Vulnerability Remediation Operations Lead - Virtual
alightDenver, CO
Vulnerability Remediation Operations Lead - Virtual
alightDenver, CO
yesterday
Occupations
Information Security AnalystsComputer and Information Systems ManagersNetwork and Computer Systems AdministratorsAbout the role
Vulnerability Remediation Operations LeadThe Vulnerability Remediation Operations Lead provides centralized operational leadership for vulnerability remediation across Technology. The role resides within IT Operations and operates in close partnership with Security leadership. The role is responsible for establishing a consistent management approach for assigning, planning, monitoring, escalating, and closing remediation work. Security retains responsibility for identifying vulnerabilities, evaluating risk, establishing priorities, and providing security reporting. Technology service and asset owners remain responsible for implementing technical fixes, compensating controls, and other remediation actions. The Vulnerability Remediation Operations Lead connects these functions by ensuring that identified vulnerabilities have clear ownership, actionable plans, appropriate visibility, and timely follow-through. Working across Security, Infrastructure, Cloud, Workplace and Network, Enterprise Architecture, Application Engineering, Platform Engineering, Service Management, and Technology leadership, the role coordinates a broad and often complex remediation portfolio. Success requires technical awareness, sound judgment, strong organization, and the ability to communicate effectively with both operational teams and senior leaders.
Key Responsibilities:
Leading and coordinating vulnerability remediation activities across technology teams to reduce enterprise risk and support business objectives.
Ensuring vulnerabilities are assigned appropriately, with clear ownership, remediation plans, timelines, and documented outcomes.
Maintaining visibility into vulnerability remediation efforts across infrastructure, cloud, applications, platforms, networks, and end-user technologies.
Partnering with Security and technology teams to prioritize remediation based on risk, business impact, operational needs, and compliance requirements.
Fostering collaboration across technical and business stakeholders to resolve vulnerabilities, remove blockers, and drive timely remediation.
Monitoring remediation performance, service-level commitments, and aging vulnerabilities, escalating issues and risks when appropriate.
Serving as a trusted partner and primary point of coordination between Security and Technology teams for remediation planning, governance, and continuous improvement.
Developing and present clear reporting, metrics, and insights for operational, leadership, audit, and governance audiences.
Supporting vulnerability exception processes by facilitating documentation, reviews, approvals, and ongoing tracking.
Identifying opportunities to improve remediation effectiveness through automation, process improvements, standardization, and enhanced tooling.
Requirements:
- Experience in vulnerability management, cybersecurity, technology operations, service management, risk management, or a related field.
- Understanding of vulnerability management practices, including prioritization, remediation planning, exception management, validation, and reporting.
- Experience working with cross-functional teams in complex technology environments.
- Familiarity with enterprise infrastructure, cloud platforms, networking, applications, endpoint technologies, and security practices.
- Experience using vulnerability management or security tools such as Tenable, Qualys, Rapid7, Microsoft Defender, or similar platforms.
- Familiarity with Service
- Now Vulnerability Response/Management or comparable workflow and ticket management solutions.
- Analytical skills with the ability to interpret data, identify trends, and communicate actionable insights.
- Demonstrated ability to influence outcomes, build partnerships, and drive accountability across teams in a collaborative and inclusive manner.
- Professional certifications such as CISSP, CISM, CRISC, Security+, ITIL, PMP, or equivalent credentials.
- Experience supporting cloud security, DevSecOps, compliance, audit, or enterprise governance initiatives.
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or an equivalent combination of education, training, and experience.
Matching similar jobs
JOB OVERVIEW
Experience level
Manager
Location
Denver, CO
Occupation
Information Security Analysts
Industry
Computer Systems Design Services
Posted
yesterday
Tired of running searches?
Rank the roles you'd take once, and matches like these arrive on their own.
CREATE PROFILE