Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Vulnerability Manager [Remote]

Full-time

jobgether

United States
  • Remote job

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Vulnerability Manager based in United States.

This role owns the vulnerability management program end to end, from intake and risk assessment through remediation, reporting, and closure verification.
You will operate the program as a hands-on security leader, designing processes, driving automation, and maintaining an authoritative view of vulnerability risk across the product portfolio.
A key focus will be supporting FedRAMP 20x requirements and establishing vulnerability management capabilities for new products and services as they launch.
You will work closely with Security Engineering and product engineering teams to integrate scanning, asset inventory, ticketing, dashboards, and other security capabilities.
The role requires strong risk judgment, balancing exploitability, exposure, asset criticality, and compensating controls rather than relying solely on vulnerability scores.
You will also lead rapid response to actively exploited and zero-day vulnerabilities while communicating risk clearly to engineers, executives, auditors, and other stakeholders.
This is a fully remote, North America-based position suited to someone who combines security expertise, operational ownership, automation, and strong cross-functional influence.

Accountabilities:

  • Design and operate the complete product vulnerability management lifecycle, including intake, triage, risk assessment, assignment, SLA tracking, exception handling, and closure verification.
  • Own vulnerability management for FedRAMP 20x, including continuous monitoring, machine-readable evidence, Key Security Indicator reporting, and POA&M management from creation through closure.
  • Establish vulnerability management processes for new products and services by defining scan coverage, onboarding assets, setting remediation SLAs, and establishing reporting from the first release.
  • Assess and prioritize vulnerability risk using exploitability, exposure, asset criticality, compensating controls, CVSS, and other relevant threat intelligence.
  • Drive remediation across product engineering teams by assigning ownership, agreeing timelines, escalating overdue Critical and High findings, and documenting time-bound risk acceptances.
  • Automate repetitive vulnerability management activities using scripting, workflow tooling, and AI-assisted analysis for triage, deduplication, enrichment, summarization, and evidence collection.
  • Define technical requirements for security platform integrations covering vulnerability scanners, ticketing systems, asset inventories, dashboards, and related capabilities.
  • Partner with Security Engineering throughout integration design, delivery, validation, and operational adoption.
  • Own and report key program metrics, including SLA attainment, mean time to remediate, vulnerability aging, backlog trends, scan and asset coverage, and exception volumes.
  • Maintain an accurate, current view of critical exposure across the product portfolio and serve as the authoritative source for vulnerability status, business impact, and remediation timelines.
  • Lead rapid response to actively exploited and zero-day vulnerabilities by assessing exposure, coordinating mitigation, tracking remediation, and communicating with relevant stakeholders.

Requirements:

  • 5+ years of experience in vulnerability management, product security, or security operations, with direct ownership of a vulnerability management program.
  • Demonstrated experience designing and operating vulnerability management processes within regulated or audited environments and sustaining them through assessment cycles.
  • Working knowledge of FedRAMP and NIST SP 800-53, particularly vulnerability scanning, flaw remediation, continuous monitoring, configuration management, and POA&M management.
  • Hands-on experience with enterprise vulnerability and exposure management platforms, cloud security posture tools, container scanning, and software composition analysis.
  • Practical automation skills using Python or an equivalent scripting language, workflow and reporting tools, and AI assistants to reduce manual triage and reporting effort.
  • Ability to write clear technical requirements and collaborate effectively with Security Engineering through design, delivery, testing, and acceptance.
  • Strong understanding of CVSS, CISA Known Exploited Vulnerabilities (KEV), EPSS, and risk-based prioritization, with sound judgment when distinguishing high scores from actual exposure.
  • Working knowledge of cloud services, preferably AWS, as well as containers, Kubernetes, CI/CD, web applications, and APIs.
  • Ability to evaluate security findings, understand technical risk, and assess proposed remediation approaches.
  • Strong ability to influence engineering teams and drive remediation without direct authority.
  • Clear written and verbal communication skills with engineers, executives, auditors, and customers.
  • Direct experience with FedRAMP Moderate or High authorization, continuous monitoring, or FedRAMP 20x is a plus.
  • Experience developing metrics, reporting, or dashboards for executive and audit audiences is a plus.
  • Experience with SaaS, identity security, or privileged access management products is advantageous.
  • Familiarity with agentic or AI-assisted security workflows is a plus.
  • Cloud security certifications such as AWS, Azure, or GCP certifications, GIAC, CISSP, or equivalent credentials are advantageous.

Benefits:

  • Fully remote work for candidates based in North America.
  • Competitive compensation and employee benefits.
  • Opportunity to own a security program with significant impact across a broad product portfolio.
  • Exposure to regulated cybersecurity environments, including FedRAMP 20x and NIST-aligned practices.
  • Hands-on work with vulnerability management, cloud security, containers, Kubernetes, automation, and AI-assisted security workflows.
  • Close collaboration with Security Engineering, product engineering, security leadership, auditors, and other technical stakeholders.
  • An environment that values flexibility, trust, continual learning, diversity, inclusion, and professional growth.

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Vulnerability Manager [Remote] in United States vacancy
  • $144.9k - $302.1k

     ...business as usual require heavy information security measures. As a Manager in the Attack & Penetration Testing team, you will lead...  ...would include identifying potential threats and vulnerabilities to enteprise environments. You role would involve leading technical... 
    Suggested
    Full time
    Work experience placement
    Immediate start
    Remote work

    EY

    Florida
    3 days ago
  •  .... You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself. The Role The Vulnerability Manager operates BeyondTrust's product vulnerability management program end to end. This is an operator role: you design the process... 
    Suggested
    Full time
    Remote work

    Beyondtrust

    Remote
    6 days ago
  •  ...federal, state and local organizations. We are seeking a seasoned Information Assurance professional to join our team as a Vulnerability Assessment Manager . The Vulnerability Assessment Manger will conduct comprehensive vulnerability assessments using advanced tools... 
    Suggested
    Full time
    Temporary work
    Work experience placement
    Work at office
    Local area
    Immediate start
    Monday to Friday

    INODE INK

    Montgomery, AL
    27 days ago
  • $100k - $200k

     ...maintain the custom solutions that ANS delivers. Together, let’s ensure today is safe and tomorrow is smarter. ANS is seeking a System Vulnerability Analyst to join our team in Annapolis Junction, MD.RequirementsActive TS/SCI clearance and Polygraph requiredMinimum of (4)... 
    Suggested
    Temporary work
    Local area

    Applied Network Solutions

    Annapolis Junction, MD
    5 days ago
  • $92.3k - $166.85k

     ...connecting intelligence, engineering analysis, and operational vulnerabilities.Primary ResponsibilitiesAll-Source Intelligence ReviewReview...  ...:C4 node hierarchy and engagement decision timelines.Battle management, weapon-target assignment, and engagement sequencing under... 
    Suggested
    Full time
    Work at office

    Leidos

    Suitland, MD
    4 days ago
  • $184k - $287.5k

    NVIDIA is looking for a brilliant Software & Systems Architect to join the NIC Software/Firmware Architecture group. Be part of a team crafting the upcoming data-center DPU generation with hardware and software architects, R&D teams, and external customers. We have assembled...
    Full time

    Nvidia

    Santa Clara, CA
    4 days ago
  • $224k - $356.5k

    NVIDIA Networking has been a leader in high performance networking infrastructure for many years. The next unit of computing is the datacenter, and the network makes it all possible! We are growing our networking architecture team with people passionate about accelerated...
    Full time

    Nvidia

    Santa Clara, CA
    5 days ago
  • $97k - $143k

     ...to achieve its goals. The Business Analyst is responsible for business analysis planning; requirements elicitation; requirements management and communication; requirements analysis and validation for medium and large projects; estimation of BA work and meeting estimates... 
    Local area
    Relocation

    Eaton Corporation

    Galesburg, MI
    5 days ago
  •  ...occasionally move about inside the office to access file cabinets, office machinery, etc . Frequently communicates with co-workers, management, and customers, which may involve delivering presentations . Must be able to exchange accurate information in these situations... 
    Work at office

    MANTECH

    Springfield, VA
    1 day ago
  •  ...applications • Sound problem resolution, judgment, and decision-making skills • Excellent organizational, interpersonal, and project management skills • Fluently communicates in both written and oral English • Ability to work well individually and as part of a team... 
    Full time
    Work experience placement

    Avtech Solution

    Remote
    1 day ago
  •  ...effective relationships with peers and communicate at all levels within the organization. ~ Ability to provide Tier 3 support and manage complex and escalated tickets in production environment Additional Information All your information will be kept... 
    Full time
    Contract work
    Work at office

    krg technology

    Herndon, VA
    1 day ago
  •  ...development of Firewall frameworks and concepts to be used as roadmaps for the business, gap analysis, metrics, reporting and for management to visualize concepts to make a business decisions Efficiently translate project architecture/environment diagrams to... 
    Permanent employment
    Full time
    Temporary work
    Flexible hours

    Epro Consulting

    Remote
    1 day ago
  • $114.6k - $157.6k

     ...TransformationLead requirements gathering, solution design reviews, functional specifications, testing, deployment, and hypercare activities.Manage multiple concurrent initiatives and project workstreams.Collaborate with development, integration, data, analytics, and... 
    Full time
    Temporary work
    Immediate start

    Campbell Soup Company

    Camden, NJ
    4 days ago
  • $148.3k - $266.9k

     ...to achieve your full potential. Unleash your talent and redefine what’s possible.Job Description:Parsons is looking for a Cyber Vulnerability Analyst with a background in Red Team/Penetration Testing to join our team. In this role you will be responsible for simulating... 
    Full time
    Work experience placement
    Flexible hours

    Parsons

    Annapolis Junction, MD
    2 days ago
  • $113.84k - $170.76k

     ...initiatives, and ensuring solutions align with business objectives and organizational standards.Responsibilities:Partner with multiple management teams to ensure appropriate integration of functions to meet goals as well as identify and define necessary system enhancements... 
    Full time

    Citigroup

    Jacksonville, FL
    3 days ago
  •  ...operational oversight of the Bank's technology governance, risk management, and compliance (GRC) program. Serves as a primary liaison...  ...domains (identity and access management, change management, vulnerability management, data protection) and validate remediation effectiveness... 
    Contract work
    Work at office

    WesBanco

    Wheeling, WV
    4 days ago
  • $146k - $234k

     ...guidance.Develop security policies and procedures, CSS, SSP, SSPP, and assess ATO package artifacts.Apply expert knowledge of Risk Management Framework (RMF) v5 processes and workflows.Use eMASS to execute RMF v5 activities, document and update system status, identify... 
    Contract work
    Work experience placement
    Shift work

    Peraton Corporation

    Washington, VA
    1 day ago
  • $110k - $150k

     ...Extending or integrating on premises AD with Entra ID. Managing identity and access in Microsoft Entra ID. Experience...  ...USS Secure CTF's) Security research resulting in a Common Vulnerabilities and Exposures (CVE) Responsibilities: Debug and... 
    Contract work
    Temporary work
    Casual work
    Flexible hours

    SimVentions, Inc - Glassdoor ✪ 4.6

    Charlotte Hall, MD
    16 hours ago
  •  ...documentation, data handling, chain-of-custody maintenance, equipment management, and other support functions that enable forensic and...  ...enterpriseResearch evolving threats, techniques, tools, and vulnerabilities in support of information security effortsStay current with... 
    Full time
    Work at office
    Local area
    Remote work
    1 day per week

    MUFG

    Jersey City, NJ
    4 days ago
  •  ...enterprise! As a Uline Senior IT Security Administrator, support our IT security operations with excellence and collaboration. From managing security controls to fostering resilience, your expertise will protect our business against evolving threats.Careers Packed with... 
    Full time

    Uline Shipping Supplies

    Waukegan, IL
    4 days ago
  • $104k - $166k

    Responsibilities Peraton is currently seeking a Senior Digital Forensic Analyst to support Federal Strategic Cyber programs in the Cyber & Intelligence sector.Location: On-site, Arlington, VAIn this role, you will: Conduct forensic examinations of digital data from cellphones...
    Contract work
    Interim role
    Local area
    Shift work

    Peraton Corporation

    Arlington, VA
    1 day ago
  •  ...intelligence, inspiring the world to learn, communicate and advance faster than ever.About our Team:As an IT Disaster Recovery Program Manager within Micron's Governance, Risk, Compliance, and Cyber Resilience organization, you will serve as the subject matter expert... 
    Full time
    Local area
    Immediate start

    Micron

    Boise, ID
    2 days ago
  • $98.57k - $160.17k

    Job DescriptionJob Title: Digital Forensics AnalystWorking Pattern: Fulltime - hybridWorking location: Indianapolis, INRelocation assistance will be provided if applicableWhy Rolls-Royce?At Rolls-Royce we are proud to be a business that has truly helped to shape the modern...
    Full time
    Remote work
    Flexible hours

    Rolls-Royce

    Indianapolis, IN
    1 day ago
  • $86k - $138k

    ResponsibilitiesPeraton is currently seeking a Mid-Level Digital Forensic Analyst to support Federal Strategic Cyber programs in the Cyber & Intelligence sector.Location: On-site, Arlington, VARole: This role focuses on the recovery, analysis, and reporting of digital evidence...
    Contract work
    Interim role
    Local area
    Shift work

    Peraton Corporation

    Arlington, VA
    1 day ago
  • $80k - $128k

     ...device support; provide configuration, change, license, and asset management; conduct training, and perform Install, Move, Add, Change (...  ...asset inventories, and standard operating procedures (SOPs).Vulnerability Remediation: Identify security vulnerabilities within the... 
    Contract work
    Shift work

    Peraton Corporation

    Florida
    1 day ago
  •  ...project borders with other teams. Thinks outside the box and proposes practical solutions to issues. Provides oversight and project management to assigned tasks. Demonstrates a solid/working level of subject matter expertise in providing support to projects, customers,... 
    Full time

    Christus Health

    Irving, TX
    1 day ago
  •  .... Specific responsibilities include providing oversight for applications support including Incident, Problem, Request and Change Management. This position requires a self-starter with the ability to work with minimal oversight. Responsibilities: Acts as primary representation... 
    Full time
    Monday to Friday

    Christus Health

    Whitehouse, TX
    1 day ago
  •  ...quality assurance and testing initiatives. Demonstrates ability to lead team through complex integrated testing processes. Able to manage testing projects as necessary. Demonstrates an advanced level of application understanding, and applies expertise to help meet customer... 
    Full time

    Christus Health

    Dallas, TX
    1 day ago
  • $114.52k - $130.76k

     ...administration and ongoing enhancement of the Information Security Management System with a primary focus on ISO 27001, Cryptographic Key...  ..., reporting and assisting in the remediation of IT security vulnerabilities for IT systems and applications that are part of G+D... 
    Temporary work
    Local area
    Flexible hours

    Veridos

    Bolingbrook, IL
    1 day ago
  •  ...for IT security (e.g., NIST, FS-ISAC, etc.)Oversight of patch management process. Works with the Security team, Network...  ...s network and systems.Stays current on emerging threats and vulnerabilities, proactively safeguarding bank systems from potential attacks... 
    Local area

    PeoplesBank

    Holyoke, MA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Vulnerability Manager [Remote]. Be the first to apply!