companies, they pride themselves on an employee-centric culture and great benefits.

$155,000–$160,000/yr
US

  • Oversee daily vulnerability identification, triage, and reporting across AWS cloud assets and AI/LLM application stacks.
  • Leverage ACAS (Tenable.sc) and AWS security tools to evaluate threat vectors and ensure compliance with DISA STIG benchmarks.
  • Translate complex technical findings into actionable remediation guidance and executive briefings for government stakeholders.

Dark Wolf is a cybersecurity firm specializing in vulnerability management and cloud security for federal and DoD systems. The company maintains a collaborative, mission-focused culture with a team of cybersecurity professionals.

India

  • Manage vulnerability assessments across operating systems, containers, dependencies, and application environments.
  • Perform vulnerability triage, validation, and proof-of-concept testing to determine real-world security impact.
  • Collaborate with engineering teams to communicate risks and drive remediation efforts.

This company provides a large-scale software platform for AI and data science solutions, serving organizations with demanding compliance and risk requirements. It fosters a culture of innovation, transparency, and collaboration, with a growing security function and an inclusive workplace.

Australia

  • Lead critical cybersecurity programs in a remote-first environment, overseeing strategic security initiatives and vulnerability management.
  • Manage multiple strategic security initiatives, ensuring timely delivery while coordinating with engineering, product, and cross-functional teams globally.
  • Drive continuous improvement by enhancing project management practices and mentoring teams on program management best practices.

Jobgether is a platform that uses AI-powered matching to connect candidates with hiring companies. The company fosters a collaborative, inclusive, and diverse workplace culture that values innovation and continuous learning.

$70,000–$77,000/yr
US

  • Perform enterprise risk assessments using NIST CSF, SOC 2, and CIS frameworks.
  • Develop and execute security awareness programs including training and phishing simulations.
  • Support governance and control management by maintaining policies and control libraries.

Protective helps protect customers against life's uncertainties by providing insurance and peace of mind. The company offers a collaborative environment with a focus on employee wellbeing and work-life balance.

US 3w PTO

  • Lead and advance governance, risk management, compliance, and information security programs to support organizational objectives and regulatory requirements.
  • Manage vulnerability management, third-party risk, security governance, policy development, and AI governance initiatives.
  • Partner with leaders to foster a culture of accountability, risk awareness, and continuous improvement.

Ultimate Medical Academy is a non-profit healthcare educational institution with a national presence, headquartered in Tampa, Florida and founded in 1994. The organization offers online and on-campus programs and fosters a culture of integrity, student success, and team member development.

US

  • Lead ISSO activities to ensure confidentiality, integrity, availability, and compliance of enterprise applications and information systems.
  • Manage RMF processes including ATO packages, continuous monitoring, risk assessments, and accreditation documentation within eMASS.
  • Implement and maintain compliance with DISA STIGs, NIST 800-53 controls, and federal cybersecurity requirements.

Jobgether is a platform that uses AI-powered matching to connect candidates with job opportunities. The company facilitates the hiring process by sharing top-fitting candidate shortlists with partner companies, focusing on efficiency and objectivity.

$80,000–$130,000/yr
US

  • You will own end-to-end compliance audits (SOC 1, SOC 2, HITRUST) and manage compliance automation platforms.
  • You will run the vulnerability management program and remediate security findings across AWS.
  • You will support security incident response, fraud investigations, and third-party risk assessments.

We are transforming post-acute care as the leading digital ordering platform for medical equipment and supplies. We connect major health systems, health plans, and suppliers to help patients get life-saving products at home, with a network of 300,000+ clinicians and 3,000+ supplier locations across all 50 states.

US

  • Support enterprise cybersecurity governance, compliance, and risk management programs.
  • Conduct security control assessments, audit readiness, and policy development.
  • Coordinate with technical teams and executive leadership to drive cybersecurity modernization.

ERP International is a nationally respected provider of health, science, and technology solutions supporting government and commercial clients. The company has been named a Top Workplace by WTOP News for 7 years and offers a culture of employee recognition, community outreach, and professional development.