Vulnerability Manager

BeyondTrust
Toronto, United States, Canada
Workplace: RemoteFull timeFunction: Data Analytics & Business IntelligenceSkills: ["Written communication","Verbal communication","Cross-team collaboration","Risk prioritization","Stakeholder management"]

Own BeyondTrust’s product vulnerability management program end to end, designing intake, triage, risk assessment, SLAs, and closure verification. Drive FedRAMP 20x vulnerability management and stand up coverage for new products as they ship. Use exploitability and exposure factors (not CVSS alone) to prioritize risk, partner with Security Engineering to integrate scanners and reporting, automate triage and evidence collection, and lead rapid response for exploited and zero-day vulnerabilities.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
BeyondTrust
BeyondTrust
15 hours ago

Vulnerability Manager

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 1 hour agoStatus: Live

Job Summary

Own BeyondTrust’s product vulnerability management program end to end, designing intake, triage, risk assessment, SLAs, and closure verification. Drive FedRAMP 20x vulnerability management and stand up coverage for new products as they ship. Use exploitability and exposure factors (not CVSS alone) to prioritize risk, partner with Security Engineering to integrate scanners and reporting, automate triage and evidence collection, and lead rapid response for exploited and zero-day vulnerabilities.
Location: Toronto, United States, Canada
Workplace: Remote
Employment Type: Full time
Job Function: Data Analytics & Business Intelligence

Key Responsibilities

  • •Design and operate the product vulnerability management process end to end, including intake, triage, risk assessment, assignment, SLA tracking, exception handling, and closure verification.
  • •Own FedRAMP 20x vulnerability management, including continuous monitoring cadence, machine-readable evidence, Key Security Indicator reporting, and POA&M lifecycle.
  • •Stand up vulnerability management for new products and services as they ship by defining scan coverage, onboarding into the process, setting SLAs, and establishing reporting from first release.
  • •Assess and rank vulnerability risk using exploitability, exposure, asset criticality, and compensating controls, and defend rankings to engineers, executives, and assessors.
  • •Drive remediation with product engineering teams, automate where manual effort scales, and lead rapid response for actively exploited and zero-day vulnerabilities.

Key Requirements

  • •5+ years in vulnerability management, product security, or security operations with direct ownership of a vulnerability management process.
  • •Experience designing and operating vulnerability management in a regulated or audited environment through assessment cycles.
  • •Working knowledge of FedRAMP and NIST SP 800-53, including vulnerability scanning, remediation, continuous monitoring, configuration management, and POA&M management.
  • •Hands-on operation of enterprise vulnerability/exposure platforms and cloud security posture tools, including container scanning and software composition analysis.
  • •Practical automation skills (scripting in Python or equivalent) plus strong risk-based prioritization judgment using CVSS, KEV, and EPSS.
Experience:CybersecurityProduct securitySecurity operationsSaaS
Skills:Written communicationVerbal communicationCross-team collaborationRisk prioritizationStakeholder management
Certifications:AWSAzureGCPGIACCISSP
Languages:English
Tech Stack:PythonFedRAMPNIST SP 800-53Vulnerability scanningContinuous monitoringConfiguration managementPOA&MCVSSCISA Known Exploited Vulnerabilities (KEV)EPSSRisk-based prioritizationEnterprise vulnerability and exposure management platformsCloud security posture toolingContainer scanningSoftware composition analysisAWSContainersKubernetesCI/CDWeb applications

Company Brief

BeyondTrust
Provides privileged access management, vulnerability management, and secure remote access solutions to help organizations protect credentials, manage privileges, and secure endpoints across on-premises and cloud environments.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Growth: Established Company
Funding: Private Equity Backed
Headquarters: Phoenix, United States
WebsiteLinkedIn