Vulnerability Manager

4 weeks ago


Boston, Massachusetts, United States BCS365 Full time

The Vulnerability Manager drives vulnerability management strategies and goals through coaching, mentoring and career guidance. Develops and maintains strong partnerships with stakeholders, ensuring end-to-end vulnerability remediation both internally and externally. Directs vulnerability assessments and penetration tests, assists with strategic planning, supports compliance and risk management activities, and pushes for improvements to mitigate risk.

Essential Duties and Responsibilities

  • Ensures continuous vulnerability lifecycle management internally within the company and externally with clients, detecting, monitoring, reporting, and assessing impact on vulnerability-related data from sources.
  • Develops and drives remediation strategies to address vulnerabilities and reduce attack surface.
  • Assists with strategic planning, driving improvements and providing input on capabilities and methods for vulnerability management and security testing.
  • Supports compliance and risk management activities, recommending security controls and corrective actions to mitigate vulnerability risks.
  • Develops and maintains strong partnerships to drive end-to-end vulnerability remediation, ensure consistent customer experience, broaden awareness, and use of services, and educate users on security best practices integrated in key areas.
  • Partners with other departments to assess potential negative impacts of remediation and apply compensating/mitigating controls.
  • Provides communications across the organization, interfacing with senior leadership, driving security hardening best practices, and representing the vulnerability management team with customers and partners.
  • Drives requirements definition, evaluation, recommendation, implementation, and troubleshooting of vulnerability management tools.
  • Develops security testing capabilities and directs ongoing vulnerability assessments and penetration tests.
  • Assesses current and emerging threats, cyberattacks, and zero-day vulnerabilities that pose risks to both the company and our clients.
  • Notifies partners on threats and vulnerabilities to reduce the attack surface.
  • Leads and supports vulnerability management team, establishing team and individual goals that support overall objectives.
  • Coaches, mentors, and provides career development guidance.
  • Establishes daily operations, regular communications, and resource planning, providing guidance, relaying expectations, and leading team initiatives and activities.
  • Recruits, trains, and directly supervises all assigned subordinate staff.
  • Evaluates employee performance, counsels, and disciplines as necessary.
  • Maintains awareness and knowledge of current changes within legal, regulatory, and technological environments which may affect operations.
  • Ensures senior management and staff are informed of any changes in a timely manner.
  • Attends meetings, seminars and conferences and maintains continuity of any required or desirable certifications, if applicable.
  • Promotes an environment that fosters inclusive relationships and creates unbiased opportunities for contributions through ideas, words, and actions.
  • Recommends departmental goals and objectives (e.g., workforce planning, compensation).
  • Reassesses or redefines priorities as appropriate to achieve performance objectives
  • Performs other related duties as assigned or requested.
  • Other duties as assigned.

Competencies, Skills, and Qualifications

  • Bachelor's degree or combined experience/education as a substitute for minimum education
  • 7 years of directly related experience
  • Extensive experience in information security management and knowledge of internet security and networking protocols.
  • Two years' experience leading a vulnerability management program, with the ability to prioritize projects and deliverables.
  • Demonstrated understanding of vulnerability management and security testing practices and methodologies.
  • Thorough knowledge of cloud computing and security issues related to cloud environments.
  • Ability to evaluate business risks and recommend appropriate information security measures.
  • Proven understanding of common vulnerability frameworks (e.g., CVSS, OWASP Top 10).
  • Ability to quickly adapt as the external environment and organization evolves.
  • Understanding of system, application, and database-hardening techniques and practices.
  • Ability to interact effectively at all levels of an organization and across diverse cultural and linguistic barriers.
  • Project management experience.
  • Excellent written and oral communication skills.

Preferred Qualifications:

  • Master's degree in related field
  • 10 years of directly related experience as a Vulnerability Management Manager or similar role
  • Experienced in presenting to large groups with confidence and polished presentation skills.
  • Working toward or has CISSP, CISSP-ISSMP, CISM, and/or CRISC certifications.
  • Experience in penetration testing

BCS365 is an Equal Opportunity Employer. We consider applicants for all positions without discrimination based on race, color, religion, creed, gender, national origin, sexual orientation, age marital or veteran status, disability, or any other legally protected status.

Please Note: BCS365 participates in E-Verify and will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the U.S.



  • Boston, Massachusetts, United States Marriott Full time

    Job Number Job Category Information TechnologyLocation Marriott International HQ, 7750 Wisconsin Avenue, Bethesda, Maryland, United StatesSchedule Full-TimeLocated Remotely? YRelocation? NPosition Type ManagementJOB SUMMARYThe Marriott Enterprise Vulnerability Management group oversees attack surface reduction across a wide range of corporate, cloud, data...


  • Boston, Massachusetts, United States Motion Recruitment Full time

    We are working with a prestigious University that is looking for a Cloud Security Project Manager will be responsible for leading and managing cloud security initiatives to ensure the confidentiality, integrity, and availability of sensitive data and systems. The individual will work closely with cross-functional teams, vendors, and stakeholders to design,...


  • Boston, Massachusetts, United States Motion Recruitment Full time

    We are working with a company that is a leading investment management firm dedicated to delivering superior investment results for our clients. We specialize in quantitative investment strategies and provide investment management services to a wide range of institutional investors.We are currently seeking a highly skilled and experienced Senior Technical...


  • Boston, Massachusetts, United States Geode Capital Management Full time

    Geode is seeking a highly skilled and experienced Platform and Security Engineer to join Geode's technology team. This role requires a strong background in software development, systems operations, and security to bridge traditional gaps between information technology and security while ensuring fast, safe delivery of code. Our ideal candidate is proficient...


  • Boston, Massachusetts, United States Bank of America Full time

    Job Description:At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day.One of the keys to driving Responsible Growth is being a great place to work for our...


  • Boston, Massachusetts, United States Seismic Software Full time

    Please be aware we have noticed an increase in hiring scams potentially targeting Seismic candidates. Read our full statement on our Career's page.Seismic, a rapidly growing Forbes Cloud 100 company, is the global leader in enablement, helping make sales teams better by becoming more productive and engaging with buyers in a compelling way. Seismic's platform...


  • Boston, Massachusetts, United States Seismic Software Full time

    Please be aware we have noticed an increase in hiring scams potentially targeting Seismic candidates. Read our full statement on our Career's page.Seismic, a rapidly growing Forbes Cloud 100 company, is the global leader in enablement, helping make sales teams better by becoming more productive and engaging with buyers in a compelling way. Seismic's platform...


  • Boston, Massachusetts, United States Seismic Software Full time

    Please be aware we have noticed an increase in hiring scams potentially targeting Seismic candidates. Read our full statement on our Career's page.Seismic, a rapidly growing Forbes Cloud 100 company, is the global leader in enablement, helping make sales teams better by becoming more productive and engaging with buyers in a compelling way. Seismic's platform...


  • Boston, United States Motion Recruitment Full time

    Job Description A security team that we are collaborating with right now is actively seeking to expand in the software development industry. This company is in San Diego, CA, and is a multidisciplinary innovation firm that creates cutting-edge artificial intelligence solutions for a safe and independent future. They are looking for a full-time Information...


  • Boston, United States Motion Recruitment Partners, LLC Full time

    Job Description A security team that we are collaborating with right now is actively seeking to expand in the software development industry. This company is in San Diego, CA, and is a multidisciplinary innovation firm that creates cutting-edge artificial intelligence solutions for a safe and independent future. They are looking for a full-time Information...


  • Boston, United States Motion Recruitment Full time

    Job Description A security team that we are collaborating with right now is actively seeking to expand in the software development industry. This company is in San Diego, CA, and is a multidisciplinary innovation firm that creates cutting-edge artificial intelligence solutions for a safe and independent future. They are looking for a full-time Information...


  • Boston, United States Planet Technology Full time

    Location: Boston office 3 days per week. and 2 days a week remoteJob is 80% security and 20% networking.Requirements:Infrastructure experience based on job descriptionNetwork experience based on job description, and 1-2 years of security engineer experience.Must understand the fundamentals of what cloud such as Azure functions, and be able to give security...


  • Boston, United States Planet Technology Full time

    Location: Boston office 3 days per week. and 2 days a week remoteJob is 80% security and 20% networking.Requirements:Infrastructure experience based on job descriptionNetwork experience based on job description, and 1-2 years of security engineer experience.Must understand the fundamentals of what cloud such as Azure functions, and be able to give security...


  • Boston, United States Motion Recruitment Full time

     We are working with a prestigious University that is looking for a Cloud Security Project Manager will be responsible for leading and managing cloud security initiatives to ensure the confidentiality, integrity, and availability of sensitive data and systems. The individual will work closely with cross-functional teams, vendors, and stakeholders to design,...

  • Program Manager

    11 hours ago


    Boston, United States City of Boston Full time

    Overview: The mission of the Mayor's Office of Housing (MOH) is to make Boston the most livable city in the nation by working with communities to build strong neighborhoods through the strategic investment of public resources. MOH oversees programs that create and preserve affordable housing, support homeowners, providing housing and support services to...


  • Boston, United States Motion Recruitment Full time

    We are working with a company that is focused on providing experiences over emails to companies of all sizes ranging from entrepreneurs and iconic brands. They bring together data, technologies, and experience to provide business details through emails all over the country. They are looking for a Staff Security Engineer – Threat Response....


  • Boston, United States Orama Solutions Full time

    Orama are excited to partner with an early-stage cybersecurity vendor just receiving their Series A, raising over $20m+ in funding from a number of the most reputable VCs in the security world. The Tech: Their platform allows enterprise companies to identify vulnerabilities and mobilise their security teams to mitigate threats before they become a problem....


  • Boston, United States Ceres Group Full time

    Job Description: The Managed Services Manager is responsible to ensure our Delivery Services meets the needs of our customers in an ever changing environment as cyber threats continue to evolve. The Manager must be passionate about cyber security and the drive to continue to evolve our service offers to stay with or ahead our client's needs. As Managed...

  • Senior Sales Engineer

    3 weeks ago


    Boston, United States Orama Solutions Full time

    Orama are excited to partner with an early-stage cybersecurity vendor just receiving their Series A, raising over $20m+ in funding from a number of the most reputable VCs in the security world. The Tech: Their platform allows enterprise companies to identify vulnerabilities and mobilise their security teams to mitigate threats before they become a problem....


  • Boston, United States Orama Solutions Full time

    Orama are excited to partner with an early-stage cybersecurity vendor just receiving their Series A, raising over $20m+ in funding from a number of the most reputable VCs in the security world. The Tech: Their platform allows enterprise companies to identify vulnerabilities and mobilise their security teams to mitigate threats before they become a problem....


  • Boston, United States Orama Solutions Full time

    Orama are excited to partner with an early-stage cybersecurity vendor just receiving their Series A, raising over $20m+ in funding from a number of the most reputable VCs in the security world. The Tech: Their platform allows enterprise companies to identify vulnerabilities and mobilise their security teams to mitigate threats before they become a problem....


  • Boston, United States Motion Recruitment Partners, LLC Full time

    We are working with a prestigious University that is looking for a Cloud Security Project Manager will be responsible for leading and managing cloud security initiatives to ensure the confidentiality, integrity, and availability of sensitive data and systems. The individual will work closely with cross-functional teams, vendors, and stakeholders to design,...


  • Boston, United States Motion Recruitment Full time

    Job Description We are working with a company located in Massachusetts that is responsible for protecting the digital assets from cyber threats. They are committed to making sure that everyone is qualified, suitable and being provided with all the correct information. Staying up-to-date with the latest cyber security threats, trends, and providing...


  • Boston, United States Motion Recruitment Partners, LLC Full time

    We are working with a company that is focused on providing experiences over emails to companies of all sizes ranging from entrepreneurs and iconic brands. They bring together data, technologies, and experience to provide business details through emails all over the country. They are looking for a Staff Security Engineer - Threat Response. Responsibilities: ...


  • Boston, United States KLR Executive Search Group LLC Full time

    KLR Executive Search Group is proud to partner with a Boston-based non-profit to recruit their next Director of Real Estate and Facilities Management. Our client's mission is to end homelessness in Greater Boston by providing a supported pathway to self-sufficiency that begins with a home, together with critical services such as life skills, financial...


  • Boston, United States KLR Executive Search Group LLC Full time

    KLR Executive Search Group is proud to partner with a Boston-based non-profit to recruit their next Director of Real Estate and Facilities Management. Our client's mission is to end homelessness in Greater Boston by providing a supported pathway to self-sufficiency that begins with a home, together with critical services such as life skills, financial...


  • Boston, United States Motion Recruitment Partners, LLC Full time

    Job Description We are working with a company located in Massachusetts that is responsible for protecting the digital assets from cyber threats. They are committed to making sure that everyone is qualified, suitable and being provided with all the correct information. Staying up-to-date with the latest cyber security threats, trends, and providing...

  • IT Compliance

    7 days ago


    Boston, United States Integrated Resources Full time

    The Specialist will develop, update, and maintain IT compliance documentation based on *** IT compliance standards. The individual will conduct regular reviews and assessments to coordinate *** System (Client) Enterprise Risk Management and Security Assurance for the *** (SAFR) reporting requirements. Responsibilities - Perform IT compliance, risk...