Job Summary:
Saronic Technologies is a leader in revolutionizing autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations through autonomous and intelligent platforms. They are seeking a hands-on Vulnerability Management Lead to own the VM program end-to-end, acting as the technical authority for vulnerability discovery, triage, prioritization, remediation, and reporting across various environments. The role involves driving accountability across engineering teams and shaping the long-term VM posture as the company scales.
Responsibilities:
โข Own end-to-end vulnerability lifecycle: discovery, validation, prioritization, remediation tracking, exception management, and verification across cloud, on-prem, container, and embedded Linux environments
โข Operate and optimize enterprise vulnerability scanning platforms for continuous credentialed scanning across servers, endpoints, network devices, containers, and cloud assets; maintain coverage, schedules, and configuration audit policies
โข Integrate vulnerability scanning into CI/CD pipelines to harden build workflows, enforce least-privilege controls, and surface supply chain risks before they reach production
โข Leverage AI-assisted scanning and graph-based enrichment pipelines to accelerate triage, map lateral exposure paths, and prioritize findings by exploitability and mission impact
โข Correlate findings across tools to eliminate noise, reduce false positives, and surface the vulnerabilities that actually matter
โข Apply CVSS, CISA KEV, exploit maturity, and asset exposure context โ including internet-facing systems, privileged access paths, and classified adjacency โ to drive risk-based SLAs and remediation sequencing
โข Partner with software and platform engineering teams to drive timely remediation; own escalation paths for aging critical and high findings
โข Lead critical CVE response: rapid triage, impact assessment, containment guidance, and stakeholder communication for zero-days and actively exploited vulnerabilities
โข Govern exception management: risk acceptance with compensating controls, time-bound approvals, and periodic review cycles
โข Coordinate patching windows and change management across Windows, Linux, network devices, and cloud services
โข Align the VM program to CMMC Level 2/3 requirements; produce audit-ready evidence, POA&Ms, and control effectiveness documentation
โข Deliver executive and operational reporting: exposure trends, SLA performance, mean time to remediate, patch coverage, and remediation velocity
โข Support CMMC assessments and audits with clean, well-documented vulnerability data and remediation history
โข Maintain asset inventory hygiene and scan coverage metrics; ensure classified and sensitive system boundaries are respected in tooling and data handling
โข Build and mature automation for scan scheduling, finding enrichment, ticket creation, SLA tracking, and reporting โ reducing manual overhead as the program scales
โข Define and refine VM policies, procedures, and playbooks including critical CVE response runbooks and patch cadence standards
โข Evaluate and recommend tooling improvements; drive integration across the vulnerability management and broader security stack
โข Mentor and support analysts as the team grows; run tabletop exercises for vulnerability and patching scenarios
Qualifications:
Required:
โข 5+ years in cybersecurity with 3+ years of hands-on vulnerability management ownership in hybrid on-prem/cloud environments
โข Deep operational expertise with enterprise vulnerability scanning platforms โ credentialed scanning, policy tuning, coverage management, and integration with downstream workflows
โข Strong command of CVE/CVSS scoring, CISA KEV, exploit maturity indicators, and the ability to translate technical risk into business impact for non-technical stakeholders
โข Experience with CI/CD security tooling and supply chain risk management, including build pipeline security principles
โข Proven track record driving remediation accountability across engineering teams โ you know how to get vulnerabilities closed, not just reported
โข Experience aligning VM programs to federal or defense compliance frameworks; CMMC, NIST SP 800-171, or NIST RMF experience strongly preferred
โข Metrics-driven: comfortable owning exposure reduction KPIs, SLA adherence, MTTR, and patch coverage dashboards
โข Clear, direct communicator โ equally effective in a technical deep-dive and an executive briefing
โข Security clearance eligibility
Preferred:
โข Active Secret or TS clearance, or prior clearance history
โข Experience with AI-assisted vulnerability tooling, graph-based asset and exposure analysis, or automated enrichment pipelines
โข Experience with CI/CD pipeline security hardening platforms
โข Experience operating in classified or air-gapped environments
โข Scripting or automation experience (Python, PowerShell, or Bash) for scan orchestration, data normalization, API integrations, and reporting pipelines
โข Experience with container and cloud-native vulnerability management using CSP-native security tooling
โข Familiarity with NIST SP 800-218 (Secure Software Development Framework) and software supply chain security frameworks
โข Relevant certifications: CISSP, CySA+, GCSA, GCPN, Security+, or equivalent
Company:
Saronic is building cutting-edge unmanned surface vehicles that enable maritime security and domain awareness by combining best-in-class hardware, software and artificial intelligence into one scalable, fully integrated platform. Founded in 2022, the company is headquartered in Austin, USA, with a team of 1001-5000 employees. The company is currently Late Stage.