About the role

Vulnerability Management LeadWe are seeking an experienced Vulnerability Management Lead to own the end-to-end infrastructure vulnerability lifecycle, including vulnerability assessment, risk-based prioritization, remediation, patch governance, and closure validation. The role will work closely with Security, Infrastructure, Application, and Business teams to drive remediation and reduce enterprise risk.
Key Responsibilities: Own the Rapid7 vulnerability lifecycle from intake and prioritization through remediation and validation. Prioritize vulnerabilities using CVSS, EPSS, exploitability, asset criticality, and business impact. Partner with Security/CSO and business stakeholders on risk acceptance, mitigation plans, and remediation status. Lead monthly and quarterly patching cadences, vulnerability reviews, and backlog burn-down. Coordinate Windows, Linux, Cisco, and infrastructure teams to resolve vulnerabilities and blockers. Drive automation using Zoho Patch Manager, Rapid7, PowerShell, and related tools. Maintain ServiceNow Vulnerability Response, CMDB/CI alignment, ticket hygiene, and remediation workflows. Own vulnerability dashboards, SLA/KPI reporting, risk posture, and executive reporting. Ensure remediation follows ITIL Change/Incident/Problem Management processes.
Must-Have:
  • Skills10–15 years of infrastructure/security operations experience with 3+ years leading vulnerability management or patch-remediation teams.
  • Strong hands-on experience with Rapid7; Tenable/Qualys experience is also acceptable.
  • Strong knowledge of CVSS, EPSS, vulnerability prioritization, remediation, and validation.
  • Experience with Zoho Patch Manager, SCCM/MECM, or similar enterprise patching tools.
  • Strong ServiceNow Vulnerability Response and CMDB/CI experience.
  • Experience with Windows Server, Linux/Ubuntu, and enterprise OS hardening.
  • Knowledge of CIS Benchmarks, NIST, and ITIL processes.
  • Excellent stakeholder management, communication, and leadership skills.
  • Good to HaveCisco IOS/NX-OS vulnerability remediationVDI patching
  • PowerShell/security automation
  • Power BI dashboards and reporting
  • Managed services/client-facing experience
Certifications: ITIL 4 Foundation – Required CISSP, CISM, GIAC (GCIH/GEVA), Rapid7/Tenable certification – Preferred

Matching similar jobs

JOB OVERVIEW

Experience level

Manager

Location

Denver, CO

Occupation

Information Security Analysts

Industry

Computer Systems Design Services

Posted

2 days ago

Tired of running searches?

Rank the roles you'd take once, and matches like these arrive on their own.

CREATE PROFILE