Vulnerability Manager [Remote]
jobgether
- Remote job
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Vulnerability Manager based in United States.
This role owns the vulnerability management program end to end, from intake and risk assessment through remediation, reporting, and closure verification.
You will operate the program as a hands-on security leader, designing processes, driving automation, and maintaining an authoritative view of vulnerability risk across the product portfolio.
A key focus will be supporting FedRAMP 20x requirements and establishing vulnerability management capabilities for new products and services as they launch.
You will work closely with Security Engineering and product engineering teams to integrate scanning, asset inventory, ticketing, dashboards, and other security capabilities.
The role requires strong risk judgment, balancing exploitability, exposure, asset criticality, and compensating controls rather than relying solely on vulnerability scores.
You will also lead rapid response to actively exploited and zero-day vulnerabilities while communicating risk clearly to engineers, executives, auditors, and other stakeholders.
This is a fully remote, North America-based position suited to someone who combines security expertise, operational ownership, automation, and strong cross-functional influence.
Accountabilities:
- Design and operate the complete product vulnerability management lifecycle, including intake, triage, risk assessment, assignment, SLA tracking, exception handling, and closure verification.
- Own vulnerability management for FedRAMP 20x, including continuous monitoring, machine-readable evidence, Key Security Indicator reporting, and POA&M management from creation through closure.
- Establish vulnerability management processes for new products and services by defining scan coverage, onboarding assets, setting remediation SLAs, and establishing reporting from the first release.
- Assess and prioritize vulnerability risk using exploitability, exposure, asset criticality, compensating controls, CVSS, and other relevant threat intelligence.
- Drive remediation across product engineering teams by assigning ownership, agreeing timelines, escalating overdue Critical and High findings, and documenting time-bound risk acceptances.
- Automate repetitive vulnerability management activities using scripting, workflow tooling, and AI-assisted analysis for triage, deduplication, enrichment, summarization, and evidence collection.
- Define technical requirements for security platform integrations covering vulnerability scanners, ticketing systems, asset inventories, dashboards, and related capabilities.
- Partner with Security Engineering throughout integration design, delivery, validation, and operational adoption.
- Own and report key program metrics, including SLA attainment, mean time to remediate, vulnerability aging, backlog trends, scan and asset coverage, and exception volumes.
- Maintain an accurate, current view of critical exposure across the product portfolio and serve as the authoritative source for vulnerability status, business impact, and remediation timelines.
- Lead rapid response to actively exploited and zero-day vulnerabilities by assessing exposure, coordinating mitigation, tracking remediation, and communicating with relevant stakeholders.
Requirements:
- 5+ years of experience in vulnerability management, product security, or security operations, with direct ownership of a vulnerability management program.
- Demonstrated experience designing and operating vulnerability management processes within regulated or audited environments and sustaining them through assessment cycles.
- Working knowledge of FedRAMP and NIST SP 800-53, particularly vulnerability scanning, flaw remediation, continuous monitoring, configuration management, and POA&M management.
- Hands-on experience with enterprise vulnerability and exposure management platforms, cloud security posture tools, container scanning, and software composition analysis.
- Practical automation skills using Python or an equivalent scripting language, workflow and reporting tools, and AI assistants to reduce manual triage and reporting effort.
- Ability to write clear technical requirements and collaborate effectively with Security Engineering through design, delivery, testing, and acceptance.
- Strong understanding of CVSS, CISA Known Exploited Vulnerabilities (KEV), EPSS, and risk-based prioritization, with sound judgment when distinguishing high scores from actual exposure.
- Working knowledge of cloud services, preferably AWS, as well as containers, Kubernetes, CI/CD, web applications, and APIs.
- Ability to evaluate security findings, understand technical risk, and assess proposed remediation approaches.
- Strong ability to influence engineering teams and drive remediation without direct authority.
- Clear written and verbal communication skills with engineers, executives, auditors, and customers.
- Direct experience with FedRAMP Moderate or High authorization, continuous monitoring, or FedRAMP 20x is a plus.
- Experience developing metrics, reporting, or dashboards for executive and audit audiences is a plus.
- Experience with SaaS, identity security, or privileged access management products is advantageous.
- Familiarity with agentic or AI-assisted security workflows is a plus.
- Cloud security certifications such as AWS, Azure, or GCP certifications, GIAC, CISSP, or equivalent credentials are advantageous.
Benefits:
- Fully remote work for candidates based in North America.
- Competitive compensation and employee benefits.
- Opportunity to own a security program with significant impact across a broad product portfolio.
- Exposure to regulated cybersecurity environments, including FedRAMP 20x and NIST-aligned practices.
- Hands-on work with vulnerability management, cloud security, containers, Kubernetes, automation, and AI-assisted security workflows.
- Close collaboration with Security Engineering, product engineering, security leadership, auditors, and other technical stakeholders.
- An environment that values flexibility, trust, continual learning, diversity, inclusion, and professional growth.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
$144.9k - $302.1k
...business as usual require heavy information security measures. As a Manager in the Attack & Penetration Testing team, you will lead... ...would include identifying potential threats and vulnerabilities to enteprise environments. You role would involve leading technical...SuggestedFull timeWork experience placementImmediate startRemote work- .... You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself. The Role The Vulnerability Manager operates BeyondTrust's product vulnerability management program end to end. This is an operator role: you design the process...SuggestedFull timeRemote work
- ...federal, state and local organizations. We are seeking a seasoned Information Assurance professional to join our team as a Vulnerability Assessment Manager . The Vulnerability Assessment Manger will conduct comprehensive vulnerability assessments using advanced tools...SuggestedFull timeTemporary workWork experience placementWork at officeLocal areaImmediate startMonday to Friday
$100k - $200k
...maintain the custom solutions that ANS delivers. Together, let’s ensure today is safe and tomorrow is smarter. ANS is seeking a System Vulnerability Analyst to join our team in Annapolis Junction, MD.RequirementsActive TS/SCI clearance and Polygraph requiredMinimum of (4)...SuggestedTemporary workLocal area$92.3k - $166.85k
...connecting intelligence, engineering analysis, and operational vulnerabilities.Primary ResponsibilitiesAll-Source Intelligence ReviewReview... ...:C4 node hierarchy and engagement decision timelines.Battle management, weapon-target assignment, and engagement sequencing under...SuggestedFull timeWork at office$184k - $287.5k
NVIDIA is looking for a brilliant Software & Systems Architect to join the NIC Software/Firmware Architecture group. Be part of a team crafting the upcoming data-center DPU generation with hardware and software architects, R&D teams, and external customers. We have assembled...Full time$224k - $356.5k
NVIDIA Networking has been a leader in high performance networking infrastructure for many years. The next unit of computing is the datacenter, and the network makes it all possible! We are growing our networking architecture team with people passionate about accelerated...Full time$97k - $143k
...to achieve its goals. The Business Analyst is responsible for business analysis planning; requirements elicitation; requirements management and communication; requirements analysis and validation for medium and large projects; estimation of BA work and meeting estimates...Local areaRelocation- ...occasionally move about inside the office to access file cabinets, office machinery, etc . Frequently communicates with co-workers, management, and customers, which may involve delivering presentations . Must be able to exchange accurate information in these situations...Work at office
- ...applications • Sound problem resolution, judgment, and decision-making skills • Excellent organizational, interpersonal, and project management skills • Fluently communicates in both written and oral English • Ability to work well individually and as part of a team...Full timeWork experience placement
- ...effective relationships with peers and communicate at all levels within the organization. ~ Ability to provide Tier 3 support and manage complex and escalated tickets in production environment Additional Information All your information will be kept...Full timeContract workWork at office
- ...development of Firewall frameworks and concepts to be used as roadmaps for the business, gap analysis, metrics, reporting and for management to visualize concepts to make a business decisions Efficiently translate project architecture/environment diagrams to...Permanent employmentFull timeTemporary workFlexible hours
$114.6k - $157.6k
...TransformationLead requirements gathering, solution design reviews, functional specifications, testing, deployment, and hypercare activities.Manage multiple concurrent initiatives and project workstreams.Collaborate with development, integration, data, analytics, and...Full timeTemporary workImmediate start$148.3k - $266.9k
...to achieve your full potential. Unleash your talent and redefine what’s possible.Job Description:Parsons is looking for a Cyber Vulnerability Analyst with a background in Red Team/Penetration Testing to join our team. In this role you will be responsible for simulating...Full timeWork experience placementFlexible hours$113.84k - $170.76k
...initiatives, and ensuring solutions align with business objectives and organizational standards.Responsibilities:Partner with multiple management teams to ensure appropriate integration of functions to meet goals as well as identify and define necessary system enhancements...Full time- ...operational oversight of the Bank's technology governance, risk management, and compliance (GRC) program. Serves as a primary liaison... ...domains (identity and access management, change management, vulnerability management, data protection) and validate remediation effectiveness...Contract workWork at office
$146k - $234k
...guidance.Develop security policies and procedures, CSS, SSP, SSPP, and assess ATO package artifacts.Apply expert knowledge of Risk Management Framework (RMF) v5 processes and workflows.Use eMASS to execute RMF v5 activities, document and update system status, identify...Contract workWork experience placementShift work$110k - $150k
...Extending or integrating on premises AD with Entra ID. Managing identity and access in Microsoft Entra ID. Experience... ...USS Secure CTF's) Security research resulting in a Common Vulnerabilities and Exposures (CVE) Responsibilities: Debug and...Contract workTemporary workCasual workFlexible hours- ...documentation, data handling, chain-of-custody maintenance, equipment management, and other support functions that enable forensic and... ...enterpriseResearch evolving threats, techniques, tools, and vulnerabilities in support of information security effortsStay current with...Full timeWork at officeLocal areaRemote work1 day per week
- ...enterprise! As a Uline Senior IT Security Administrator, support our IT security operations with excellence and collaboration. From managing security controls to fostering resilience, your expertise will protect our business against evolving threats.Careers Packed with...Full time
$104k - $166k
Responsibilities Peraton is currently seeking a Senior Digital Forensic Analyst to support Federal Strategic Cyber programs in the Cyber & Intelligence sector.Location: On-site, Arlington, VAIn this role, you will: Conduct forensic examinations of digital data from cellphones...Contract workInterim roleLocal areaShift work- ...intelligence, inspiring the world to learn, communicate and advance faster than ever.About our Team:As an IT Disaster Recovery Program Manager within Micron's Governance, Risk, Compliance, and Cyber Resilience organization, you will serve as the subject matter expert...Full timeLocal areaImmediate start
$98.57k - $160.17k
Job DescriptionJob Title: Digital Forensics AnalystWorking Pattern: Fulltime - hybridWorking location: Indianapolis, INRelocation assistance will be provided if applicableWhy Rolls-Royce?At Rolls-Royce we are proud to be a business that has truly helped to shape the modern...Full timeRemote workFlexible hours$86k - $138k
ResponsibilitiesPeraton is currently seeking a Mid-Level Digital Forensic Analyst to support Federal Strategic Cyber programs in the Cyber & Intelligence sector.Location: On-site, Arlington, VARole: This role focuses on the recovery, analysis, and reporting of digital evidence...Contract workInterim roleLocal areaShift work$80k - $128k
...device support; provide configuration, change, license, and asset management; conduct training, and perform Install, Move, Add, Change (... ...asset inventories, and standard operating procedures (SOPs).Vulnerability Remediation: Identify security vulnerabilities within the...Contract workShift work- ...project borders with other teams. Thinks outside the box and proposes practical solutions to issues. Provides oversight and project management to assigned tasks. Demonstrates a solid/working level of subject matter expertise in providing support to projects, customers,...Full time
- .... Specific responsibilities include providing oversight for applications support including Incident, Problem, Request and Change Management. This position requires a self-starter with the ability to work with minimal oversight. Responsibilities: Acts as primary representation...Full timeMonday to Friday
- ...quality assurance and testing initiatives. Demonstrates ability to lead team through complex integrated testing processes. Able to manage testing projects as necessary. Demonstrates an advanced level of application understanding, and applies expertise to help meet customer...Full time
$114.52k - $130.76k
...administration and ongoing enhancement of the Information Security Management System with a primary focus on ISO 27001, Cryptographic Key... ..., reporting and assisting in the remediation of IT security vulnerabilities for IT systems and applications that are part of G+D...Temporary workLocal areaFlexible hours- ...for IT security (e.g., NIST, FS-ISAC, etc.)Oversight of patch management process. Works with the Security team, Network... ...s network and systems.Stays current on emerging threats and vulnerabilities, proactively safeguarding bank systems from potential attacks...Local area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Manager [Remote]. Be the first to apply!
- vulnerability manager United States
- disaster recovery manager United States
- remote writer editor United States
- product manager remote United States
- remote frontend developer United States
- php developer remote United States
- remote salesforce developer United States
- junior project manager remote United States
- remote contract attorney United States
- instructional designer (remote) United States



