1

Vice President Vulnerability Management Jobs (NOW HIRING)

VP Information Security

Houston, TX · On-site

$149K - $187K/yr

The Vice President, Information Security will build the company's enterprise security program from ... Directly manage security operations including SIEM, EDR, identity management, and vulnerability ...

IT Risk Management VP

New York, NY

$171K - $215K/yr

... Management VP in their HQ NYC office. The incumbent will be responsible for the day-to-day ... Candidates should have at least 5 years of relevant experience (information security/vulnerability ...

next page

Showing results 1-20

Vice President Vulnerability Management information

See salary details

$43.5K

$157.5K

$277.5K

How much do vice president vulnerability management jobs pay per year?

As of Aug 26, 2026, the average yearly pay for vice president vulnerability management in the United States is $157,532.00, according to ZipRecruiter salary data. Most workers in this role earn between $115,000.00 and $190,000.00 per year, depending on experience, location, and employer.

What does a vice president vulnerability management do?

A Vice President of Vulnerability Management oversees the strategy and execution of identifying, assessing, and mitigating security vulnerabilities across an organization’s systems and infrastructure. They lead teams responsible for vulnerability scanning, risk assessment, and remediation efforts, and collaborate with other IT and security leaders to ensure the company's assets are protected against threats. This role also involves developing policies, staying up-to-date with evolving cyber threats, and reporting on the organization's risk posture to executive leadership. Their work is critical in maintaining the security and compliance of the company.

How does a vice president vulnerability management typically collaborate with other departments to enhance organizational security?

A Vice President of Vulnerability Management works closely with IT, security operations, compliance, and risk management teams to identify, assess, and remediate vulnerabilities across the organization. This role often leads cross-functional meetings to prioritize remediation efforts, communicate risk levels, and align security initiatives with business objectives. Effective collaboration ensures that vulnerability management strategies are integrated into broader security and business processes, fostering a proactive security culture and supporting regulatory compliance. Regular interaction with executive leadership is also common, as reporting on risk posture and program effectiveness is a key responsibility.

What is the difference between Vice President Vulnerability Management vs Security Director?

AspectVice President Vulnerability ManagementSecurity Director
ResponsibilitiesOversees enterprise-wide vulnerability programs, sets strategic direction, manages teams, and collaborates with executive leadershipManages security operations, implements security policies, and oversees security teams at the organizational level
CredentialsTypically requires CISSP, CISA, or similar certifications; extensive experience in cybersecurity and vulnerability managementOften holds CISSP, CISM, or equivalent; strong background in security operations and management
Work EnvironmentStrategic, executive-level role often involving cross-department collaborationOperational role focused on day-to-day security management and incident response

The Vice President Vulnerability Management focuses on strategic oversight of vulnerability programs at an enterprise level, while the Security Director handles daily security operations and policy implementation. Both roles require relevant certifications and experience but differ mainly in scope and focus.

What cities are hiring for Vice President Vulnerability Management jobs?

Cities with the most Vice President Vulnerability Management job openings:

What are the most commonly searched types of Vulnerability Management jobs?

The most popular types of Vulnerability Management jobs are:

What states have the most Vice President Vulnerability Management jobs?

States with the most job openings for Vice President Vulnerability Management jobs include:

Infographic showing various Vice President Vulnerability Management job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 13% Part Time, and 2% Contract. Highlights an 83% Physical, 2% Hybrid, and 15% Remote job distribution, with an average salary of $157,532 per year, or $75.7 per hour.

Vice President, Product Management - Exposure Command & Vulnerability Management

San Francisco, CA • On-site

Rapid7
1 - 5K employees

Full-time

Posted 7 days ago


Job description

Vice President, Product Management - Exposure Command & Vulnerability Management
Rapid7 is looking for an experienced and visionary leader to join our Product team as Vice President, Product Management for our Exposure Command and Vulnerability Management product suite. In this role, you will set the strategic direction for Rapid7's flagship exposure and vulnerability management platform, driving the products that help thousands of security teams around the world identify, prioritize, and eliminate risk across their entire attack surface.
About the Team
The Product Management team at Rapid7 defines the future of cybersecurity by transforming complex security challenges into seamless, customer-centric cloud solutions that protect thousands of global enterprises. Our Exposure Command team sits at the center of Rapid7's mission - building the platform that brings together vulnerability management, attack surface management, cloud security, and application risk into a unified, actionable view of exposure.
About the Role
Reporting to the Chief Product & Technology Office, Vice President, Product Management for Exposure Command and Vulnerability Management, your primary responsibility will be to own and evolve the end-to-end product strategy, roadmap, and execution for Rapid7's core exposure management platform.
Specifically, your focus will be to:
  • Partner with the Chief Product & Technology Officer and senior executive leadership to define and execute a multi-year product vision for Exposure Command, InsightVM, and adjacent vulnerability and attack surface management capabilities that positions Rapid7 as the definitive leader in the Gartner Exposure Assessment Platform category.
  • Drive the evolution from point-in-time vulnerability management to continuous, risk-based exposure management - translating market trends such as CTEM (Continuous Threat Exposure Management), autonomous remediation, and AI-driven exposure validation into differentiated product capabilities.
  • Lead cross-functional orchestration across engineering, UX design, data science, threat intelligence, and go-to-market teams to ship high-quality, customer-validated product releases on time and within scope.
  • Own the product portfolio P&L lens - partnering with finance, sales, and marketing to define packaging, pricing, and competitive positioning that drives ARR growth and customer retention across the Exposure Command product line.
  • Establish a robust customer engagement and feedback framework - including Customer Zero, advisory boards, and field validation loops - to ground product decisions in real-world security operations workflows and practitioner needs.
  • Champion the platform integration strategy, ensuring Exposure Command's 500+ connectors, third-party data ingestion, and ecosystem partnerships deliver a seamless, unified experience that reduces tool sprawl for security teams.
  • Define and track product-level OKRs and KPIs - including adoption, feature utilization, NPS, and risk reduction outcomes - to continuously measure and communicate the business impact of the product portfolio.
  • Build, mentor, and scale a world-class product management organization, identifying senior leadership talent, establishing development paths, and fostering a culture of customer obsession, rigorous execution, and continuous learning.
  • Serve as an external evangelist and thought leader for exposure management - representing Rapid7's product vision at industry conferences, with analysts (Gartner, Forrester, IDC), and in strategic customer and partner conversations.

The skills and qualities you'll bring include
  • 15+ years of progressive product management leadership experience, including direct ownership of complex cloud-native enterprise security or cybersecurity SaaS products at scale, with at least five years at the director or VP level.
  • Deep domain expertise in vulnerability management, exposure management, attack surface management, or adjacent cybersecurity domains - with a clear point of view on where the market is heading and how to build a winning product against that trajectory.
  • Demonstrated ability to translate ambiguous market and customer signals into a crisp, compelling product strategy, and to rally engineering, design, and GTM teams around a shared roadmap and set of priorities.
  • Strong understanding of hybrid and cloud-native security architectures - including SaaS platforms, cloud environments (AWS, Azure, GCP), CI/CD pipelines, and CNAPP/AppSec tooling - sufficient to engage deeply with both customers and engineering.
  • Track record of driving measurable business outcomes: ARR growth, expansion within installed base, improved win rates, and category leadership recognition from analysts and customers alike.
  • Exceptional executive communication skills - capable of presenting complex product strategy and technical tradeoffs in a clear, compelling narrative to C-suite, board, customers, and analysts.
  • Strong cross-functional influence and collaboration skills, with a history of building alignment across engineering, sales, marketing, and customer success without direct authority.
  • Experience building and scaling product management teams, with a coaching mindset and the ability to develop senior PMs into leaders.
  • Comfortable operating in a fast-paced, publicly traded company environment with the organizational maturity to navigate competing priorities, resource constraints, and executive stakeholders.
  • Embody Rapid7's core values and foster a culture of excellence, psychological safety, and customer impact across the product organization.

We know that the best ideas and solutions come from multi-dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don't be shy - apply today.
#LI-CG4
About Rapid7
At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what's possible and drive extraordinary impact. We're building a dynamic and collaborative workplace where new ideas are welcome.
Protecting 11,500+ customers against bad actors and threats means we're continuing to push the envelope just like we' ve been doing for the past 20 years. If you 're ready to solve some of the toughest challenges in cybersecurity, we're ready to help you take command of your career. Join us.
Rapid7, Inc. is committed to fair and equitable compensation practices. A candidate's salary is determined by various factors including, but not limited to, relevant work experience, skills, and certifications. We evaluate compensation decisions on a case-by-case basis, and it is not typical for an individual to be hired at the very top of the salary range.
The annual salary range for this role, depending on location, is:
United States: $259,300.00 - 350,800.00 USD Annual
Salary ranges may vary based on geographical location. This range does not include variable/incentive compensation, equity and benefits (where applicable/eligible).
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or any other status protected by applicable national, federal, state or local law.