Director – Vulnerability Management & Cloud Security Platform 2
Ampcus Inc · New York, NY · 4 wk ago
HybridOTHRFull-time
About the role
We are seeking a Director - Vulnerability Management & Cloud Security Platform to join a Cybersecurity Engineering Tools & Platforms team. This is a highly technical individual contributor role responsible for engineering, operating, and continuously improving enterprise vulnerability management and cloud security platforms.
Responsibilities
- Own engineering and operational responsibility for enterprise vulnerability management and cloud security posture management platforms.
- Administer and maintain enterprise security platforms, including platform health, upgrades, configuration, integrations, onboarding, access management, troubleshooting, and vendor support.
- Improve platform scalability, reliability, automation, data quality, performance, and operational resilience.
- Manage scanner infrastructure, agents, cloud connectors, platform configurations, tenant administration, and service health.
- Support vulnerability scanning across servers, endpoints, databases, network devices, appliances, cloud environments, containers, and internet-facing assets.
- Collaborate with infrastructure and networking teams on scanner deployment, routing, segmentation, firewall configuration, authenticated scanning, and connectivity troubleshooting.
- Drive enterprise asset discovery, inventory reconciliation, CMDB integration, ownership validation, and coverage reporting.
- Build automation using APIs, scripting, configuration management, dashboards, reporting workflows, and data pipeline integrations.
- Integrate security platforms with CMDBs, ticketing systems, cloud platforms, enterprise reporting, and remediation workflows.
- Enable vulnerability prioritization, remediation tracking, SLA management, exception handling, and critical vulnerability response.
- Monitor platform health, create operational dashboards, support incident response, disaster recovery, business continuity, and vendor escalations.
- Manage SSO, RBAC, privileged access, API tokens, service accounts, audit evidence, and regulatory compliance requirements.
- Troubleshoot issues involving scanners, agents, APIs, cloud connectors, identity systems, networking, firewalls, routing, and reporting platforms.
- Develop automation using Python, Go, Java, or similar programming languages.
- Mentor engineers and improve operational documentation, runbooks, and engineering standards.
Requirements
- Bachelor's degree in Computer Science or a related discipline (or equivalent experience); advanced degree preferred.
- 10-12 years of information security or related technology experience.
- Experience supporting enterprise cybersecurity platforms within large organizations; financial services experience is preferred.
- Strong experience operating vulnerability management, asset discovery, scanning, cloud security posture management, or cloud-native security platforms.
- Hands-on experience supporting production environments, incident management, change management, platform monitoring, and lifecycle management.
- Strong engineering background with automation, APIs, configuration management, and operational optimization.
- Deep understanding of vulnerability management processes, remediation tracking, SLA governance, ownership validation, and exception management.
- Strong networking knowledge including TCP/IP, DNS, routing, firewalls, proxies, NAT, segmentation, packet flow analysis, and troubleshooting.
- Experience scanning enterprise infrastructure including servers, endpoints, databases, network devices, appliances, containers, cloud assets, and internet-facing systems.
- Knowledge of scanner architecture, authenticated scanning, credential management, agent health, and scan troubleshooting.
- Experience with AWS, Azure, and GCP cloud environments including IAM, APIs, cloud connectors, and cloud security controls.
- Experience integrating security platforms with CMDBs, ticketing systems, reporting platforms, enterprise dashboards, and cloud services.
- Strong understanding of identity and access management including SSO, MFA, RBAC, privileged access, service accounts, and API security.
- Programming experience with Python, Go, Java, or similar languages.
- Experience troubleshooting distributed enterprise security platforms across networking, cloud, identity, APIs, and data pipelines.
- Experience supporting audits, compliance reporting, production controls, and regulatory requirements.
- Experience with Kubernetes, container security, image scanning, runtime visibility, registry integrations, and cloud-native asset inventory.
Qualifications
- Bachelor's degree in Computer Science or a related discipline (or equivalent experience); advanced degree preferred.
- 10-12 years of information security or related technology experience.
- Experience supporting enterprise cybersecurity platforms within large organizations; financial services experience is preferred.
- Strong experience operating vulnerability management, asset discovery, scanning, cloud security posture management, or cloud-native security platforms.
- Hands-on experience supporting production environments, incident management, change management, platform monitoring, and lifecycle management.
- Strong engineering background with automation, APIs, configuration management, and operational optimization.
- Deep understanding of vulnerability management processes, remediation tracking, SLA governance, ownership validation, and exception management.
- Strong networking knowledge including TCP/IP, DNS, routing, firewalls, proxies, NAT, segmentation, packet flow analysis, and troubleshooting.
- Experience scanning enterprise infrastructure including servers, endpoints, databases, network devices, appliances, containers, cloud assets, and internet-facing systems.
- Knowledge of scanner architecture, authenticated scanning, credential management, agent health, and scan troubleshooting.
- Experience with AWS, Azure, and GCP cloud environments including IAM, APIs, cloud connectors, and cloud security controls.
- Experience integrating security platforms with CMDBs, ticketing systems, reporting platforms, enterprise dashboards, and cloud services.
- Strong understanding of identity and access management including SSO, MFA, RBAC, privileged access, service accounts, and API security.
- Programming experience with Python, Go, Java, or similar languages.
- Experience troubleshooting distributed enterprise security platforms across networking, cloud, identity, APIs, and data pipelines.
- Experience supporting audits, compliance reporting, production controls, and regulatory requirements.
- Experience with Kubernetes, container security, image scanning, runtime visibility, registry integrations, and cloud-native asset inventory.