Senior Security Manager - Vulnerability Management
Vulnerability Management
We are seeking a Senior Security Manager, Vulnerability Management to own and mature Alter Domus’s enterprise vulnerability management program and drive continuous reduction of our attack surface.
Vulnerability Management Program Leadership: Own and continuously mature the end-to-end enterprise Vulnerability Management (VM) program — policy, scanning cadence, risk-based prioritization, and remediation SLAs — across on-premises, cloud, and hybrid environments. Build, lead, and develop a small team of vulnerability management analysts/engineers, setting priorities and managing delivery against program KPIs. Partner with Infrastructure, Application, and DevOps teams to drive timely remediation of critical and high-risk findings; manage formal risk-acceptance and exception processes for items that cannot be remediated on schedule. Identify and reduce the organization’s attack surface, including unmanaged assets, shadow IT, and internet-facing exposures, in partnership with IT and Network teams.
Vulnerability Management Platform Deployment & Operations: Own the deployment, configuration, and ongoing administration of the enterprise vulnerability management (VM) scanning and detection–response platform across the enterprise estate. Drive scanner/agent coverage expansion, asset discovery accuracy, and integration of the VM platform with ITSM/ticketing and CMDB tools. Continuously tune scan policies, authentication, and reporting configurations to improve detection accuracy and reduce false positives. Evaluate and recommend enhancements to the VM tooling stack as the threat landscape and business needs evolve.
AI-Augmented Vulnerability Management: Leverage AI/ML-driven risk scoring and predictive exploitability signals (beyond static CVSS) to sharpen remediation prioritization and focus analyst effort on the highest-impact exposures. Evaluate and adopt AI-assisted capabilities within the VM platform — automated finding triage, deduplication, and correlation with threat intelligence — to increase remediation velocity and reduce manual analyst workload. Extend vulnerability and attack surface management practices to AI/ML assets in use across the business — models, training data pipelines, and AI-enabled applications — identifying and remediating AI-specific exposures. Partner with Security Governance on emerging AI risk frameworks (e.g., NIST AI RMF, OWASP Top 10 for LLM Applications) where they intersect with vulnerability and configuration management practices.
Governance, Metrics & Reporting: Design and maintain executive and operational reporting (KPIs/KRIs, remediation SLA performance, risk trends) for the CISO, technology leadership, and risk committees. Own and keep current the vulnerability management policies, standards, and procedures in line with the evolving threat landscape and regulatory expectations. Present program status, risk posture, and remediation progress at security governance forums and, as needed, executive-level updates.
Audit & Compliance: Serve as the primary control owner for vulnerability and configuration management controls during SOC 2 (Type I/II) and related audits (e.g., ISO 27001, client due-diligence reviews). Manage evidence collection, auditor engagement, and remediation tracking for audit findings tied to vulnerability, patch, and configuration management. Support broader information security governance activities, including risk assessments and control testing, as needed.