Senior Security Manager - Vulnerability Management
Vulnerability Management
The Senior Security Manager, Vulnerability Management will own and mature Alter Domus's enterprise vulnerability management program.
- Own and continuously mature the end-to-end enterprise Vulnerability Management (VM) program — policy, scanning cadence, risk-based prioritization, and remediation SLAs — across on-premises, cloud, and hybrid environments.
- Build, lead, and develop a small team of vulnerability management analysts/engineers, setting priorities and managing delivery against program KPIs.
- Partner with Infrastructure, Application, and DevOps teams to drive timely remediation of critical and high-risk findings; manage formal risk-acceptance and exception processes for items that cannot be remediated on schedule.
- Identify and reduce the organization’s attack surface, including unmanaged assets, shadow IT, and internet-facing exposures, in partnership with IT and Network teams.
Platform Deployment & Operations
Own the deployment, configuration, and ongoing administration of the enterprise vulnerability management (VM) scanning and detection–response platform across the enterprise estate.
- Drive scanner/agent coverage expansion, asset discovery accuracy, and integration of the VM platform with ITSM/ticketing and CMDB tools.
- Continuously tune scan policies, authentication, and reporting configurations to improve detection accuracy and reduce false positives.
- Evaluate and recommend enhancements to the VM tooling stack as the threat landscape and business needs evolve.
AI-Augmented Vulnerability Management
Leverage AI/ML-driven risk scoring and predictive exploitability signals (beyond static CVSS) to sharpen remediation prioritization and focus analyst effort on the highest-impact exposures.
- Evaluate and adopt AI-assisted capabilities within the VM platform — automated finding triage, deduplication, and correlation with threat intelligence — to increase remediation velocity and reduce manual analyst workload.
- Extend vulnerability and attack surface management practices to AI/ML assets in use across the business — models, training data pipelines, and AI-enabled applications — identifying and remediating AI-specific exposures.
- Partner with Security Governance on emerging AI risk frameworks (e.g., NIST AI RMF, OWASP Top 10 for LLM Applications) where they intersect with vulnerability and configuration management practices.
Governance, Metrics & Reporting
Design and maintain executive and operational reporting (KPIs/KRIs, remediation SLA performance, risk trends) for the CISO, technology leadership, and risk committees.
- Own and keep current the vulnerability management policies, standards, and procedures in line with the evolving threat landscape and regulatory expectations.
- Present program status, risk posture, and remediation progress at security governance forums and, as needed, executive-level updates.
Audit & Compliance
Serve as the primary control owner for vulnerability and configuration management controls during SOC 2 (Type I/II) and related audits (e.g., ISO 27001, client due-diligence reviews).
- Manage evidence collection, auditor engagement, and remediation tracking for audit findings tied to vulnerability, patch, and configuration management.
- Support broader information security governance activities, including risk assessments and control testing, as needed.