About the role

Vulnerability Management Lead
Location: Remote-San Deigo CA
Duration: Longterm ContractKEY RESPONSIBILITIESOwn the infrastructure vulnerability lifecycle: intake of Rapid7 findings, risk-based prioritization (Critical → High → Medium → Low), remediation planning, execution oversight and closure validation. Serve as the single conduit into the customer CSO / Security organization; represent remediation status, risk acceptance and mitigation plans to security and business stakeholders. Negotiate and secure maintenance windows / downtime with business and application owners for application-impacting patches. Govern the monthly patch cadence (Dev/Test after Patch Tuesday, Production after ~2-week stabilization) and the quarterly manufacturing cadence. Lead the monthly top 20–30 vulnerability review and backlog burn-down; own the customized patching-status dashboard. Drive automation strategy includes the Zoho Patch Manager ↔ Rapid7 integrated deployment pipeline and PowerShell-based configuration remediation. Own ticket-hygiene standards in ServiceNow (deduplication against CIs, exclusion of offline/inactive assets) to reduce noise in the Infrastructure Vulnerability Response queue. Coordinate Windows, Linux, Cisco and coordination resources; set priorities, resolve blockers and own escalations. Report SLA/KPI attainment, risk posture and continuous-improvement roadmap to customer and leadership.
MUST-HAVE: SKILLS & EXPERIENCE10–15 years in infrastructure / security operations, including 3+ years leading vulnerability-management or patch-remediation teams. Deep, hands-on knowledge of the vulnerability lifecycle: scanning, prioritization (CVSS/EPSS, exploitability), remediation and validation. Strong working knowledge of Rapid7 (or equivalent — Tenable / Qualys) and enterprise patch-deployment tooling (Zoho Patch Manager, SCCM/MECM or similar).Proven ServiceNow experience — vulnerability response, CMDB/CI alignment and ticket-noise reduction. ITIL-aligned Change, Incident and Problem management across large virtual server estates. Excellent stakeholder management — able to translate technical risk into business language and secure downtime. Understanding of OS hardening (Windows Server 2008 R2–2025, Ubuntu) and CIS/NIST benchmarks. GOOD-TO-HAVE SKILLSExposure to network vulnerability remediation (Cisco IOS/NX-OS) and VDI image patching. Experience standing up automation pipelines and dashboards / Power BI reporting. Prior managed-services / client-facing delivery experience. PREFERRED CERTIFICATIONSCISSP, CISM or GIAC (GCIH/GEVA) preferred; ITIL 4 Foundation required; Rapid7 / Tenable product certification desirable.

Matching similar jobs

JOB OVERVIEW

Experience level

Manager

Location

Denver, CO

Occupation

Computer and Information Systems Managers

Industry

Computer Systems Design Services

Posted

5 days ago

Tired of running searches?

Rank the roles you'd take once, and matches like these arrive on their own.

CREATE PROFILE