Back to Jobs
Beyondtrust
Cybersecurity 1d ago

Vulnerability Manager

Beyondtrust
United StatesUnited States
CanadaCanada
Full-time
Not Disclosed
Senior-Level

Job Description

Key Skills Required

Master these to land this role

Python2h 41mFree Trial ✨
Start 10-Day Free Trial
Automation EngineerNIST SP 800-53AI & Machine LearningFedRAMP

Want to know if you're a match for this job?

Calculate My Match Score

The Vulnerability Manager operates BeyondTrust’s product vulnerability management program end-to-end. This is an operator role where you design the process, drive automation, own the metrics, and are accountable for vulnerability risk assessment.

What You’ll Do

  • Design and operate the product vulnerability management process end-to-end: intake, triage, risk assessment, assignment, SLA tracking, exception handling, and closure verification.
  • Own vulnerability management for FedRAMP 20x, including continuous monitoring cadence, machine-readable evidence, Key Security Indicator reporting, and POA&M lifecycle from creation through closure.
  • Stand up vulnerability management for new products and services as they ship: define scan coverage, onboard them into the process, set SLAs, and establish reporting from first release.
  • Assess and rank vulnerability risk using exploitability, exposure, asset criticality, and compensating controls rather than CVSS alone, and defend that ranking to engineers, executives, and assessors.
  • Drive remediation with product engineering teams: assign ownership, agree timelines, escalate overdue Critical and High findings, and record risk acceptances as time-bound decisions with an expiry.
  • Automate the process wherever manual effort scales with finding volume, using scripting, workflow tooling, and AI-assisted analysis for triage, deduplication, enrichment, summarization, and evidence collection.
  • Define the requirements for platform integrations built by Security Engineering, covering scanners, ticketing, asset inventory, and dashboards. Partner with that team through delivery and validate the result against the operational need.
  • Own the program metrics: SLA attainment, mean time to remediate, vulnerability aging, backlog trend, scan and asset coverage, and exception volume. Report them on a fixed cadence to security and engineering leadership.
  • Monitor the vulnerabilities that matter most. Maintain a current view of critical exposure across the product portfolio and serve as the authoritative answer to what is open, what it means, and when it closes.
  • Lead rapid response for actively exploited and zero-day vulnerabilities, including exposure assessment across the product fleet, mitigation tracking, and stakeholder communication.

What You’ll Bring

  • 5+ years in vulnerability management, product security, or security operations, with direct ownership of a vulnerability management process rather than participation in one.
  • Demonstrated experience designing and operating vulnerability management process in a regulated or audited environment, and sustaining it through assessment cycles.
  • Working knowledge of FedRAMP and NIST SP 800-53, specifically vulnerability scanning, flaw remediation, continuous monitoring, configuration management, and POA&M management.
  • Hands-on operation of enterprise vulnerability and exposure management platforms, cloud security posture tooling, container scanning, and software composition analysis.
  • Practical automation skill: scripting in Python or equivalent, workflow and reporting tooling, and use of AI assistants to reduce manual triage and reporting effort.
  • Ability to write clear technical requirements and partner with security engineering through design, delivery, and acceptance.
  • Strong understanding of CVSS, CISA Known Exploited Vulnerabilities (KEV), EPSS, and risk-based prioritization, with the judgment to separate a high score from a real exposure.
  • Working knowledge of cloud services (AWS preferred), containers, Kubernetes, CI/CD, web applications, and APIs, sufficient to assess a finding and evaluate a proposed fix.
  • Ability to drive remediation across engineering teams without direct authority.
  • Clear written and verbal communication with engineers, executives, auditors, and customers.

Nice To Have

  • Direct experience supporting FedRAMP Moderate or High authorization and continuous monitoring, or FedRAMP 20x.
  • Experience defining metrics and building reporting or dashboards for executive and audit audiences.
  • Experience with SaaS, identity security, or privileged access management products.
  • Familiarity with agentic or AI-assisted security workflows.
  • Cloud security certifications (AWS, Azure, GCP), GIAC, CISSP, or equivalent.

How would you rate this job post?

See what other professionals think about this role.

banner

BeyondTrust is a global leader in the cybersecurity industry, specializing in privileged access management solutions. With a strong focus on safeguarding sensitive data and preventing cyber threats, the company provides a range of innovative products and services designed to help organizations protect themselves from potential security breaches. BeyondTrust's comprehensive platform enables businesses to manage and control privileged accounts, monitor and analyze user activity, and respond quickly to potential security incidents. By leveraging advanced technologies such as Artificial Intelligence and Machine Learning, BeyondTrust empowers organizations to stay one step ahead of cyber threats and maintain the trust of their customers, partners, and stakeholders. With a commitment to delivering exceptional customer experiences and a passion for cybersecurity excellence, BeyondTrust has established itself as a trusted partner for companies across various industries, including finance, healthcare, government, and technology.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More
Vulnerability Manager at Beyondtrust | HireSkys