Must be local to Minneapolis, MN
Must work on-site 5 days a week
Must be US Citizen or GC
Job Description: Security Vulnerability Program Manager
We are seeking a highly motivated and experienced Security Vulnerability Program Manager to lead the design, implementation, and management of a comprehensive vulnerability management program. In this leadership role, you will drive initiatives to identify, prioritize, and remediate vulnerabilities across diverse technology environments, collaborating with cross-functional teams to ensure timely and effective mitigation.
Key Responsibilities
- Lead the development and execution of a best-in-class vulnerability management program.
- Design and automate a robust patching process for Windows and Linux systems.
- Manage the discovery, evaluation, and implementation of scanning, patching, and testing for security vulnerabilities.
- Oversee the configuration and maintenance of vulnerability scanning tools.
- Conduct regular vulnerability assessments and penetration testing to identify and prioritize security weaknesses.
- Analyze vulnerability data to assess risks and recommend mitigation strategies.
- Collaborate with technology teams to develop and implement remediation plans.
- Create dashboards to track and report program metrics to key stakeholders.
- Stay current on emerging security threats and vulnerabilities, ensuring program adaptability.
- Review and approve mitigating controls and communicate emerging threats.
- Research and assess new security threats and vulnerabilities.
Qualifications
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- 8+ years of experience in vulnerability management and security operations.
- Expertise with patching tools such as MS SCCM and RedHat Satellite Servers.
- Experience in EDR administration (e.g., Microsoft Windows Defender, CrowdStrike Falcon, VMware Carbon Black, Palo Alto Cortex XDR, Cylance, Tanium).
- Skilled in requirements gathering, deployment, configuration, and threat hunting using EDR tools.
- Strong proficiency in operational information security disciplines (e.g., incident response, security infrastructure management, monitoring services).
- Solid understanding of the NIST CSF Framework.
- Proven leadership in managing vulnerability management programs.
- In-depth knowledge of vulnerability scanning tools and methodologies.
- Strong understanding of risk assessment and prioritization frameworks.
- Excellent communication, collaboration, and interpersonal skills.
Preferred Qualifications
- Experience working with MDR service providers.
- Familiarity with security automation and SOAR tools.
This role offers the opportunity to lead a critical security function, ensuring the protection of enterprise technology environments while driving continuous improvement in vulnerability management practices.