Continuous Threat and Exposure Management (CTEM) The position transforms legacy, siloed security functions (e.g., vulnerability management, attack surface management, application security) into a ...
Continuous Threat and Exposure Management (CTEM) The position transforms legacy, siloed security functions (e.g., vulnerability management, attack surface management, application security) into a ...
AVP of Information Technology
Dover, DE · On-site
$124K - $156K/yr
Experience with SIEM tools, multi-factor authentication (MFA) deployment, and vulnerability management Experience & Leadership * Management: At least 5 years of experience leading multi-disciplinary ...
AVP of Information Technology
Dover, DE · On-site
$124K - $156K/yr
Experience with SIEM tools, multi-factor authentication (MFA) deployment, and vulnerability management Experience & Leadership * Management: At least 5 years of experience leading multi-disciplinary ...
Continuous Threat and Exposure Management (CTEM) The position transforms legacy, siloed security functions (e.g., vulnerability management, attack surface management, application security) into a ...
Continuous Threat and Exposure Management (CTEM) The position transforms legacy, siloed security functions (e.g., vulnerability management, attack surface management, application security) into a ...
Assess the maturity and effectiveness of cybersecurity governance, incident response, threat management, and vulnerability management programs from an internal audit perspective. * Lead audits and ...
Assess the maturity and effectiveness of cybersecurity governance, incident response, threat management, and vulnerability management programs from an internal audit perspective. * Lead audits and ...
Continuous Threat and Exposure Management (CTEM) The position transforms legacy, siloed security functions (e.g., vulnerability management, attack surface management, application security) into a ...
Continuous Threat and Exposure Management (CTEM) The position transforms legacy, siloed security functions (e.g., vulnerability management, attack surface management, application security) into a ...
Assess the maturity and effectiveness of cybersecurity governance, incident response, threat management, and vulnerability management programs from an internal audit perspective. * Lead audits and ...
Assess the maturity and effectiveness of cybersecurity governance, incident response, threat management, and vulnerability management programs from an internal audit perspective. * Lead audits and ...
Senior ServiceNow Architect
$70 - $80/hr
The role requires deep architectural expertise across CMDB, ITOM, ITSM, IRM, Vulnerability Response, and overall platform health, ensuring scalable, secure, and high-performing ServiceNow solutions ...
Quick apply
Senior ServiceNow Architect
$70 - $80/hr
The role requires deep architectural expertise across CMDB, ITOM, ITSM, IRM, Vulnerability Response, and overall platform health, ensuring scalable, secure, and high-performing ServiceNow solutions ...
Senior ServiceNow Architect
Bellefonte, DE · On-site
$70 - $80/hr
The role requires deep architectural expertise across CMDB, ITOM, ITSM, IRM, Vulnerability Response, and overall platform health, ensuring scalable, secure, and high-performing ServiceNow solutions ...
Senior ServiceNow Architect
Bellefonte, DE · On-site
$70 - $80/hr
The role requires deep architectural expertise across CMDB, ITOM, ITSM, IRM, Vulnerability Response, and overall platform health, ensuring scalable, secure, and high-performing ServiceNow solutions ...
Lead Java Platform Engineer (Payments Publish) - Senior Vice President
New Castle, DE · On-site
$156 - $234.24/hr
... vulnerability assessments, and secure design reviews. * Agile at Scale: Experience with Agile/SAFe delivery at the program level, including PI planning, cross‑team dependency management, and ...
Lead Java Platform Engineer (Payments Publish) - Senior Vice President
New Castle, DE · On-site
$156 - $234.24/hr
... vulnerability assessments, and secure design reviews. * Agile at Scale: Experience with Agile/SAFe delivery at the program level, including PI planning, cross‑team dependency management, and ...
Lead, Service Management
Dover, DE · On-site
$12.75 - $16.75/hr
Lead, Service Management Descriptor: This role aligns to industry level titles such as Lead Service ... Keep vulnerability remediation, patching, and hardening on track. * Make risk-acceptance calls ...
Lead, Service Management
Dover, DE · On-site
$12.75 - $16.75/hr
Lead, Service Management Descriptor: This role aligns to industry level titles such as Lead Service ... Keep vulnerability remediation, patching, and hardening on track. * Make risk-acceptance calls ...
Community Health Worker - Bilingual
$18.50 - $24.25/hr
... Vulnerability Index. * CHWs will support the public health response to COVID-19 among priority ... Coordinate with clinical care teams, to support, and follow-up/case-manage/track patient/client ...
Community Health Worker - Bilingual
$18.50 - $24.25/hr
... Vulnerability Index. * CHWs will support the public health response to COVID-19 among priority ... Coordinate with clinical care teams, to support, and follow-up/case-manage/track patient/client ...
Java AWS/ Terraform Developer
Wilmington, DE · On-site
$49.50 - $64/hr
... Management Chef Ansible We advocate cloud platform security and hence you should have experience ... vulnerability scanning A good understanding of distributed systems and microservices Previous JPMC ...
Java AWS/ Terraform Developer
Wilmington, DE · On-site
$49.50 - $64/hr
... Management Chef Ansible We advocate cloud platform security and hence you should have experience ... vulnerability scanning A good understanding of distributed systems and microservices Previous JPMC ...
Business Process Red Team Operator
$59K - $79K/yr
Perform and manage hands-on offensive security activities leveraging social engineering skillsets ... Windows/ Linux/Unix/Mac operating systems as well as software vulnerability and exploitation ...
Business Process Red Team Operator
$59K - $79K/yr
Perform and manage hands-on offensive security activities leveraging social engineering skillsets ... Windows/ Linux/Unix/Mac operating systems as well as software vulnerability and exploitation ...
Business Process Red Team Operator
Wilmington, DE · On-site
$156K - $260K/yr
Perform and manage hands-on offensive security activities leveraging social engineering skillsets ... Windows/ Linux/Unix/Mac operating systems as well as software vulnerability and exploitation ...
Business Process Red Team Operator
Wilmington, DE · On-site
$156K - $260K/yr
Perform and manage hands-on offensive security activities leveraging social engineering skillsets ... Windows/ Linux/Unix/Mac operating systems as well as software vulnerability and exploitation ...
Business Process Red Team Operator
$156K - $260K/yr
Perform and manage hands-on offensive security activities leveraging social engineering skillsets ... Windows/ Linux/Unix/Mac operating systems as well as software vulnerability and exploitation ...
Business Process Red Team Operator
$156K - $260K/yr
Perform and manage hands-on offensive security activities leveraging social engineering skillsets ... Windows/ Linux/Unix/Mac operating systems as well as software vulnerability and exploitation ...
Business Process Red Team Operator
Wilmington, DE · On-site
$59K - $79K/yr
Perform and manage hands-on offensive security activities leveraging social engineering skillsets ... Windows/ Linux/Unix/Mac operating systems as well as software vulnerability and exploitation ...
Business Process Red Team Operator
Wilmington, DE · On-site
$59K - $79K/yr
Perform and manage hands-on offensive security activities leveraging social engineering skillsets ... Windows/ Linux/Unix/Mac operating systems as well as software vulnerability and exploitation ...
DevOps Engineer
Newark, DE · On-site
$51.50 - $70.75/hr
Identifying and deploying cybersecurity measures by continuously performing vulnerability assessment and risk management * Incidence management and root cause analysis * Coordination and ...
DevOps Engineer
Newark, DE · On-site
$51.50 - $70.75/hr
Identifying and deploying cybersecurity measures by continuously performing vulnerability assessment and risk management * Incidence management and root cause analysis * Coordination and ...
Information Assurance Officer
Dover, DE · On-site +1
$140K - $150K/yr
Support Vulnerability Program Management including scanning and remediation coordination * Support oversight of Lab Linux applications, research and scripting * GOTS/COTS compliance support and ...
Information Assurance Officer
Dover, DE · On-site +1
$140K - $150K/yr
Support Vulnerability Program Management including scanning and remediation coordination * Support oversight of Lab Linux applications, research and scripting * GOTS/COTS compliance support and ...
Sr. Systems Administrator
Newark, DE · On-site
$84K - $113K/yr
... e professional to manage and support our Windows, Linux, Active Directory, virtualization ... patching, vulnerability remediation, and disaster recovery capabilities • Implement ...
Sr. Systems Administrator
Newark, DE · On-site
$84K - $113K/yr
... e professional to manage and support our Windows, Linux, Active Directory, virtualization ... patching, vulnerability remediation, and disaster recovery capabilities • Implement ...
Sr Lead Security Engineer
$111K - $152K/yr
... of vulnerability * Be responsible for triaging based on risk assessments of various threats and managing resources to cover impact of disruptive events * Adds to team culture of diversity ...
Sr Lead Security Engineer
$111K - $152K/yr
... of vulnerability * Be responsible for triaging based on risk assessments of various threats and managing resources to cover impact of disruptive events * Adds to team culture of diversity ...
Vulnerability Management information
What are the common challenges faced in a vulnerability management role?
Professionals in Vulnerability Management often encounter challenges such as rapidly evolving threat landscapes, prioritizing remediation efforts among numerous vulnerabilities, and ensuring continuous communication between technical and non-technical stakeholders. They may also need to adapt to changing regulatory requirements and work within tight deadlines to protect the organization from emerging risks. As part of this role, you'll collaborate regularly with IT, security, and business teams to ensure remediation steps are effectively implemented. Continuous learning and adaptability are important, as technologies and attack vectors change frequently in this field. Being proactive and detail-oriented will help you address these challenges and advance your career in cybersecurity.
What does a vulnerability management do?
What are the key skills and qualifications needed to thrive in a vulnerability management position?
To thrive in Vulnerability Management, you need a strong understanding of cybersecurity principles, network protocols, and risk assessment, typically supported by a relevant degree and experience in information security. Familiarity with vulnerability scanning tools (such as Nessus or Qualys), security frameworks, and industry certifications like CISSP or CompTIA Security+ is highly valued. Exceptional analytical thinking, communication skills, and an ability to work collaboratively across IT and business teams help professionals excel in this field. These competencies are crucial to effectively identifying, prioritizing, and mitigating security risks in dynamic organizational environments.
Is vulnerability management a good career?
What is vulnerability management?
A Vulnerability Management job involves identifying, assessing, prioritizing, and mitigating security vulnerabilities in an organization's systems, networks, and applications. Professionals in this role use tools like vulnerability scanners and threat intelligence to detect weaknesses and coordinate remediation efforts with IT and security teams. They also establish policies, monitor security risks, and ensure compliance with industry standards. The goal is to reduce the organization's exposure to cyber threats and improve overall security posture.

Job description
"Thoughtful Minds | Empowering Possibilities"
W. R. Berkley Corporation is comprised of 60+ businesses alongside Berkley Technology Services (BTS) and other shared services groups.
Here at Berkley Technology Services, the core of our success is our people. Our teams bring their own unique perspective and experiences which enables us to translate the needs of our business to deliver adaptable, secure solutions while providing an unmatched user-focused experience.
Our tagline "Thoughtful Minds | Empowering Possibilities" was crafted with our own teams in mind. At BTS, our teams thrive in Berkley's decentralized model - leveraging the power of being part of a long standing, heritage brand with extensive expertise while innovation and being entrepreneurial is encouraged.
Internally, we operate as a relatively flat organization valuing communication and feedback. We pride ourselves in an open-door policy where no one is treated differently based on title, fostering a culture of trust, transparency, and engagement.
Mission (what we stand for): We believe in the value of every voice, translate needs into capabilities, and secure the future of Berkley.
Vision (where we're going): Be the foundation of Berkley through adaptable solutions, resilient environments, and an unmatched experience.
Come join us as we push forward into the future of industry leading technological solutions.
The Company is an equal employment opportunity employer.
Responsibilities
The SVP, Head of Security Technology, leads the modernization and delivery of the enterprise's core cybersecurity technology capabilities through an AI-enabled, automation-first, engineering-led model. This role reports to the CISO.
This role is accountable for evolving and integrating:
- Security Architecture
- Security Engineering
- Identity and Access Management (IAM)
- Continuous Threat and Exposure Management (CTEM)
The position transforms legacy, siloed security functions (e.g., vulnerability management, attack surface management, application security) into a scalable, intelligence-driven security ecosystem that:
- Reduces enterprise risk through engineering and automation
- Embeds security into enterprise architecture and technology platforms
- Strengthens identity lifecycle governance and compliance
- Enables continuous, risk-based exposure management
- Improves efficiency, control effectiveness, and compliance readiness
- Drives alignment between cybersecurity capabilities and business risk priorities, ensuring security investments directly support enterprise resilience, customer trust, and growth objectives
Responsibilities
Report to the CISO and lead the strategic execution across a team of security directors, managers, architects, engineers and analysts across multiple security technology disciplines.
Security Architecture
- Define enterprise security architecture strategy, standards, and roadmaps
- Embed secure-by-design principles across cloud, applications, data, and AI
- Establish reusable design patterns and reduce exception-based approvals
- Integrate security into transformation and modernization efforts
- Lead Zero Trust security architecture strategy and adoption across identity, network, application, and data layers
- Establish reference architectures for multi-cloud and hybrid environments, including CNAPP, CIEM, and data protection controls
Security Engineering
- Lead engineering and lifecycle management of security platforms and controls
- Establish automation-first operations (API, orchestration, policy-as-code)
- Standardize tooling and reduce manual processes through automation
- Improve platform resilience, telemetry, and service performance
- Transition to a product and platform-based security engineering model with defined service ownership, SLAs, and performance metrics
- Drive rationalization of security tools and vendors to reduce cost and complexity while improving capability coverage
Identity and Access Management (IAM) - User Administrative Lifecycle Scope
- Lead and own overarching IAM strategy and lifecycle governance, including:
- Provisioning (joiners), Access changes (movers), De-provisioning (leavers)
- Enhance user access reviews and certifications
- Implement, enhance and automate segregation of duties (SoD) monitoring and governance
- Design and implement role and entitlement management capabilities
- Enable access-related compliance and audit readiness in preparation for continuous control monitoring and assessment in alignment with Governance Risk and Control Function
- Ensure least privilege, timely access removal, and reduction of orphaned accounts
- Integrate IAM with HR, applications, and enterprise platforms
- Enhance privileged access management and management of non-human identities in preparation for advanced agentic AI capabilities
- Advance privileged access, machine identity, and non-human identity security in support of automation, cloud, and AI use cases
- Implement identity-centric Zero Trust controls and continuous authentication models
Continuous Threat and Exposure Management (CTEM)
- Transform vulnerability, attack surface, and application security into a unified CTEM function
- Implement continuous, threat-informed prioritization of exposures
- Align findings to asset criticality and business risk
- Improve remediation effectiveness and reduce exploitable attack paths
- Enhance asset visibility, ownership clarity, and dependency mapping
- Partner with Security Operations and Security Incident and Response functions to coordinate a unified approach across teams
- Establish attack path analysis and exploitability-based risk prioritization to reduce material exposure
- Define measurable outcomes such as reduction in attack surface, time-to-remediation, and control effectiveness
AI and Automation Enablement
- Deploy AI and analytics to improve prioritization and decision-making
- Automate repetitive security processes and control validation
- Enhance reporting, telemetry, and audit evidence generation
- Partner with Head of Security AI to establish secure AI lifecycle practices, including model governance, data protection, prompt security, and third-party AI risk management
- Partner with Head of Security Operations to leverage AI to enhance threat detection, anomaly identification, and predictive risk analytics
DevSecOps and Secure Development
- Embed security into the software development lifecycle (SDLC), CI/CD pipelines, and developer workflows
- Partner with engineering teams to implement scalable DevSecOps practices and developer-friendly security tooling
Operating Model, Leadership and Other Requirements
- Establish a global operating model with clear accountability, service ownership, and capability maturity roadmaps
- Develop business cases tied to measurable risk reduction, operational efficiency, and cost optimization
- Partner with executive leadership and provide board-level reporting on security posture, risk trends, and investment impact
- Technology first leader with very strong interpersonal skills with demonstrated ability to build and maintain strong relationships and partnerships vertically and horizontally across a mix of business, technology, legal, HR, risk and audit leaders and practitioners
- Establish a product- and platform-based security technology operating model
- Define core requirements that evidence demonstrable risk reduction and can be measured using KPIs/KRIs in conjunction with the metrics and analytics program
- Drive roadmap, investment prioritization, and tool rationalization
- Drive budgetary discipline through management of finances, including the build of defendable business cases
- Lead and develop high-performing, multi-disciplinary teams in a positive and respectful capacity leading to high engagement across all disciplines
- Organically improve the security posture of the organization by ensuring the incorporation of secure principles into every phase of the design, development, deployment, and operation of systems and solutions
- Assess current environment and design a target state architecture with all accompanying diagrams and documentation as required by architecture teams
- Provide top-level support as needed on security and operational related issues
- Represent information security interests on various project teams and special assignments as directed
- Active in a continuous improvement of the existing process, methodologies, technologies and practices
- Provide top-level on-call support as required for this type of role, which is factored into the compensation for this role
Resilience and Risk Integration
- Partner with Security Operations and Incident Response to improve cyber resilience, recovery readiness, and crisis response integration
- Ensure alignment with enterprise risk management and regulatory expectations through continuous control monitoring
Qualifications
- 15+ years' experience in a cybersecurity role with at least 5 as head of senior most security architect
- Previous and progressive experience in a technical security leadership position.
- Demonstrated experience modernizing security organizations (tool consolidation, automation, operating model redesign)
- Strong expertise in cloud-native security, Zero Trust, IAM, and CTEM practices
- Experience integrating cybersecurity with AI/ML technologies and governance frameworks
- Strong strategic thinking and decision-making capabilities
- Experience managing budgets, vendors, and large-scale programs
- Track record of delivering measurable improvements in risk reduction, efficiency, and security posture
- Disciplined thinker with structured approach to security architecture and strategic planning
- Inherent intellectual capability and curiosity to learn complex processes.
- Proven thought leadership, strategic thinking and decision-making.
- Must have strong analytical and problem-solving skills with the capability to identify solutions to unusual and complex problems.
- CISSP certification is strongly preferred
- Direct security related AI, networking, infrastructure, cloud, operating system, development, cloud, database experience is required
- Must be able to demonstrate proficiency in a wide range of security technologies, embedded security, and network platforms - in a global institution
- Ability to balance multiple priorities in high pressure situations
- Project, portfolio and resource management experience is required
- Must be willing to travel (Domestic and International) as required, but not to exceed 30-40%
Education Requirement:
Bachelors Degree in Computer Science, Information Technology, Information Systems, or a related discipline. Equivalent experience and/or alternative qualifications will be considered.
Additional Company Details
We do not accept unsolicited resumes from third party recruiting agencies or firms.
Additional Requirements
Location and Travel:
• Primary location Wilmington, DE.
• Travel: Domestic and international travel up to 30-40% as required.
Sponsorship Details
Sponsorship not Offered for this Role