1

Vulnerability Management Project Manager Jobs in California

Project Manager

Oakland, CA · Hybrid

$130K - $165K/yr

We welcome applicants from engineering, construction management, project management, business analytics, scheduling, and anyone who thrives in a collaborative environment. Job Overview Title: Project ...

Project Manager

Oakland, CA · On-site

$130K - $165K/yr

We welcome applicants from engineering, construction management, project management, business analytics, scheduling, and anyone who thrives in a collaborative environment. Job Overview Title: Project ...

Project Manager

Sacramento, CA · Hybrid

$130K - $165K/yr

We welcome applicants from engineering, construction management, project management, business analytics, scheduling, and anyone who thrives in a collaborative environment. Job Overview Title: Project ...

Project Manager

Sacramento, CA · On-site

$130K - $165K/yr

We welcome applicants from engineering, construction management, project management, business analytics, scheduling, and anyone who thrives in a collaborative environment. Job Overview Title: Project ...

Lead the project team in planning, scheduling, cost control, and quality management. * Serve as the primary point of contact for the client, design team, and subcontractors. * Manage procurement ...

Lead the project team in planning, scheduling, cost control, and quality management. * Serve as the primary point of contact for the client, design team, and subcontractors. * Manage procurement ...

Lead the project team in planning, scheduling, cost control, and quality management. * Serve as the primary point of contact for the client, design team, and subcontractors. * Manage procurement ...

Showing results 41-60

Vulnerability Management Project Manager information

What is a vulnerability management project manager?

A Vulnerability Management Project Manager is a professional responsible for overseeing and coordinating projects that identify, assess, and remediate security vulnerabilities within an organization’s IT environment. They work with cross-functional teams to ensure vulnerabilities are tracked, prioritized, and addressed according to risk. This role involves project management, communication with stakeholders, and ensuring compliance with security policies and standards. Their goal is to minimize security risks and protect the organization’s assets from potential threats.

How does a vulnerability management project manager typically collaborate with IT and security teams to address identified vulnerabilities?

A Vulnerability Management Project Manager acts as a bridge between technical teams and organizational leadership, ensuring that vulnerabilities are prioritized and remediated efficiently. They coordinate with IT and security professionals to track the status of vulnerabilities, assign remediation tasks, and establish timelines for resolution. Regular meetings and progress updates help align all stakeholders and ensure compliance with internal policies and external regulations. This collaborative approach fosters a proactive security posture and streamlines communication across departments.

What are the key skills and qualifications needed to thrive as a vulnerability management project manager, and why are they important?

To thrive as a Vulnerability Management Project Manager, you need expertise in cybersecurity frameworks, risk assessment, and project management, often supported by a bachelor’s degree and certifications like CISSP or PMP. Familiarity with vulnerability scanning tools (e.g., Qualys, Nessus), ticketing systems, and remediation tracking software is essential. Strong communication, leadership, and problem-solving skills help coordinate cross-functional teams and drive remediation efforts. These skills ensure vulnerabilities are identified, prioritized, and resolved efficiently, reducing organizational risk and ensuring compliance.

What is the difference between Vulnerability Management Project Manager vs Vulnerability Analyst?

AspectVulnerability Management Project ManagerVulnerability Analyst
CertificationsCompTIA Security+, PMP, CISSP (preferred)CompTIA Security+, GIAC Security Essentials (GSEC)
Work EnvironmentOversees projects, coordinates teams, manages timelinesPerforms vulnerability assessments, analyzes security data
Industry UsageUsed in cybersecurity teams across various industriesCommonly found in security operations centers (SOCs)

The Vulnerability Management Project Manager focuses on leading and coordinating vulnerability management projects, ensuring timely remediation. In contrast, the Vulnerability Analyst conducts technical assessments and analyzes vulnerabilities. Both roles require cybersecurity certifications and work within similar environments, but their responsibilities differ in scope and focus.

What cities in California are hiring for Vulnerability Management Project Manager jobs?

Cities in California with the most Vulnerability Management Project Manager job openings:

Infographic showing various Vulnerability Management Project Manager job openings in California as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 14% Part Time, 2% Temporary, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution.

Director/Sr Director, Product Management, Risk-Based Vulnerability Mgmt (RBVM)

Foster City, CA • On-site

Qualys
Network Security • 1 - 5K employees

$266K - $278K/yr

Other

Re-posted 7 days ago


Job description

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

Job Description: Director/Sr Director of Product Management - RBVM, ASM, CTEM - Risk Operation Center (ROC)

Date posted: April 2026

About the job

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!
Director/Sr Director of Product Management - RBVM, CTEM, ASM - Risk Operation Center (ROC)

Location: Foster City, CA, USA
Organization: Product GTM & SME
Reports To: SVP of Product Management

Role Overview

Qualys is seeking a Director / Sr. Director of Product Management to lead its flagship Risk-Based Vulnerability Management (RBVM) product powered by Qualys VMDR and drive the evolution toward Continuous Threat Exposure Management (CTEM) via Qualys ETM.

This leader will own the end-to-end product strategy, execution, and business performance of VMDR, serving 8,000+ global customers, while driving the transition from vulnerability management risk-based prioritization autonomous remediation CTEM platform adoption.

You will lead a team of 5+ product managers, partner with engineering, GTM, and field teams, and directly influence revenue growth, customer retention, and platform expansion.

What You Will Be Doing

Product Ownership: VMDR (RBVM)

This role sits at the intersection of VMDR (execution) ETM (risk platform), part of ROC (Risk Operation Center)

What Makes This Role Unique

  • Own Qualys' flagship product (VMDR) used by thousands of enterprises
  • Drive transition from VM CTEM platform leadership
  • Build Agentic AI-powered security workflows
  • Direct impact on revenue, growth, and company strategy
  • Lead the next evolution of cybersecurity: autonomous risk reduction

Strategic Mandate (What You'll Really Be Doing)

This role is fundamentally about:

  • Turning VMDR into the front door of Qualys platform growth
  • Using AI + workflows to drive customer expansion into ETM
  • Building the industry's first autonomous RemOps + CTEM platform

Key Responsibilities

Product Leadership - Own VMDR as a Business (P&L Mindset)

  • Own product strategy, roadmap, and execution for VMDR
  • Lead and mentor a team of 5+ Product Managers
  • Drive innovation across:
    • vulnerability prioritization (RBVM)
    • remediation workflows
    • asset-risk correlation
    • Deliver features that reduce MTTR and improve risk reduction outcomes

Business Ownership (Revenue + Growth)

Own end-to-end business metrics:

  • ARR / revenue growth for VMDR product line
  • Customer renewals and retention
  • Cross-sell and upsell into:
    • ETM
    • CSAM
    • Patch / Remediation solutions
  • Partner with GTM teams to:
    • Drive pipeline generation
    • Enable Sales with product positioning
    • Define pricing and packaging strategy

Customer-Centric Innovation (Short-Mid Term)

Drive customer deal-breaker capabilities including:

  • Scalable remediation workflows and automation
  • Better prioritization beyond CVSS (business context, exploitability)
  • Improved reporting, dashboards, and executive insights
  • Seamless ITSM / DevOps integrations
  • Cross-asset visibility (cloud, endpoint, identity)

Translate customer friction product wins revenue growth

Lead RBVM CTEM Evolution

  • Define roadmap to evolve VMDR into:
    • Risk-based vulnerability management (RBVM)
    • Exposure management platform
    • CTEM-aligned workflows
  • Build tight integration with:
    • CSAM (asset context)
    • ETM (risk aggregation and prioritization)

Drive VMDR "Deal Breaker" Requirements (0-18 months)

  • Identify and deliver top customer gaps blocking large deals, such as:
    • Faster prioritization accuracy (TruRisk improvements)
    • Better remediation workflows (ownership, SLA tracking)
    • Reporting and executive dashboards
    • Scalable performance for large enterprises
  • Partner with field (SEs, TAMs) to capture:
    • Competitive losses
    • Renewal risks
    • Enterprise feature gaps

Design Agentic AI Workflows (Next-Gen Differentiation)

  • Lead innovation in Agentic AI-driven vulnerability remediation, including:
    • Intelligent prioritization agents (what to fix first)
    • Remediation planning agents (patch vs mitigate vs isolate)
    • Workflow orchestration agents (who should fix it)
    • Autonomous nudges and recommendations

Success Metrics

  • VMDR revenue growth and market share
  • ETM attach rate (VMDR ETM conversion)
  • Customer retention and renewal rates
  • MTTR reduction across customer base
  • Adoption of new AI-driven features
  • Pipeline contribution and deal acceleration

Experience required

Experience working with platforms like Qualys and competitive vendor landscape focusing on RBVM, CTEM, AppSec, ASPM, CNAPP etc.

  • 10-15+ years in Product Management (cybersecurity preferred)
  • Deep expertise in:
    • Vulnerability Management
    • Risk-Based VM (RBVM)
    • Exposure Management / CTEM
  • Proven experience owning large-scale enterprise products
  • Strong understanding of:
    • cloud, endpoint, identity, and application security
  • Experience working with:
    • CISOs, CIOs, and security teams

Preferred

  • Experience building AI/ML-driven security products
  • Knowledge of:
    • attack surface management
    • remediation workflows
    • ITSM / DevOps integrations
  • Track record of:
    • scaling products from platform ecosystem
    • driving upsell / cross-sell motions

Product Context

Qualys VMDR

  • Unified platform to discover, assess, prioritize, and remediate vulnerabilities across hybrid environments
  • AI-driven prioritization and integrated patch workflows
  • Core revenue engine and entry point for Qualys customers

Qualys CSAM

  • Continuous asset discovery across IT, cloud, containers, identities
  • Provides business context and asset criticality for risk prioritization

Qualys ETM

  • Aggregates risk signals across Qualys and third-party tools
  • Delivers unified risk scoring, prioritization, and remediation orchestration

***************************************************************************************************************

The salary range for this position is $210,000 - $240,000 per year. Final compensation will be determined based on several factors, including but not limited to skills, relevant experience, and work location. Please note this range reflects base salary and does not include incentive compensation or potential equity grants. We also offer a comprehensive and highly competitive benefits package.

Qualys is an Equal Opportunity Employer, please see our EEO policy.