1

Director Vulnerability Management Jobs (NOW HIRING)

The Vulnerability Management Lead directs client's vulnerability management program across the ... Direct remediation tracking from finding to closure, including communication and coordination with ...

next page

Showing results 1-20

Director Vulnerability Management information

What are some common challenges faced by a director vulnerability management, and how can they be addressed?

A Director of Vulnerability Management often encounters challenges such as prioritizing remediation efforts among numerous vulnerabilities, coordinating across multiple teams, and keeping up with rapidly evolving threat landscapes. Addressing these challenges requires strong communication skills to align IT, security, and business stakeholders, as well as implementing effective vulnerability assessment tools and processes. Building a culture of continuous improvement and staying updated with the latest cybersecurity trends can also help in proactively managing and mitigating risks.

What does a director vulnerability management do?

A Director of Vulnerability Management oversees an organization's efforts to identify, assess, and remediate security vulnerabilities in its systems and networks. This role involves leading a team of security professionals, developing vulnerability management strategies, ensuring compliance with industry standards, and collaborating with IT and business units to mitigate risks. The director also communicates security risks to executive leadership and helps prioritize remediation efforts based on potential business impact.

What are the key skills and qualifications needed to thrive as a director vulnerability management?

To thrive as a Director of Vulnerability Management, you need a strong background in cybersecurity, risk assessment, and vulnerability management frameworks, typically supported by a bachelor's degree in information security or related fields and relevant certifications like CISSP or CISM. Familiarity with vulnerability scanning tools (e.g., Qualys, Nessus), SIEM platforms, and patch management systems is essential. Exceptional leadership, communication, and strategic thinking skills help coordinate cross-functional teams and drive remediation efforts. These skills and qualities are crucial for proactively identifying risks, ensuring regulatory compliance, and safeguarding organizational assets from cyber threats.

What is the difference between Director Vulnerability Management vs Security Manager?

AspectDirector Vulnerability ManagementSecurity Manager
Primary FocusOverseeing vulnerability assessment and remediation strategiesManaging overall security policies and team operations
CertificationsCertifications like CISSP, CISA, GIACCertifications like CISSP, CISM, CompTIA Security+
Work EnvironmentSecurity teams, vulnerability scanning tools, incident responseSecurity teams, policy development, risk management
Industry UsageCommon in large enterprises with dedicated vulnerability teamsWidespread across organizations managing overall security

The main difference is that the Director Vulnerability Management focuses specifically on identifying and addressing security vulnerabilities, while the Security Manager oversees broader security policies and team management. Both roles require similar certifications and work in security-focused environments, but their scope and responsibilities differ.

More about Director Vulnerability Management jobs
What cities are hiring for Director Vulnerability Management jobs? Cities with the most Director Vulnerability Management job openings:
What are the most commonly searched types of Vulnerability Management jobs? The most popular types of Vulnerability Management jobs are:
What states have the most Director Vulnerability Management jobs? States with the most job openings for Director Vulnerability Management jobs include:
Infographic showing various Director Vulnerability Management job openings in the United States as of August 2026, with employment types broken down into 50% Full Time, and 50% Contract. Highlights an 50% In-person, and 50% Remote job distribution.

Director - Vulnerability Management & Cloud Security Platform 2

Capgemini

Manhattan, NY • On-site

$95 - $149/hr

Other

Medical, Dental, Vision, Retirement

Posted 5 days ago


Capgemini North America rating

7.7

Company rating: 7.7 out of 10

Based on 17 frontline employees who took The Breakroom Quiz

99th of 223 rated it services


Job description

Director – Vulnerability Management & Cloud Security Platform 2 (Contract)

New York, NY, United States (On-site)

Contract (11 months 28 days)

Published 4 days ago

vulnerability management

CMDB platforms

Security Tools

Python

production support

Programming & Automation

We’re seeking a team member for the role of Director - Vulnerability Management & Cloud Security Platform join our Cybersecurity Engineering Tools & Platforms team. This role is located in New York, NY; Pittsburgh, PA; or Washington, DC.

This is a high-impact, deeply technical individual contributor role focused on both running and engineering enterprise cybersecurity platforms that support vulnerability management, asset discovery, network and infrastructure scanning, cloud security posture management, cloud-native risk visibility, reporting, and remediation enablement.

This role fits in the intersection of hands-on platform operations, deployment and execution, troubleshooting, automation engineering, service ownership, and technical leadership.

In this role, you’ll make an impact in the following ways:

Own engineering and operational accountability for enterprise vulnerability management and cloud security posture management tooling.

Run critical cybersecurity platforms day to day, including platform health, configuration, access, integrations, upgrades, onboarding, troubleshooting, vendor support, and production stability.

Engineer platform improvements that increase reliability, scalability, coverage, automation, performance, data quality, and operational resilience.

Manage platform configuration, tenant administration, access models, scanner and agent lifecycle, cloud connectors, onboarding standards, and service health.

Support scanning across servers, endpoints, databases, network devices, appliances, cloud assets, containers, external-facing assets, and other enterprise technologies.

Partner with network and infrastructure teams on scanner placement, network zones, routing, firewall rules, segmentation, latency, reachability, authenticated scanning, and scan troubleshooting.

Drive asset discovery, inventory reconciliation, coverage reporting, ownership validation, and integration with CMDB and authoritative asset sources.

Build and maintain automation, APIs, configuration management, dashboards, reporting workflows, and data pipeline integrations, including integrations that ingest asset, ownership, cloud, and configuration data from enterprise systems and publish vulnerability and posture data to downstream remediation, reporting, and risk platforms.

Partner with vulnerability management teams to enable prioritization, remediation tracking, SLA governance, exception workflows, and major vulnerability response.

Own platform monitoring, health checks, operational dashboards, incident response, vendor escalations, disaster recovery readiness, and business continuity procedures.

Support SSO, RBAC, privileged access, service accounts, API tokens, access recertification, segregation of duties, audit evidence, and regulatory reporting.

Troubleshoot complex issues across tools, agents, scanners, APIs, cloud connectors, networks, identity systems, data pipelines, vendor platforms, and downstream reporting consumers.

Create dynamic engineering solutions using languages such as Python, Go, Java, or similar.

Mentor engineers, improve runbooks and documentation, and raise the technical bar through hands-on platform expertise.

To be successful in this role, you bring:

Hands-on experience running and engineering enterprise cybersecurity platforms, especially vulnerability management, scanning, asset discovery, cloud security posture, or cloud-native application protection platforms in large financial institutions.

Strong operational discipline, including production support, incident response, change management, service health monitoring, vendor escalation, and lifecycle management.

Strong engineering mindset, including automation, API integration, configuration management, repeatable deployment patterns, data quality improvement, and toil reduction.

Strong understanding of vulnerability management operating models, including remediation tracking, SLA governance, exceptions, ownership validation, and major vulnerability response.

Strong networking knowledge, including TCP/IP, routing, DNS, firewalls, proxies, load balancers, network segmentation, NAT, packet flows, latency, and reachability troubleshooting.

Experience scanning and assessing diverse enterprise technologies, including servers, endpoints, network devices, databases, appliances, cloud assets, containers, and externally exposed systems.

Knowledge of scanner architecture, agent health, network zones, scan routes, authenticated scanning, credential management, and scan troubleshooting.

Experience with cloud environments, including AWS, Azure, and GCP, cloud connectors, IAM, APIs, and security control frameworks.

Experience integrating cybersecurity platforms with CMDB, ticketing systems, reporting platforms, data pipelines, cloud platforms, vulnerability management systems, and enterprise dashboards.

Strong understanding of access management, including SSO, MFA, RBAC, privileged access, service accounts, API tokens, and recertification.

Programming and automation skills using Python, Go, Java, or similar.

Ability to debug complex issues across platforms, agents, scanners, cloud connectors, APIs, data pipelines, identity systems, networks, firewalls, routing paths, and vendor services.

Experience supporting audit, regulatory reporting, evidence retention, operational controls, and production change management.

A mindset focused on automation, scalability, governance, resilience, and reducing operational friction.

Experience with Kubernetes and container vulnerability management, including cluster visibility, container image assessment, runtime context, registry integrations, cloud-native asset inventory, and remediation workflows.

Preferred:

Experience with the following tooling preferred: Qualys, Wiz.io, Lumeta, or similar vulnerability management, asset discovery, network visibility, and cloud security posture platforms.

Experience operating or engineering cybersecurity platforms in FedRAMP-authorized or FedRAMP-aligned cloud environments.

Familiarity with FedRAMP control expectations, evidence collection, vulnerability scanning requirements, continuous monitoring, access governance, and cloud security operations.


Success Profile:

Becomes a senior technical authority for both operating and engineering vulnerability management and cloud security posture tooling.

Bachelor's degree in computer science or a related discipline, or equivalent work experience required, advanced degree preferred

10-12 years of experience in information security or related technology experience required, experience in the securities or financial services industry is a plus

Keeps critical cybersecurity platforms stable, healthy, upgraded, monitored, documented, and supportable.

Improves platform reliability, scan health, agent health, connector health, data quality, and operational visibility.

Expands coverage across infrastructure, applications, business units, cloud accounts, containers, network devices, appliances, and external-facing assets.

Enables reliable reporting, remediation tracking, SLA governance, audit evidence, and regulatory support.

Reduces manual effort through automation, repeatable onboarding, self-service intake, standardized runbooks, and engineered controls.

Strengthens access governance, platform controls, service ownership discipline, and production resilience.

The pay range that the employer in good faith reasonably expects to pay for this position is $69.34/hour - $108.35/hour. Our benefits include medical, dental, vision and retirement benefits.

Tundra Technical Solutions is among North America’s leading providers of Staffing and Consulting Services. Our success and our clients’ success are built on a foundation of service excellence. We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic. Qualified applicants with arrest or conviction records will be considered for employment in accordance with applicable law, including the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Unincorporated LA County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: client provided property, including hardware (both of which may include data) entrusted to you from theft, loss or damage; return all portable client computer hardware in your possession (including the data contained therein) upon completion of the assignment, and; maintain the confidentiality of client proprietary, confidential, or non-public information. In addition, job duties require access to secure and protected client information technology systems and related data security obligations.

#J-18808-Ljbffr

What Capgemini North America employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom