Jobs · Management · New York

Senior Security Manager - Vulnerability Management

Alter Domus · New York, United States · 1 mo ago
HybridManagementFull-time

Vulnerability Management

The Senior Security Manager, Vulnerability Management will own and mature Alter Domus's enterprise vulnerability management program.

  • Own and continuously mature the end-to-end enterprise Vulnerability Management (VM) program — policy, scanning cadence, risk-based prioritization, and remediation SLAs — across on-premises, cloud, and hybrid environments.
  • Build, lead, and develop a small team of vulnerability management analysts/engineers, setting priorities and managing delivery against program KPIs.
  • Partner with Infrastructure, Application, and DevOps teams to drive timely remediation of critical and high-risk findings; manage formal risk-acceptance and exception processes for items that cannot be remediated on schedule.
  • Identify and reduce the organization’s attack surface, including unmanaged assets, shadow IT, and internet-facing exposures, in partnership with IT and Network teams.

Platform Deployment & Operations

Own the deployment, configuration, and ongoing administration of the enterprise vulnerability management (VM) scanning and detection–response platform across the enterprise estate.

  • Drive scanner/agent coverage expansion, asset discovery accuracy, and integration of the VM platform with ITSM/ticketing and CMDB tools.
  • Continuously tune scan policies, authentication, and reporting configurations to improve detection accuracy and reduce false positives.
  • Evaluate and recommend enhancements to the VM tooling stack as the threat landscape and business needs evolve.

AI-Augmented Vulnerability Management

Leverage AI/ML-driven risk scoring and predictive exploitability signals (beyond static CVSS) to sharpen remediation prioritization and focus analyst effort on the highest-impact exposures.

  • Evaluate and adopt AI-assisted capabilities within the VM platform — automated finding triage, deduplication, and correlation with threat intelligence — to increase remediation velocity and reduce manual analyst workload.
  • Extend vulnerability and attack surface management practices to AI/ML assets in use across the business — models, training data pipelines, and AI-enabled applications — identifying and remediating AI-specific exposures.
  • Partner with Security Governance on emerging AI risk frameworks (e.g., NIST AI RMF, OWASP Top 10 for LLM Applications) where they intersect with vulnerability and configuration management practices.

Governance, Metrics & Reporting

Design and maintain executive and operational reporting (KPIs/KRIs, remediation SLA performance, risk trends) for the CISO, technology leadership, and risk committees.

  • Own and keep current the vulnerability management policies, standards, and procedures in line with the evolving threat landscape and regulatory expectations.
  • Present program status, risk posture, and remediation progress at security governance forums and, as needed, executive-level updates.

Audit & Compliance

Serve as the primary control owner for vulnerability and configuration management controls during SOC 2 (Type I/II) and related audits (e.g., ISO 27001, client due-diligence reviews).

  • Manage evidence collection, auditor engagement, and remediation tracking for audit findings tied to vulnerability, patch, and configuration management.
  • Support broader information security governance activities, including risk assessments and control testing, as needed.

Similar jobs

Senior Security Manager

Giga EnergyGreater Houston· 1 mo ago
Information Technologyapply on job-boards.greenhouse.io