Jobs · OTHR

Vulnerability Manager- Remote

BeyondTrust · United States · 2 days ago
RemoteRemoteOTHRFull-time
We need to output HTML fragment with sections: h3 headings for sections present: About the role? Actually the posting includes "The Role", "What You’ll Do", "What You’ll Bring", "Nice To Have", "Better Together Diversity", "About Us". Also maybe "Benefits", "Pay", "Schedule" not present, so omit. We need to use

for section headings. Use
  • for any list of duties/requirements/benefits. Use

    for prose. We must preserve all substantive info, not invent. Remove boilerplate: cookie/navigation/legal/EEO etc. There's none explicit. Also remove duplicated lines. We need to include sections only when posting has real specific content. So we will have sections: About the role? The posting starts with a paragraph about BeyondTrust culture. Could be "About the role" or maybe "About Us". The instruction: use headings e.g. About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule. But we can also use other headings? It says use

    for section headings (e.g. About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule). It seems they expect those headings if applicable. But we can also use other headings if needed? Probably better to map content to those headings. We have: "BeyondTrust is a place where you can bring your purpose to life..." that's about company culture; could be "About the role"? Actually "About the role" is more about the role description. The initial paragraph is about company culture and mission; could be considered "About the role"? Might be better as a

    before any heading? But they said do NOT repeat the job title as a heading (the page already shows it) and do NOT put Job ID etc. They didn't forbid a general intro paragraph before headings. So we can start with a

    containing that intro. Then we have "The Role" paragraph describing the role. Could be under

    About the role

    maybe. Or we could treat "The Role" as heading but they want h3 for section headings like About the role, Responsibilities etc. So we can put

    About the role

    and then include that paragraph. Then "What You’ll Do" corresponds to Responsibilities. So

    Responsibilities

    with list items. Then "What You’ll Bring" corresponds to Requirements/Qualifications/Skills. Could split into Requirements (must have) and Qualifications (nice to have). But we have "What You’ll Bring" (required) and "Nice To Have". So we can do

    Requirements

    for required, and

    Qualifications

    for nice to have? Or Skills. The instruction list includes Qualifications, Skills. We'll map required to Requirements, nice to have to Qualifications. Then "Better Together Diversity" and "About Us" could be combined into a section maybe "About Us". But we have both. Could put

    About Us

    containing both paragraphs. We must not include Pay/Benefits/Schedule as they are not present. We need to use
    • for any list of duties/requirements/benefits. So for responsibilities list, each bullet as
    • . For requirements list, each bullet as
    • . For nice to have list, each as
    • . Also maybe for "What You’ll Bring" we have bullet-like sentences separated by periods; we need to convert to list items. The text is a paragraph with sentences separated by periods. We should split into list items each representing a bullet. Similarly for nice to have. We must preserve all substantive information; do not invent or summarize away detail. So we need to keep each point. Let's extract. Intro paragraph: "BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cybersecurity SaaS portfolio. Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself." Then "The Role" paragraph: "The Vulnerability Manager operates BeyondTrust's product vulnerability management program end to end. This is an operator role: you design the process, drive the automation that runs it, own the metrics, and are accountable for the answer when leadership asks what our open vulnerability risk is today. The primary focus is vulnerability management for FedRAMP 20x and standing up vulnerability management for new products as they ship. You partner closely with Security Engineering to define the integration requirements, partner with them closely through delivery, and own the operational outcome. The ideal candidate has designed a vulnerability management process inside a regulated environment, uses automation and AI to remove manual work rather than absorbing it, and can hold a remediation conversation with an engineering lead and an evidence conversation with an assessor on the same day. Fully remote, must be North America based." We could keep that as prose under About the role. Then "What You’ll Do" list: each sentence starting with a capital letter after line break? Let's extract bullet points: - Design and operate the product vulnerability management process end to end: intake, triage, risk assessment, assignment, SLA tracking, exception handling, and closure verification. - Own vulnerability management for FedRAMP 20x, including continuous monitoring cadence, machine-readable evidence, Key Security Indicator reporting, and POA&M lifecycle from creation through closure. - Stand up vulnerability management for new products and services as they ship: define scan coverage, onboard them into the process, set SLAs, and establish reporting from first release. - Assess and rank vulnerability risk using exploitability, exposure, asset criticality, and compensating controls rather than CVSS alone, and defend that ranking to engineers, executives, and assessors. - Drive remediation with product engineering teams: assign ownership, agree timelines, escalate overdue Critical and High findings, and record risk acceptances as time-bound decisions with an expiry. - Automate the process wherever manual effort scales with finding volume, using scripting, workflow tooling, and AI-assisted analysis for triage, deduplication, enrichment, summarization, and evidence collection. - Define the requirements for platform integrations built by Security Engineering, covering scanners, ticketing, asset inventory, and dashboards. Partner with that team through delivery and validate the result against the operational need. - Own the program metrics: SLA attainment, mean time to remediate, vulnerability aging, backlog trend, scan and asset coverage, and exception volume. Report them on a fixed cadence to security and engineering leadership. - Monitor the vulnerabilities that matter most. Maintain a current view of critical exposure across the product portfolio and serve as the authoritative answer to what is open, what it means, and when it closes. - Lead rapid response for actively exploited and zero-day vulnerabilities, including exposure assessment across the product fleet, mitigation tracking, and stakeholder communication. We need to keep each as
    • . Then "What You’ll Bring" required list: - 5+ years in vulnerability management, product security, or security operations, with direct ownership of a vulnerability management process rather than participation in one. - Demonstrated experience designing and operating vulnerability management process in a regulated or audited environment, and sustaining it through assessment cycles. - Working knowledge of FedRAMP and NIST SP 800-53, specifically vulnerability scanning, flaw remediation, continuous monitoring, configuration management, and POA&M management. - Hands-on operation of enterprise vulnerability and exposure management platforms, cloud security posture tooling, container scanning, and software composition analysis. - Practical automation skill: scripting in Python or equivalent, workflow and reporting tooling, and use of AI assistants to reduce manual triage and reporting effort. This role automates its own process; it does not build platform software. - Ability to write clear technical requirements and partner with security engineering through design, delivery, and acceptance. - Strong understanding of CVSS, CISA Known Exploited Vulnerabilities (KEV), EPSS, and risk-based prioritization, with the judgment to separate a high score from a real exposure. - Working knowledge of cloud services (AWS preferred), containers, Kubernetes, CI/CD, web applications, and APIs, sufficient to assess a finding and evaluate a proposed fix. - Ability to drive remediation across engineering teams without direct authority. - Clear written and verbal communication with engineers, executives, auditors, and customers. Then "Nice To Have" list: - Direct experience supporting FedRAMP Moderate or High authorization and continuous monitoring, or FedRAMP 20x. - Experience defining metrics and building reporting or dashboards for executive and audit audiences. - Experience with SaaS, identity security, or privileged access management products. - Familiarity with agentic or AI-assisted security workflows. - Cloud security certifications (AWS, Azure, GCP), GIAC, CISSP, or equivalent. Then "Better Together Diversity" paragraph: "Better Together Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected. We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together." Then "About Us" paragraph: "BeyondTrust is the global identity security leader protecting Paths to Privilege™. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders. BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners. Learn more at www.beyondtrust.com." We should combine these two under About Us heading. Now produce HTML fragment. We need to ensure we don't include any extra text outside HTML. No markdown fences. Let's craft:

      BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cybersecurity SaaS portfolio. Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself.

      About the role

      The Vulnerability Manager operates BeyondTrust's product vulnerability management program end to end. This is an operator role: you design the process, drive the automation that runs it, own the metrics, and are accountable for the answer when leadership asks what our open vulnerability risk is today. The primary focus is vulnerability management for FedRAMP 20x and standing up vulnerability management for new products as they ship. You partner closely with Security Engineering to define the integration requirements, partner with them closely through delivery, and own the operational outcome. The ideal candidate has designed a vulnerability management process inside a regulated environment, uses automation and AI to remove manual work rather than absorbing it, and can hold a remediation conversation with an engineering lead and an evidence conversation with an assessor on the same day. Fully remote, must be North America based.

      Responsibilities

      • Design and operate the product vulnerability management process end to end: intake, triage, risk assessment, assignment, SLA tracking, exception handling, and closure verification.
      • Own vulnerability management for FedRAMP 20x, including continuous monitoring cadence, machine-readable evidence, Key Security Indicator reporting, and POA&M lifecycle from creation through closure.
      • Stand up vulnerability management for new products and services as they ship: define scan coverage, onboard them into the process, set SLAs, and establish reporting from first release.

Similar jobs

Remote Manager

QureosNew York, United States· 1 mo ago
OTHR$95k–$165k/yrapply on jobs.qureos.com

Cyber Security Manager (Remote)

CareFirst BlueCross BlueShieldBaltimore, MD· 2 mo ago
Information Technology$147k–$272k/yrapply on carefirstcareers.ttcportals.com