Vulnerability Manager
An organization is looking for an experienced vulnerability management professional to help strengthen and mature the enterprise vulnerability program across infrastructure, cloud, workplace, and application environments. In this role, you will take ownership of risk-based remediation, governance reporting, and stakeholder coordination, ensuring vulnerabilities are prioritized and resolved in line with agreed service levels and regulatory expectations.
What you will do.
- Act as the main point of contact for vulnerability management within the security function.
- Own and continuously improve the end-to-end vulnerability management process, from scan ingestion through verified remediation and closure.
- Lead remediation efforts across IT, business, application, cloud, infrastructure, and security stakeholders.
- Monitor remediation performance, track aging and trends, and ensure vulnerabilities are handled according to risk and priority.
- Manage exception handling, including compensating controls, formal approvals, and time-boxed risk acceptance.
- Prepare and present monthly governance reporting for senior stakeholders.
- Support audit readiness by maintaining evidence packs and compliance documentation.
- Promote vulnerability management best practices across the organization.
What they ask
- Strong understanding of the vulnerability management lifecycle, including scanning, prioritization, remediation, verification, and closure.
- Experience with CVSS scoring, exploitability analysis, threat intelligence, and business-criticality-based prioritization.
- Knowledge of enterprise infrastructure, cloud, networking, servers, laptops, applications, and containers.
- Hands-on experience with Qualys, AWS Inspector, and Microsoft Defender Vulnerability Management.
- Experience in multi-cloud environments, specifically AWS and Azure.
- Familiarity with container security.
- Experience integrating vulnerability management processes with ITSM tooling such as Jira or ServiceNow.
- Awareness of NIS2 and related audit/compliance requirements.
Profile
- At least 5 years of experience in vulnerability management or patch management with direct ownership.
- Proven ability to work in complex, large-scale environments with legacy or technical debt exposure.
- Strong analytical mindset and the ability to turn data into clear reporting and actionable insights.
- Confident in collaborating with technical teams and business stakeholders to drive remediation commitments.
- Comfortable managing competing priorities and resolving capacity-versus-risk conflicts.
How to apply
View the full assignment text and application details once your tailored application is ready.
Order a tailored application to view the full assignment and application details.
More context, less searching.
You get enough context to judge whether this job is relevant. The full brief, client details and next steps stay available inside the app.