2

Director Remote Vulnerability Management Jobs (NOW HIRING)

Potential opening for remote candidates in PST. This position supports advancing the enterprise ... Direct implementation experience with at least one enterprise VM platform (Tenable, Qualys, Rapid7 ...

Vulnerability Management Team Lead

Charleston, WV · Remote

$94K - $124K/yr

This role is fully remote and can be based anywhere in the United States. What You'll Do (Core ... direct authority. * An Analytical & Investigative Mindset: You possess an innate curiosity and a ...

Sr Vulnerability Management Engineer

$107K - $146K/yr

The Impact You'll Make in this Role The Senior Vulnerability Management Engineer is a senior ... Remote - US Only Travel: No travel required Relocation Assistance: Not authorized Must be legally ...

next page

Showing results 1-20

Director Remote Vulnerability Management information

What does a director of remote vulnerability management do?

A Director of Remote Vulnerability Management leads teams and strategies to identify, assess, and mitigate security vulnerabilities across an organization’s remote infrastructure. This role involves overseeing vulnerability assessments, ensuring compliance with security standards, and coordinating responses to threats that target remote systems and users. The director also collaborates with other IT and security leaders to integrate vulnerability management into broader cybersecurity initiatives, while keeping up with evolving threats and technologies.

What are the key skills and qualifications needed to thrive as a director of remote vulnerability management?

To thrive as a Director of Remote Vulnerability Management, you need deep expertise in cybersecurity frameworks, risk assessment, and vulnerability management, typically supported by a bachelor’s or master’s degree in information security or a related field. Familiarity with tools such as Qualys, Nessus, Tenable, and certifications like CISSP or CISM are common requirements. Leadership, strategic thinking, and strong communication skills are crucial for managing distributed teams and collaborating across departments. These skills ensure the effective identification, prioritization, and mitigation of security risks in dynamic and remote IT environments.

What are the main challenges faced by a director of remote vulnerability management, and how can they be addressed?

One of the primary challenges in this role is effectively coordinating vulnerability assessments and remediation efforts across distributed teams and diverse technology environments. Ensuring consistent communication, prioritizing vulnerabilities based on risk, and maintaining up-to-date inventories can be complex when managing remote teams and assets. Leveraging automated tools, establishing clear processes, and fostering strong cross-functional relationships with IT, security, and business units are key strategies for overcoming these challenges. Regularly scheduled meetings and transparent reporting also help align remote teams and ensure timely issue resolution.

What is the difference between Director Remote Vulnerability Management vs Vulnerability Analyst?

AspectDirector Remote Vulnerability ManagementVulnerability Analyst
CertificationsCertified Ethical Hacker (CEH), CISSP, CISACompTIA Security+, CEH, GIAC Security Essentials (GSEC)
Work EnvironmentStrategic leadership, cross-department collaboration, overseeing teamsHands-on analysis, vulnerability scanning, report generation
Employer & Industry UsageLarge enterprises, cybersecurity firms, IT departmentsSecurity teams, IT departments, consulting firms
Search & Comparison IntentUnderstanding leadership roles in vulnerability managementTechnical analysis and operational tasks

The main difference is that the Director Remote Vulnerability Management focuses on strategic oversight, team leadership, and policy development, while the Vulnerability Analyst handles technical vulnerability assessments and analysis. Both roles require cybersecurity certifications, but the director's role is more managerial and strategic, whereas the analyst's role is more technical and operational.

More about Director Remote Vulnerability Management jobs

What cities are hiring for Director Remote Vulnerability Management jobs?

Cities with the most Director Remote Vulnerability Management job openings:

What are the most commonly searched types of Remote Vulnerability Management jobs?

The most popular types of Remote Vulnerability Management jobs are:

What states have the most Director Remote Vulnerability Management jobs?

States with the most job openings for Director Remote Vulnerability Management jobs include:

What other helpful pages are available for Director Remote Vulnerability Management?

Other pages related to Director Remote Vulnerability Management:

Infographic showing various Director Remote Vulnerability Management job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 84% Full Time, 13% Part Time, and 2% Contract. Highlights an 86% Physical, 2% Hybrid, and 12% Remote job distribution.

Vulnerability Management Engineer

Seattle, WA • On-site, Remote

widenet
Marketing • 1 - 10 employees

$140 - $155/hr

Contractor

Medical, Retirement

Posted 20 days ago


Job description

Job Description:
Location: This position requires the candidate to work onsite 2-3 days a week in Seattle, WA. Potential opening for remote candidates in PST.
Job Description:
This position supports advancing the enterprise vulnerability management program across four functional pillars: Detect, Prioritize, Report, Remediate.
Detect:
- Maintain and expand scan and sensor coverage across endpoints, servers, cloud workloads, containers, network devices, and SaaS
- Close asset visibility gaps, including shadow IT, unmanaged devices, and assets provisioned outside IT
- Tune authenticated scanning, credential health, agent health, and scan cadence to reduce false negatives
- Reconcile vulnerability data across multiple sources into a single authoritative inventory
Prioritize:
- Build and operate risk-based prioritization that blends CVSS severity, EPSS likelihood, CISA KEV exploitation status, and SSVC decision logic
- Enrich findings with business context: asset criticality, data classification, internet exposure, compensating controls, application owner, and business unit
- Replace severity-only queues with defensible, tiered remediation SLAs
- Operate the exception and risk acceptance workflow, including expiration and re-review
Report:
- Design and publish program metrics: coverage, mean time to remediate by tier, backlog aging, SLA compliance, and burndown
- Deliver executive and operational dashboards, including Power BI reporting fed by automated pipelines
- Produce audit and assurance evidence on request
- Translate technical findings into business risk language for non-technical stakeholders
Remediate:
- Drive remediation campaigns in partnership with IT operations, endpoint, cloud, and application teams
- Automate ticket creation, routing, and closure into the ITSM platform
- Perform closed-loop verification that remediation actually reduced exposure
- Support emergency response for actively exploited vulnerabilities
Platform and program:
- Direct, hands-on experience implementing or migrating to a new enterprise vulnerability management platform, including requirements definition, proof of concept, integration, data migration, and rollout
- Direct experience driving continuous improvement to an established VM program, including maturity assessment, process redesign, and runbook development
Required Qualifications
- 5+ years hands-on vulnerability management or security engineering
- Direct implementation experience with at least one enterprise VM platform (Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or Tanium)
- Demonstrated experience building prioritization models that incorporate business context, not severity alone
- Scripting and automation to scale program operations: Python and PowerShell, plus REST API integration
- Working fluency with KQL or an equivalent query language for security data
- Experience integrating VM data with CMDB, ITSM, and BI platforms
- Cloud vulnerability management experience across Azure and at least one other provider
- Ability to work independently and produce written deliverables without heavy oversight
Preferred
- Experience with Tanium and Microsoft Defender for Endpoint as data sources
- Container and image scanning experience
- Familiarity with NVD, EPSS, KEV, and ExploitDB data feeds and their API consumption patterns
- Exposure to CTEM or exposure management program models
- Certifications: CISSP, GIAC (GEVA, GCIA), AZ-500
Pay Range: $75.00 - $85.00 per hour, depending upon experience.
Health & Medical Benefits, 401K, Employee Assistance Program, and Sick Time applicable by state.
SLA
Describe hiring preference (C/CTH/FTE)
12 month contract
Bill rate or FTE Salary range and target:
Target rate: We need to make our best offer, so let's discuss rates, keeping in mind they can go a bit higher than for our other clients.
Potential target: $140 to $155/hr
Work Authorization Requirements:
No C2C without approval
1099 ok
Budget Confirmed?
Yes
Why is the position open?
New role
How long has the position been open?
Just opened
Is there HR/vendor competition? Exclusive?
Competition - this is an RFP process
Interview Process:
  • 2 interviews - likely team fit/leadership + technical
Work location :
  • Local and onsite 2-3 days a week is ideal and will be prioritized over remote
  • Open to remote but must be in PST. This is not preferred.
Team size
Enterprise wide
Project overview:
Advance the enterprise vulnerability management program across four functional pillars: Detect, Prioritize, Report, Remediate.
Top 5:
  • 5+ years hands-on vulnerability management or security engineering
  • Direct implementation experience with at least one enterprise VM platform (Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or Tanium)
  • Demonstrated experience building prioritization models that incorporate business context, not severity alone
  • Scripting and automation to scale program operations: Python and PowerShell, plus REST API integration
  • Working fluency with KQL or an equivalent query language for security data
  • Experience integrating VM data with CMDB, ITSM, and BI platforms
  • Cloud vulnerability management experience across Azure and at least one other provider

  • Nice to Have:
    • Experience with Tanium and Microsoft Defender for Endpoint as data sources
    • Container and image scanning experience
    • Familiarity with NVD, EPSS, KEV, and ExploitDB data feeds and their API consumption patterns
    • Exposure to CTEM or exposure management program models
    • Certifications: CISSP, GIAC (GEVA, GCIA), AZ-500
    Job Description:
    Location: This position requires the candidate to work onsite 2-3 days a week in Seattle, WA. Potential opening for remote candidates in PST.
    Job Description:
    This position supports advancing the enterprise vulnerability management program across four functional pillars: Detect, Prioritize, Report, Remediate.
    Detect:
    - Maintain and expand scan and sensor coverage across endpoints, servers, cloud workloads, containers, network devices, and SaaS
    - Close asset visibility gaps, including shadow IT, unmanaged devices, and assets provisioned outside IT
    - Tune authenticated scanning, credential health, agent health, and scan cadence to reduce false negatives
    - Reconcile vulnerability data across multiple sources into a single authoritative inventory
    Prioritize:
    - Build and operate risk-based prioritization that blends CVSS severity, EPSS likelihood, CISA KEV exploitation status, and SSVC decision logic
    - Enrich findings with business context: asset criticality, data classification, internet exposure, compensating controls, application owner, and business unit
    - Replace severity-only queues with defensible, tiered remediation SLAs
    - Operate the exception and risk acceptance workflow, including expiration and re-review
    Report:
    - Design and publish program metrics: coverage, mean time to remediate by tier, backlog aging, SLA compliance, and burndown
    - Deliver executive and operational dashboards, including Power BI reporting fed by automated pipelines
    - Produce audit and assurance evidence on request
    - Translate technical findings into business risk language for non-technical stakeholders
    Remediate:
    - Drive remediation campaigns in partnership with IT operations, endpoint, cloud, and application teams
    - Automate ticket creation, routing, and closure into the ITSM platform
    - Perform closed-loop verification that remediation actually reduced exposure
    - Support emergency response for actively exploited vulnerabilities
    Platform and program:
    - Direct, hands-on experience implementing or migrating to a new enterprise vulnerability management platform, including requirements definition, proof of concept, integration, data migration, and rollout
    - Direct experience driving continuous improvement to an established VM program, including maturity assessment, process redesign, and runbook development
    Required Qualifications
    - 5+ years hands-on vulnerability management or security engineering
    - Direct implementation experience with at least one enterprise VM platform (Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, or Tanium)
    - Demonstrated experience building prioritization models that incorporate business context, not severity alone
    - Scripting and automation to scale program operations: Python and PowerShell, plus REST API integration
    - Working fluency with KQL or an equivalent query language for security data
    - Experience integrating VM data with CMDB, ITSM, and BI platforms
    - Cloud vulnerability management experience across Azure and at least one other provider
    - Ability to work independently and produce written deliverables without heavy oversight
    Preferred
    - Experience with Tanium and Microsoft Defender for Endpoint as data sources
    - Container and image scanning experience
    - Familiarity with NVD, EPSS, KEV, and ExploitDB data feeds and their API consumption patterns
    - Exposure to CTEM or exposure management program models
    - Certifications: CISSP, GIAC (GEVA, GCIA), AZ-500
    Pay Range: $75.00 - $85.00 per hour, depending upon experience.
    Health & Medical Benefits, 401K, Employee Assistance Program, and Sick Time applicable by state.