1

Director Vulnerability Management Jobs (NOW HIRING)

Direct experience supporting vulnerability management in at least two of the following cloud providers: AWS, Azure, GCP * Background working within at least one compliance framework (for example ...

SOC Vulnerability Management ACAS Lead - Senior

Fairfax, VA · On-site

$105K - $143K/yr

... directing scan planning, execution, validation, and reporting across supported ARNG enterprise ... Coordinate vulnerability management activities with SOC functions and enterprise cyber operations ...

next page

Showing results 1-20

Director Vulnerability Management information

What are some common challenges faced by a Director of Vulnerability Management, and how can they be addressed?

A Director of Vulnerability Management often encounters challenges such as prioritizing remediation efforts among numerous vulnerabilities, coordinating across multiple teams, and keeping up with rapidly evolving threat landscapes. Addressing these challenges requires strong communication skills to align IT, security, and business stakeholders, as well as implementing effective vulnerability assessment tools and processes. Building a culture of continuous improvement and staying updated with the latest cybersecurity trends can also help in proactively managing and mitigating risks.

Can I make $200,000 a year in cyber security?

A Director of Vulnerability Management can potentially earn $200,000 or more annually, especially with extensive experience, advanced certifications like CISSP, and leadership responsibilities. Salaries vary by industry, location, and company size, but senior cybersecurity roles often reach or exceed this level for experienced professionals.

Can you make $500,000 a year in cyber security?

A Director of Vulnerability Management can potentially earn $500,000 annually, especially with extensive experience, advanced certifications, and working in high-paying industries or organizations. Such salaries often include bonuses, stock options, or other incentives. Achieving this level typically requires a combination of technical expertise, leadership skills, and strategic responsibilities.

What does a Director of Vulnerability Management do?

A Director of Vulnerability Management oversees an organization's efforts to identify, assess, and remediate security vulnerabilities in its systems and networks. This role involves leading a team of security professionals, developing vulnerability management strategies, ensuring compliance with industry standards, and collaborating with IT and business units to mitigate risks. The director also communicates security risks to executive leadership and helps prioritize remediation efforts based on potential business impact.

Who is Trump's director of cyber security?

There is no publicly known position titled 'Director of Cyber Security' specifically associated with Donald Trump. In government, cybersecurity roles are typically held by officials such as the Cybersecurity and Infrastructure Security Agency (CISA) Director or National Cyber Director, but these are not directly linked to Trump personally. The role and leadership in cybersecurity within the government can vary depending on administration and organizational structure.

Is 40 too old for cyber security?

Age is not a barrier to becoming a Director of Vulnerability Management or working in cybersecurity. Many professionals successfully transition into cybersecurity roles at various ages, leveraging skills such as problem-solving, technical knowledge, and certifications like CISSP or CISA. Experience and continuous learning are often more important than age in this field.

What are the key skills and qualifications needed to thrive as a Director of Vulnerability Management, and why are they important?

To thrive as a Director of Vulnerability Management, you need a strong background in cybersecurity, risk assessment, and vulnerability management frameworks, typically supported by a bachelor's degree in information security or related fields and relevant certifications like CISSP or CISM. Familiarity with vulnerability scanning tools (e.g., Qualys, Nessus), SIEM platforms, and patch management systems is essential. Exceptional leadership, communication, and strategic thinking skills help coordinate cross-functional teams and drive remediation efforts. These skills and qualities are crucial for proactively identifying risks, ensuring regulatory compliance, and safeguarding organizational assets from cyber threats.

What is the difference between Director Vulnerability Management vs Security Manager?

AspectDirector Vulnerability ManagementSecurity Manager
Primary FocusOverseeing vulnerability assessment and remediation strategiesManaging overall security policies and team operations
CertificationsCertifications like CISSP, CISA, GIACCertifications like CISSP, CISM, CompTIA Security+
Work EnvironmentSecurity teams, vulnerability scanning tools, incident responseSecurity teams, policy development, risk management
Industry UsageCommon in large enterprises with dedicated vulnerability teamsWidespread across organizations managing overall security

The main difference is that the Director Vulnerability Management focuses specifically on identifying and addressing security vulnerabilities, while the Security Manager oversees broader security policies and team management. Both roles require similar certifications and work in security-focused environments, but their scope and responsibilities differ.

More about Director Vulnerability Management jobs
What cities are hiring for Director Vulnerability Management jobs? Cities with the most Director Vulnerability Management job openings:
What are the most commonly searched types of Vulnerability Management jobs? The most popular types of Vulnerability Management jobs are:
What states have the most Director Vulnerability Management jobs? States with the most job openings for Director Vulnerability Management jobs include:
Testing, Exercising & Vulnerability Management, Managing Director

Testing, Exercising & Vulnerability Management, Managing Director

State Street Global Advisors

Boston, MA

$170K - $252K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 5 days ago


Job description

Role Purpose

The Managing Director leads the firm's global resilience testing, exercising and vulnerability management capability. The role is accountable for establishing the enterprise framework, strategy and annual programme, ensuring a risk-based, regulator-ready approach that identifies vulnerabilities, drives remediation and strengthens resilience across critical business services, functions and third-party dependencies.

The role provides enterprise-wide oversight of testing activities and operates a Centre of Excellence to support consistent execution across business and functional teams, while driving continuous improvement through innovation, automation and AI.

Key Responsibilities

Framework, Strategy & Governance

  • Define and maintain global frameworks, standards, methodologies and controls
  • Establish consistent approaches to scenario design, execution, reporting and remediation
  • Lead the annual testing strategy aligned to critical services, risks and dependencies
  • Ensure robust governance across central and federated testing activities

Global Testing & Exercising Programme

  • Design and deliver a global, risk-based testing programme
  • Ensure coverage across business services, operations, technology, cyber and third parties
  • Oversee full lifecycle of exercises (planning, execution, evaluation, follow-up)
  • Deliver diverse and realistic testing (e.g. crisis simulations, cross-functional exercises, severe-but-plausible scenarios)

Vulnerability Management & Remediation

  • Own identification, analysis and reporting of vulnerabilities from testing activities
  • Ensure actionable remediation plans with clear ownership, timelines and prioritisation
  • Drive root cause analysis and identification of systemic issues
  • Track closure and escalate delays or recurring deficiencies

Centre of Excellence & Advisory

  • Provide standards, tools, templates and guidance across the enterprise
  • Offer expert challenge, advisory and quality assurance
  • Build capability and promote consistency across business-led testing

Policy, Compliance & Assurance

  • Ensure alignment with internal policies, governance and regulatory expectations
  • Partner with risk, compliance and audit functions
  • Maintain audit-ready documentation, reporting and evidence

Innovation, Tooling & AI

  • Drive adoption of automation, workflow tools and AI
  • Enhance data capture, reporting, analytics and action tracking
  • Support a scalable, data-driven testing capability

Emerging Risks & External Developments

  • Incorporate emerging threats, cyber risks and geopolitical developments into scenarios
  • Monitor regulatory and industry practices
  • Continuously evolve methodologies and testing approaches

Stakeholder & Regulatory Engagement

  • Engage senior stakeholders, regulators, clients and third parties
  • Present programme outcomes, vulnerabilities and remediation priorities
  • Drive enterprise ownership, participation and accountability

Leadership

  • Lead and develop a global team of resilience professionals
  • Foster a high-performance, accountable and collaborative culture
  • Build organisational capability across testing, exercising and analysis

Scope of Responsibility

  • Global remit across all business lines, functions, legal entities and jurisdictions
  • Oversight of testing across critical services, operations and third-party ecosystems
  • Accountability for enterprise standards, execution oversight, advisory and remediation governance
  • Engagement with senior executives, regulators and external stakeholders

Experience & Qualifications

  • Senior leadership experience in resilience, testing/exercising, risk or related disciplines
  • Proven experience leading enterprise-wide resilience testing programmes in regulated environments
  • Strong track record in cross-functional and regulator-facing engagement
  • Experience with technology, automation, analytics and AI in resilience
  • Degree required; advanced qualifications or relevant certifications preferred

Knowledge, Skills & Capabilities

  • Deep expertise in resilience testing methodologies and governance
  • Strong understanding of operational resilience and scenario design
  • Ability to translate testing outputs into clear insights and remediation actions
  • Strong executive communication and influencing skills
  • Strategic mindset with strong execution discipline
  • Ability to drive change across complex global organisations

Salary Range:

$170,000 - $252,500 Annual

The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.

Employees are eligible to participate in State Street's comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.

For a full overview, visit https://hrportal.ehr.com/statestreet/Home.

About State Street

Across the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.

We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you'll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.

As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.

Discover more information on jobs at StateStreet.com/careers

Read our CEO Statement

Job Application Disclosure:

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.