2

Full Time Vulnerability Management Jobs (NOW HIRING)

Vulnerability Analyst

Washington, DC · On-site

$99K - $225K/yr

Lead the enterprise vulnerability management process in support of continuous monitoring and RMF ... Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible ...

Job Type Full-time Description Paylocity is an award-winning provider of cloud-based HR and payroll ... Develops and maintains vulnerability management policies, provides technical analysis and guidance ...

next page

Showing results 1-20

Full Time Vulnerability Management information

What are the key skills and qualifications needed to thrive in a Full Time Vulnerability Management role, and why are they important?

To excel in a Full Time Vulnerability Management role, you need expertise in cybersecurity principles, vulnerability assessment, and risk management, often supported by a degree in computer science or a related field. Familiarity with tools such as Nessus, Qualys, Rapid7, and certifications like CISSP or CompTIA Security+ are typically required. Strong analytical thinking, problem-solving abilities, and effective communication are crucial soft skills for this position. These competencies are essential to proactively identify, assess, and mitigate security vulnerabilities, protecting organizational assets from potential threats.

What is the difference between Full Time Vulnerability Management vs Vulnerability Analyst?

AspectFull Time Vulnerability ManagementVulnerability Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CEH, OSCP
Work EnvironmentSecurity teams, IT departments, corporate environmentsSecurity teams, IT departments, cybersecurity firms
Employer & Industry UsageLarge enterprises, government agencies, financial institutionsTech companies, consulting firms, cybersecurity providers
Job FocusManaging vulnerability programs, coordinating remediation, policy enforcementIdentifying vulnerabilities, analyzing security gaps, reporting findings

Full Time Vulnerability Management roles focus on overseeing vulnerability programs, coordinating remediation efforts, and implementing security policies. Vulnerability Analysts primarily identify and analyze security vulnerabilities, providing detailed reports. While both roles require similar certifications and work in cybersecurity environments, Vulnerability Management is more strategic and managerial, whereas Vulnerability Analysts are more technical and investigative.

What are some common challenges faced in a full-time vulnerability management role, and how can they be addressed?

In a full-time vulnerability management position, professionals often face challenges such as managing a high volume of discovered vulnerabilities, prioritizing remediation efforts, and coordinating with various teams to ensure timely patching. Keeping up with the rapidly changing threat landscape and ensuring all stakeholders understand the risks can also be demanding. These challenges can be addressed by implementing automated tools for scanning and tracking, establishing clear communication channels with IT and development teams, and developing a risk-based prioritization strategy to focus on the most critical vulnerabilities first.

What is a Full Time Vulnerability Management professional?

A Full Time Vulnerability Management professional is responsible for identifying, assessing, and mitigating security vulnerabilities within an organization's IT systems and networks. Their primary tasks include conducting regular vulnerability scans, analyzing security risks, prioritizing vulnerabilities based on potential impact, and coordinating remediation efforts with IT teams. They also develop and implement processes to continuously monitor security weaknesses, ensure compliance with industry standards, and help protect the organization from cyber threats. This role is crucial in maintaining the overall security posture of a company.
More about Full Time Vulnerability Management jobs
What cities are hiring for Full Time Vulnerability Management jobs? Cities with the most Full Time Vulnerability Management job openings:
What are the most commonly searched types of Vulnerability Management jobs? The most popular types of Vulnerability Management jobs are:
Infographic showing various Full Time Vulnerability Management job openings in the United States as of June 2026, with employment types broken down into 74% Full Time, 24% Part Time, and 2% Contract. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution.
Senior Manager, Vulnerability Management and Application Security

Senior Manager, Vulnerability Management and Application Security

CarMax, Inc.

Richmond, VA • On-site

Full-time

PTO

Posted 13 days ago


Key responsibilities

  • Oversee and continuously improve the enterprise vulnerability management and application security programs, ensuring effective alignment of processes, tools, and assessments.

  • Develop and manage program roadmaps, budgets, and priorities for security assessments across infrastructure, networks, cloud services, and applications.

  • Create and deliver executive-ready reporting with clear documentation, risk insights, program metrics, and prioritized mitigation recommendations.


CarMax rating

8.0

Company rating: 8.0 out of 10

Based on 368 frontline employees who took The Breakroom Quiz

28th of 722 rated retailers


Job description

8901 - Corp Office West Crk - 12800 Tuckahoe Creek Parkway, Richmond, Virginia, 23238
CarMax, the way your career should be!
Position Overview
As a Senior Manager, Vulnerability Management and Application Security, you will lead CarMax's enterprise vulnerability management and application security programs and serve as a trusted subject matter expert responsible for strengthening the organization's security posture. You will mentor and guide a high-performing team, streamline processes, optimize program operations, and deliver actionable insights that influence decision-making across all levels, including executive leadership. This role is ideal for a collaborative, results-driven leader with a passion for building effective programs and improving the security, resilience, and reliability of technology environments and software delivery practices.
Why CarMax?
At CarMax, we are the nation's largest retailer of used cars with stores from coast to coast, and we are still growing. We're rethinking the way people buy cars - and it's our associates that help us do just that. We believe work should feel meaningful and rewarding, with opportunities to make an impact every day. This is where innovation meets passion - be inspired and supported to take us to the future.
Team Overview
The Vulnerability Management and Application Security team guides enterprise strategy for identifying, analyzing, and prioritizing remediation of risks across CarMax's systems, infrastructure, and applications. As the Senior Manager, you will shape program strategy, strengthen integration with cybersecurity and engineering partners, and enable teams to build and operate secure technology through clear communication, effective governance, thorough reporting, and trusted leadership.
Role Responsibilities
  • Oversee and continuously improve the enterprise vulnerability management and application security programs, ensuring effective alignment of processes, tools, and assessments.
  • Develop and manage program roadmaps, budgets, and priorities for security assessments across infrastructure, networks, cloud services, and applications.
  • Create and deliver executive-ready reporting with clear documentation, risk insights, program metrics, and prioritized mitigation recommendations.
  • Define and maintain vulnerability management and application security standards, SLAs, and governance practices in partnership with cybersecurity and technology leaders.
  • Lead risk-based remediation prioritization and ensure consistent progress across infrastructure, engineering, and product teams and partners.
  • Coordinate and communicate responses to emerging threats, zero-day vulnerabilities, and critical application security findings to drive timely remediation.
  • Lead the application security program, including secure development lifecycle practices, application security testing, and risk-based remediation strategies.
  • Partner with engineering, architecture, and product teams to embed security requirements, threat modeling, code scanning, and security reviews into the software development lifecycle - foster a culture of security.
  • Mature application security capabilities such as SAST, DAST, software composition analysis, secrets detection, and security testing for internally developed and third-party applications.
  • Provide guidance on secure coding practices, common vulnerabilities, and remediation approaches.
  • Adapt to and apply technology innovation, including AI, to the role and program overall.
  • Adapt the team and programs to ever-changing threat and regulatory landscape.

Required Qualifications
  • 8+ years of cybersecurity experience with emphasis on vulnerability management, application security, risk analysis, and security assessment practices.
  • 5+ years of experience designing, implementing, or supporting secure information systems and application security practices.
  • 3+ years in a security leadership or management role guiding teams or programs.
  • One or more certifications such as CISA, CISM, CEH, CISSP, or SANS.
  • Experience with enterprise security technologies and application security tooling such as vulnerability scanners, SAST, DAST, software composition analysis, SIEM platforms, and network devices - firewalls, IDS/IPS, routers, and switches.
  • Strong ability to analyze complex security findings, communicate risk clearly to diverse audiences, and drive remediation across infrastructure, engineering, and business teams or partners.
  • Bachelor's Degree in a technology-related field or equivalent experience in Cybersecurity and Risk Management, preferred.

Work Location and Arrangement: This role will be based out of the CarMax Home Office in Richmond, VA and Associates will work onsite 4 days per week.
Work Authorization: Applicants must be currently authorized to work in the United States on a full-time basis. Sponsorship will not be considered for this specific role.
About CarMax
At CarMax, we revolutionized the used car buying experience over 30 years ago by introducing transparency and integrity into the process. Our commitment to customer experience, innovation, and community has made us the nation's largest used car retailer. With over 250 store locations and over 30,000 associates, we are proud to have been recognized as one of the Fortune 100 Best Companies to Work For® and are committed to helping our communities thrive.
As an associate, you are part of an innovative movement to empower the modern customer and drive progress. Your work fuels change-sparking ideas, overcoming challenges, and shaping what's next. Join us in creating a better future- for our company, our customers, and the communities we call home.
CarMax is an equal opportunity employer, and all qualified candidates will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, protected veteran status, disability status, or any other characteristic protected by law.
The annual salary for this position is:
$144,500.00 - $231,200.00
May be eligible for bonus and equity.
Benefits:
Except as otherwise required by state law, CarMax Associates are entitled to the following paid sick, vacation, and holiday time.
Associates that are considered full-time hourly or commission/incentive eligible:
  • To earn up to 48 hours of sick time per year accrued on a per pay period basis and between 80 hours and 200 hours per year of vacation time after a 90 day waiting period depending on years of continuous service with the Company.
  • For 8 hours of pay for each of a total of 6 paid scheduled holidays per year plus 1 floating holiday. If such an Associate does work on a scheduled holiday due to business need, they are eligible for Holiday Premium Pay.

Associates considered full-time salaried are entitled to paid time away with no specified limit as needed for sick, vacation, bereavement, jury duty, holidays, floating holiday, etc. subject to manager approval.
For more details about benefits, please visit our CarMax Benefits website.
Upon an applicant's request, CarMax will consider reasonable accommodation to complete the CarMax Job Application.

What CarMax employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom