Vulnerability Management and Cyber Controls Lead

4 weeks ago


New York, United States Apollo Inc Full time

Position Overview At Apollo, we're a global team of alternative investment managers passionate about delivering uncommon value to our investors and shareholders. With over 30 years of proven expertise across Private Equity, Credit, and Real Estate, we're known for our integrated businesses, strong investment performance, and value-oriented philosophy - all powered by our people. Role Overview Apollo is seeking a Vulnerability Management and Cyber Controls Lead to join our dynamic and growing Cybersecurity organization. This individual will own and evolve the firm's global Vulnerability Management (VM) program - driving continuous improvement toward a best-in-class capability. This is a technical and hands-on role, responsible for end-to-end processes spanning external exposure management, imminent threat response, vulnerability identification and prioritization, and facilitation of remediation across infrastructure, applications, and cloud environments. The ideal candidate combines deep technical expertise with strategic vision - able to design, operate, and improve scalable, data-driven solutions that strengthen Apollo's overall security posture. Primary Responsibilities Own and mature the global Vulnerability Management program, covering external exposure, imminent threats, vulnerability identification and prioritization, and remediation facilitation. Serve as the technical subject matter expert for vulnerability management tools and processes (e.g., Tenable, Qualys, Rapid7, or equivalent). Continuously assess and improve VM processes to achieve best-in-class coverage, efficiency, and visibility. Leverage automation, analytics, and threat intelligence to enhance accuracy and reduce remediation timelines. Operate and optimize scanning platforms, discovery tooling, and reporting pipelines to ensure comprehensive asset visibility. Partner with Infrastructure, Engineering, Application, and Cloud teams to drive effective risk reduction across environments. Lead critical vulnerability identification and response exercises, including analysis of zero-day or imminent threats. Develop and maintain metrics, dashboards, and executive-level reporting on vulnerability posture, remediation progress, and program maturity. Collaborate with Enterprise Risk, Internal Audit, and Application Security teams to ensure alignment with firm-wide risk management practices. Maintain ownership of service delivery quality, issue resolution, and stakeholder communication. Stay current with industry trends, threat intelligence, and evolving tools to proactively strengthen Apollo's defenses. Qualifications & Experience 7+ years of experience in Cybersecurity, Infrastructure Security, or Vulnerability Management. Technical proficiency across network, system, and application layers - including scanning methodologies, asset discovery, and exploit analysis. Hands-on experience operating and tuning vulnerability management tools (e.g., Tenable.io, Qualys VMDR, Rapid7 InsightVM) and discovery utilities (e.g., Nmap, SSLScan, Shodan, or custom scripts). Experience leveraging threat intelligence and CVSS/CISA/EPSS data for vulnerability prioritization. Strong understanding of cloud infrastructure (AWS, Azure, GCP) and modern application stacks. Proficiency in scripting or automation (e.g., Python, PowerShell, Bash) and query-based data analysis (SQL, Excel, or equivalent). Demonstrated success in building and optimizing technical processes at scale; experience designing metrics, dashboards, and analytics (Tableau, PowerBI, or similar). Ability to partner across technical and business teams, influence remediation activities, and communicate risk in clear, actionable terms. Knowledge of IT processes, secure configuration baselines, and control frameworks (CIS, NIST, ISO, FFIEC). Experience in financial services or other highly regulated environments preferred. Consulting or architecture background a plus. Pay Range $140,000 - $205,000 Apollo Global Management, Inc. (together with its subsidiaries and affiliates) is committed to championing opportunity. The firm and its affiliates comply with applicable discrimination and equal opportunities legislation in all of its jurisdictions and do not discriminate in employment or recruitment based on race, color, religion, gender, national origin, veteran status, disability, age, citizenship, marital or domestic/civil partnership status, sexual orientation, gender identity or expression or any other protected characteristic under applicable law. The contents of the qualifications and experience section of this job description are a guideline only. If an applicant can otherwise demonstrate their suitability for the role they will be considered. The base salary range for this position is listed above. This position is also eligible for a discretionary annual bonus based on personal, team, and Firm performance. Compensation ranges are based on several factors including job function, level, and geographic location. Final offer amounts are determined by multiple factors including candidate experience and expertise, and may vary from the amounts listed here.



  • New York, United States Apollo Global Management, Inc. Full time

    Position OverviewAt Apollo, we’re a global team of alternative investment managers passionate about delivering uncommon value to our investors and shareholders. With over 30 years of proven expertise across Private Equity, Credit, and Real Estate, we’re known for our integrated businesses, strong investment performance, and value-oriented philosophy —...

  • Cyber Compliance

    3 weeks ago


    New Brunswick, United States Ernst and Young Full time

    Location: Anywhere in Country At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. Cyber Compliance (Vulnerability Management Lead) – Assistant Director Ethics, Compliance,...


  • New York, United States Apple Inc. Full time

    A leading technology firm is seeking a Cyber Risk Analyst, AVP in New York, NY. You will play a key role in vulnerability management using the Qualys platform and support security operations through collaboration with IT and business units. The ideal candidate has at least 4 years of experience in vulnerability management and is well-versed in SIEM...

  • Cyber Compliance

    3 weeks ago


    New Orleans, United States Louisiana Staffing Full time

    Cyber Compliance (Vulnerability Management Lead) Assistant Director At EY, we're all in to shape your future with confidence. We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. Ethics, Compliance, and Risk Management (ECRM) supports our...


  • New York, United States Open Systems Technologies Full time

    A financial firm is looking for a Vulnerability Management Specialist in Iselin, NJ or NYC. Compensation: $105-110kResponsibilities: As part of the IT Security team, develop and implement firm IT Strategy in consultation with the IT teams, ensuring that all initiatives are mirrored in respective strategies including the overall firm Strategy Research new...


  • New York, United States Marathon Asset Management LP Full time

    Overview Marathon is a leading global asset manager specializing in public and private credit with approximately $23 billion in assets under management. Marathon is recognized as a distinguished leader with 26.2 years of exceptional performance and partnership. Marathons integrated global credit platform is driven by our specialized highly experienced and...


  • New York, New York, United States Jobs via Dice Full time

    Software Guidance & Assistance, Inc., (SGA), is searching for aVulnerability Management Analystfor aCONTRACT assignmentwith one of our premierFinancial Services clientsin lower Manhattan, NYC. He or she will need to be onsite for 3 days/week (most likely 5 days/week for 1 st few weeks) and be able to work alternating shifts on occasion - 7:00 am-3:30 pm or...


  • New York, United States Kaav Inc. Full time

    HiHope you are doing Great.Role: Cyber Security EngineerLocation: New yorkDescription: Under the general guidance of the IT/Security Architect or Systems Manager, the candidate will be responsible for evaluating and implementing new technologies, analyzing cybersecurity related components and controls associated to the product, process and solution, and...


  • New York, United States Kaav Inc. Full time

    Under the general guidance of the IT/Security Architect or Systems Manager, the candidate will be responsible for evaluating and implementing new technologies, analyzing cybersecurity related components and controls associated to the product, process and solution, and identify and resolve potential issues to help enhance and secure a large enterprise...

  • Sales Engineer

    3 days ago


    New York, United States XM Cyber Full time

    Sales EngineerXM Cyber is a continuous threat and exposure management solution that drives the most efficient remediation options for clients by understanding, continuously, all the ways that critical assets can be attacked. The technology turns the existing silo based cyber security model on its head and removes the big disconnect that exists within end...