1

Vp Vulnerability Management Jobs (NOW HIRING)

VP, Cybersecurity

Washington, DC · Hybrid

$177K - $222K/yr

... vulnerability management, and emerging security technologies. The role is responsible for ensuring cybersecurity capabilities remain effective, scalable, resilient, and aligned with business ...

VP, Cybersecurity

Washington, DC · Hybrid

$177K - $222K/yr

... vulnerability management, and emerging security technologies. The role is responsible for ensuring cybersecurity capabilities remain effective, scalable, resilient, and aligned with business ...

VP, Cybersecurity

Reston, VA · Hybrid

$163K - $204K/yr

... vulnerability management, and emerging security technologies. The role is responsible for ensuring cybersecurity capabilities remain effective, scalable, resilient, and aligned with business ...

VP, Cybersecurity

Washington, DC · Hybrid

$177K - $222K/yr

... vulnerability management, and emerging security technologies. The role is responsible for ensuring cybersecurity capabilities remain effective, scalable, resilient, and aligned with business ...

next page

Showing results 1-20

Vp Vulnerability Management information

See salary details

$43.5K

$157.5K

$277.5K

How much do vp vulnerability management jobs pay per year?

As of Sep 8, 2026, the average yearly pay for vp vulnerability management in the United States is $157,532.00, according to ZipRecruiter salary data. Most workers in this role earn between $115,000.00 and $190,000.00 per year, depending on experience, location, and employer.

What does a VP of Vulnerability Management do?

A VP of Vulnerability Management oversees an organization's strategies and operations for identifying, assessing, and mitigating security vulnerabilities in IT systems. This executive leads teams that manage vulnerability assessments, remediation efforts, and compliance with security standards. They also collaborate with other departments to ensure that security measures are integrated into business processes and technology initiatives. The role requires a deep understanding of cybersecurity frameworks, risk management, and leadership in guiding security policies across the organization.

How does a VP of Vulnerability Management typically collaborate with other departments to ensure effective security risk mitigation?

A VP of Vulnerability Management plays a pivotal role in cross-departmental collaboration, frequently working with IT, development, compliance, and executive teams to address security risks. They facilitate communication between technical and non-technical stakeholders, translating complex vulnerabilities into actionable insights for leadership and operational teams. This collaboration ensures that vulnerability remediation aligns with business objectives and regulatory requirements, fostering a culture of shared responsibility for security across the organization.

What are the key skills and qualifications needed to thrive as a VP of Vulnerability Management, and why are they important?

To thrive as a VP of Vulnerability Management, you need deep expertise in cybersecurity, risk assessment, and regulatory compliance, usually backed by a degree in information security or a related field and significant leadership experience. Familiarity with vulnerability scanning tools (such as Qualys and Nessus), SIEM platforms, and relevant certifications like CISSP or CISM is crucial. Strong leadership, communication, and strategic thinking skills set top performers apart in managing cross-functional security initiatives. These capabilities are essential to safeguard organizational assets, ensure regulatory compliance, and effectively lead complex security programs.

What is the difference between Vp Vulnerability Management vs Vulnerability Analyst?

AspectVp Vulnerability ManagementVulnerability Analyst
CertificationsCertified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH)CompTIA Security+, GIAC Security Essentials (GSEC)
Work EnvironmentStrategic leadership, overseeing vulnerability programs, collaborating with executive teamsHands-on analysis, vulnerability scanning, reporting, and remediation support
Employer & Industry UsageLarge enterprises, cybersecurity firms, IT departmentsSecurity teams, IT departments, consulting firms

The Vp Vulnerability Management role focuses on strategic oversight, policy development, and managing vulnerability programs at an organizational level. In contrast, Vulnerability Analysts perform technical assessments, conduct scans, and support remediation efforts. Both roles are essential but differ in scope, responsibilities, and required credentials.

What are the most commonly searched types of Vulnerability Management jobs?

The most popular types of Vulnerability Management jobs are:

What are popular job titles related to Vp Vulnerability Management jobs?

For Vp Vulnerability Management jobs, the most frequently searched job titles are:

Infographic showing various Vp Vulnerability Management job openings in the United States as of September 2026, with employment types broken down into 95% Full Time, and 5% Part Time. Highlights an 90% In-person, 5% Hybrid, and 5% Remote job distribution, with an average salary of $157,532 per year, or $75.7 per hour.

SVP, Vulnerability Management & Cloud Security Posture Platform Engineering

Manhattan, NY • On-site

Other

This job post has expired 2 days ago. Applications are no longer accepted.


Job description

SVP, Vulnerability Management & Cloud Security Posture Platform Engineering

We're seeking a team member for the role of SVP, Vulnerability Management & Cloud Security Posture Platform Engineering to join our Cybersecurity Engineering Tools & Platforms team. This role is located in New York, NY; Pittsburgh, PA; or Washington, DC.

This is a high-impact, deeply technical individual contributor role focused on both running and engineering enterprise cybersecurity platforms that support vulnerability management, asset discovery, network and infrastructure scanning, cloud security posture management, cloud-native risk visibility, reporting, and remediation enablement.

This role fits in the intersection of hands-on platform operations, deployment and execution, troubleshooting, automation engineering, service ownership, and technical leadership.

In this role, you'll make an impact in the following ways:

  • Own engineering and operational accountability for enterprise vulnerability management and cloud security posture management tooling.
  • Run critical cybersecurity platforms day to day, including platform health, configuration, access, integrations, upgrades, onboarding, troubleshooting, vendor support, and production stability.
  • Engineer platform improvements that increase reliability, scalability, coverage, automation, performance, data quality, and operational resilience.
  • Manage platform configuration, tenant administration, access models, scanner and agent lifecycle, cloud connectors, onboarding standards, and service health.
  • Support scanning across servers, endpoints, databases, network devices, appliances, cloud assets, containers, external-facing assets, and other enterprise technologies.
  • Partner with network and infrastructure teams on scanner placement, network zones, routing, firewall rules, segmentation, latency, reachability, authenticated scanning, and scan troubleshooting.
  • Drive asset discovery, inventory reconciliation, coverage reporting, ownership validation, and integration with CMDB and authoritative asset sources.
  • Build and maintain automation, APIs, configuration management, dashboards, reporting workflows, and data pipeline integrations, including integrations that ingest asset, ownership, cloud, and configuration data from enterprise systems and publish vulnerability and posture data to downstream remediation, reporting, and risk platforms.
  • Partner with vulnerability management teams to enable prioritization, remediation tracking, SLA governance, exception workflows, and major vulnerability response.
  • Own platform monitoring, health checks, operational dashboards, incident response, vendor escalations, disaster recovery readiness, and business continuity procedures.
  • Support SSO, RBAC, privileged access, service accounts, API tokens, access recertification, segregation of duties, audit evidence, and regulatory reporting.
  • Troubleshoot complex issues across tools, agents, scanners, APIs, cloud connectors, networks, identity systems, data pipelines, vendor platforms, and downstream reporting consumers.
  • Create dynamic engineering solutions using languages such as Python, Go, Java, or similar.
  • Mentor engineers, improve runbooks and documentation, and raise the technical bar through hands-on platform expertise.

To be successful in this role, you bring:

  • Hands-on experience running and engineering enterprise cybersecurity platforms, especially vulnerability management, scanning, asset discovery, cloud security posture, or cloud-native application protection platforms in large financial institutions.
  • Strong operational discipline, including production support, incident response, change management, service health monitoring, vendor escalation, and lifecycle management.
  • Strong engineering mindset, including automation, API integration, configuration management, repeatable deployment patterns, data quality improvement, and toil reduction.
  • Strong understanding of vulnerability management operating models, including remediation tracking, SLA governance, exceptions, ownership validation, and major vulnerability response.
  • Strong networking knowledge, including TCP/IP, routing, DNS, firewalls, proxies, load balancers, network segmentation, NAT, packet flows, latency, and reachability troubleshooting.
  • Experience scanning and assessing diverse enterprise technologies, including servers, endpoints, network devices, databases, appliances, cloud assets, containers, and externally exposed systems.
  • Knowledge of scanner architecture, agent health, network zones, scan routes, authenticated scanning, credential management, and scan troubleshooting.
  • Experience with cloud environments, including AWS, Azure, and GCP, cloud connectors, IAM, APIs, and security control frameworks.
  • Experience integrating cybersecurity platforms with CMDB, ticketing systems, reporting platforms, data pipelines, cloud platforms, vulnerability management systems, and enterprise dashboards.
  • Strong understanding of access management, including SSO, MFA, RBAC, privileged access, service accounts, API tokens, and recertification.
  • Programming and automation skills using Python, Go, Java, or similar.
  • Ability to debug complex issues across platforms, agents, scanners, cloud connectors, APIs, data pipelines, identity systems, networks, firewalls, routing paths, and vendor services.
  • Experience supporting audit, regulatory reporting, evidence retention, operational controls, and production change management.
  • A mindset focused on automation, scalability, governance, resilience, and reducing operational friction.
  • Experience with Kubernetes and container vulnerability management, including cluster visibility, container image assessment, runtime context, registry integrations, cloud-native asset inventory, and remediation workflows.

Preferred:

  • Experience with the following tooling preferred: Qualys, Wiz.io, Lumeta, or similar vulnerability management, asset discovery, network visibility, and cloud security posture platforms.
  • Experience operating or engineering cybersecurity platforms in FedRAMP-authorized or FedRAMP-aligned cloud environments.
  • Familiarity with FedRAMP control expectations, evidence collection, vulnerability scanning requirements, continuous monitoring, access governance, and cloud security operations.

Success Profile

  • Becomes a senior technical authority for both operating and engineering vulnerability management and cloud security posture tooling.
  • Bachelor's degree in computer science or a related discipline, or equivalent work experience required, advanced degree preferred.
  • 10-12 years of experience in information security or related technology experience required, experience in the securities or financial services industry is a plus.
  • Keeps critical cybersecurity platforms stable, healthy, upgraded, monitored, documented, and supportable.
  • Improves platform reliability, scan health, agent health, connector health, data quality, and operational visibility.
  • Expands coverage across infrastructure, applications, business units, cloud accounts, containers, network devices, appliances, and external-facing assets.
  • Enables reliable reporting, remediation tracking, SLA governance, audit evidence, and regulatory support.
  • Reduces manual effort through automation, repeatable onboarding, self-service intake, standardized runbooks, and engineered controls.
  • Strengthens access governance, platform controls, service ownership discipline, and production resilience.

This role is for someone who wants to run, own, and engineer the platforms that define cyber risk visibility across the enterprise. Day-to-day platform execution and long-term engineering decisions will directly impact security posture, vulnerability response, regulatory confidence, and operational resilience across BNY.

At BNY, our culture allows us to run our company better and enables employees' growth and success. As a leading global financial services company at the heart of the global financial system, we influence nearly 20% of the world's investible assets. Every day, our teams harness cutting-edge AI and breakthrough technologies to collaborate with clients, driving transformative solutions that redefine industries and uplift communities worldwide.

Recognized as a top destination for innovators, BNY is where bold ideas meet advanced technology and exceptional talent. Together, we power the future of finance and this is what #LifeAtBNY is all about. Join us and be part of something extraordinary.