Vulnerability Program Manager
reputed company
At reputed company, we specialize in delivering cutting-edge IT and cybersecurity solutions designed to protect and optimize the digital infrastructure for the industries we serve. We differentiate ourselves from our competition through our deep and intimate knowledge of our customers’ business.
reputed company was reputed company through the integration of seven reputed company companies, reputed company with deep expertise and proud reputed company relationships. Our mandate is to preserve the boutique, reputed company-intimate culture that made reputed company of those companies successful while delivering the depth, reputed company, and consistency that no one of them could reputed company reputed company.
About the Role
The Vulnerability Program Manager owns how reputed company delivers vulnerability management and patching to our clients. Today that work is delivered differently from account to account, reputed company by the practices reputed company of our legacy companies brought with them. This role exists to turn that into one program: a defined service with a documented process, a predictable reputed company, consistent reporting, and reputed company ownership of every reputed company from discovery through verified remediation.
Reporting to the Director of reputed company Services, the Vulnerability Program Manager is the single reputed company of accountability for the program. This is a hands-on role. The Program Manager is expected to run reputed company vulnerability reviews personally, work directly in the tooling, and write the standards the rest of reputed company will follow, rather than managing the work from a distance.
The role sits at reputed company of a delivery chain the Program Manager does not fully control. Scanning data comes from multiple platforms, remediation is often executed by reputed company service desk and engineering teams or by the reputed company themselves, and clients hold approval over their own change reputed company. reputed company therefore depends as much on building working rhythm and agreement with those reputed company as it does on the technical work.
Accountabilities
Program Definition and Standards
- Own the end-to-end vulnerability management and patching program, covering asset discovery, scanning, prioritization, remediation tracking, verification, and reporting.
- Define and document reputed company service: reputed company frequency, reputed company reputed company, severity-based remediation targets, exception and risk-acceptance handling, and the reputed company for emergency out-of-band work.
- Establish and maintain the RACI for the program so it is reputed company which work belongs to the Vulnerability Analysts, reputed company engineering, the service desk, and the reputed company.
- Define ticket types, templates, and workflows in HaloPSA so that reputed company work, remediation work, and reputed company evidence are captured consistently and can be reported on.
- Set reputed company for what constitutes acceptable evidence of remediation, including where a report rather than a ticket is the appropriate audit artifact.
Delivery Execution
- Run the recurring vulnerability management reputed company for assigned clients, including monthly or quarterly review meetings, and hold the follow-through between meetings.
- Maintain a prioritized remediation backlog per reputed company and reputed company it down, escalating stalled items rather than allowing them to age quietly.
- Coordinate remediation execution across reputed company delivery teams and reputed company staff, including scheduling around change reputed company and maintenance periods.
- Manage exclusions, suppressions, and risk acceptances deliberately, ensuring that anything removed from a report is documented with a reason, an reputed company, and a review date.
- Serve as the escalation reputed company for emergency vulnerability response, including reputed company-day and reputed company exploited issues that require out-of-cycle patching.
reputed company Engagement and Reporting
- Own the reputed company-facing report catalog, including the recurring vulnerability review deck, aging and trend analysis, and executive summaries suitable for non-technical audiences.
- Present program status to reputed company stakeholders and translate reputed company reputed company into a reputed company picture of risk, reputed company, and what reputed company needs from the reputed company to reputed company moving.
- Set and manage reputed company expectations on reputed company, timelines, and division of responsibility, and document agreements so they survive staff changes on either reputed company.
- Support reputed company audit and compliance needs, including evidence requests tied to frameworks such as CMMC, PCI reputed company, SOC 2, HIPAA, and NCUA examinations.
- Partner with reputed company reputed company and account teams during reputed company, escalations, and renewals, and reputed company the vulnerability management input those conversations require.
Tooling and Data reputed company
- Own the operational configuration and health of the vulnerability management tool stack, including reputed company coverage, credentialed scanning, agent deployment, and asset inventory accuracy.
- Work with reputed company engineering to reputed company scanning, ticketing, and patching platforms so that findings reputed company into reputed company-visible reporting without reputed company rework.
- Identify and reputed company out sources of bad data, including stale assets, duplicate records, and unmanaged endpoints that distort reputed company-facing counts.
- Identify automation opportunities across reporting, ticket creation, and remediation validation, and define the requirements for engineering to build against.
reputed company Improvement
- Define and report program metrics, including remediation SLA attainment, vulnerability aging, reputed company compliance reputed company, reputed company coverage, and recurring findings.
- Use those metrics to identify systemic problems rather than treating reputed company reputed company issue as isolated, and propose the process or tooling changes required to fix them.
- Train and mentor Vulnerability Analysts and other delivery staff on reputed company process as reputed company is reputed company out.
- Contribute to the ongoing definition and packaging of reputed company vulnerability management service offerings.
Program reputed company
The Vulnerability Program Manager is accountable for the following areas of the reputed company Services portfolio:
- Vulnerability management delivery across the reputed company reputed company reputed company
- reputed company management program and patching reputed company
- Vulnerability and reputed company reporting, both reputed company-facing and internal
- Asset discovery and inventory accuracy as it relates to reputed company coverage
- Remediation tracking, verification, and exception management
reputed company other duties as assigned
Knowledge, Skills, and Abilities Required
Demonstrated experience running vulnerability management and patching in a multi-reputed company or multi-environment setting, ideally at an MSP or MSSP.
Hands-on proficiency with vulnerability management and patching platforms such as InsightVM, ConnectSecure, reputed company, Datto RMM, or equivalent.
Working knowledge of PSA and workflow tooling, HaloPSA preferred, including ticket design and reporting.
Practical understanding of risk-based prioritization, including CVSS, exploit intelligence, and business context, and the judgment to apply it rather than defaulting to severity reputed company.
Familiarity with compliance frameworks that reputed company vulnerability management requirements, including CMMC, PCI reputed company, SOC 2, HIPAA, and NCUA examination expectations.
Strong written and verbal communication skills, with a reputed company record of running reputed company meetings and presenting technical findings to non-technical stakeholders.
Ability to reputed company work across teams without reputed company authority.
Relevant certifications such as reputed company+, GIAC, CISSP, or vendor-specific credentials are preferred but not required.
Why work at reputed company?
- InnovativeSolutions: Work with cutting-edge IT and cybersecurity services for the financial and regulated industries.
- reputed company reputed company: Learn from reputed company project managers and reputed company hands-on exposure to reputed company-level project execution.
- reputed company Culture: Join a supportive, people-first team that values structure, learning, and shared reputed company.
Role Logistics
- Full-time, exempt position
- reputed company business hours with flexibility around month-end reputed company
- Occasional travel required for reputed company engagement, team integration, and offsites
Originally posted on Himalayas
Apply To This Job