Position Overview As a Senior Manager, Vulnerability Management and Application Security, you will lead CarMax's enterprise vulnerability management and application security programs and serve as a ...
Position Overview As a Senior Manager, Vulnerability Management and Application Security, you will lead CarMax's enterprise vulnerability management and application security programs and serve as a ...
Senior Manager, Vulnerability Management and Application Security
Richmond, VA · On-site
$144K - $231K/yr
Position Overview As a Senior Manager, Vulnerability Management and Application Security, you will lead CarMax's enterprise vulnerability management and application security programs and serve as a ...
Senior Manager, Vulnerability Management and Application Security
Richmond, VA · On-site
$144K - $231K/yr
Position Overview As a Senior Manager, Vulnerability Management and Application Security, you will lead CarMax's enterprise vulnerability management and application security programs and serve as a ...
Senior Manager, Vulnerability Management and Application Security As a Senior Manager, Vulnerability Management and Application Security, you will lead CarMax's enterprise vulnerability management ...
New
Senior Manager, Vulnerability Management and Application Security As a Senior Manager, Vulnerability Management and Application Security, you will lead CarMax's enterprise vulnerability management ...
New
Position Overview As a Senior Manager, Vulnerability Management and Application Security, you will lead CarMax's enterprise vulnerability management and application security programs and serve as a ...
Position Overview As a Senior Manager, Vulnerability Management and Application Security, you will lead CarMax's enterprise vulnerability management and application security programs and serve as a ...
SOC-Vulnerability Management AESS Technician - Junior
Fairfax, VA · On-site
$89K - $134K/yr
Position Summary ECS is seeking a SOC-Vulnerability Management AESS Technician - Junior to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS ...
SOC-Vulnerability Management AESS Technician - Junior
Fairfax, VA · On-site
$89K - $134K/yr
Position Summary ECS is seeking a SOC-Vulnerability Management AESS Technician - Junior to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS ...
The Lead will manage a comprehensive vulnerability management program for The Department of U.S. Customs and Border Protection (CBP). The Lead will direct a team of analysts responsible for ...
The Lead will manage a comprehensive vulnerability management program for The Department of U.S. Customs and Border Protection (CBP). The Lead will direct a team of analysts responsible for ...
Sr. Manager, Vulnerability Management & Application at Henrico, Virginia
Henrico, VA · On-site
$53.25 - $71.25/hr
Senior Manager, Vulnerability Management and Application Security As a Senior Manager, Vulnerability Management and Application Security, you will lead CarMax's enterprise vulnerability management ...
New
Sr. Manager, Vulnerability Management & Application at Henrico, Virginia
Henrico, VA · On-site
$53.25 - $71.25/hr
Senior Manager, Vulnerability Management and Application Security As a Senior Manager, Vulnerability Management and Application Security, you will lead CarMax's enterprise vulnerability management ...
New
The Lead will manage a comprehensive vulnerability management program for The Department of U.S. Customs and Border Protection (CBP). The Lead will direct a team of analysts responsible for ...
The Lead will manage a comprehensive vulnerability management program for The Department of U.S. Customs and Border Protection (CBP). The Lead will direct a team of analysts responsible for ...
SOC Vulnerability Management AESS Lead - Senior
Fairfax, VA · On-site
$105K - $143K/yr
Position Summary ECS is seeking a SOC Vulnerability Management AESS Lead - Senior to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS) program.
SOC Vulnerability Management AESS Lead - Senior
Fairfax, VA · On-site
$105K - $143K/yr
Position Summary ECS is seeking a SOC Vulnerability Management AESS Lead - Senior to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS) program.
ECS is seeking a SOC-Vulnerability Management AESS Technician - Junior to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support program in Fairfax, VA. This ...
ECS is seeking a SOC-Vulnerability Management AESS Technician - Junior to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support program in Fairfax, VA. This ...
Vulnerability Analyst, Senior
$104K - $166K/yr
Establish and govern enterprise vulnerability management strategy: scanning methodologies, validation protocols, and assessment standards aligned with RMF, DoD, and Army requirements. * Oversee ...
Vulnerability Analyst, Senior
$104K - $166K/yr
Establish and govern enterprise vulnerability management strategy: scanning methodologies, validation protocols, and assessment standards aligned with RMF, DoD, and Army requirements. * Oversee ...
Vulnerability Analyst, Senior
Herndon, VA · On-site
$104K - $166K/yr
Establish and govern enterprise vulnerability management strategy: scanning methodologies, validation protocols, and assessment standards aligned with RMF, DoD, and Army requirements. * Oversee ...
Vulnerability Analyst, Senior
Herndon, VA · On-site
$104K - $166K/yr
Establish and govern enterprise vulnerability management strategy: scanning methodologies, validation protocols, and assessment standards aligned with RMF, DoD, and Army requirements. * Oversee ...
Vulnerability Analyst, Senior
Herndon, VA · On-site
$104K - $166K/yr
Establish and govern enterprise vulnerability management strategy: scanning methodologies, validation protocols, and assessment standards aligned with RMF, DoD, and Army requirements. * Oversee ...
Vulnerability Analyst, Senior
Herndon, VA · On-site
$104K - $166K/yr
Establish and govern enterprise vulnerability management strategy: scanning methodologies, validation protocols, and assessment standards aligned with RMF, DoD, and Army requirements. * Oversee ...
Summary Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring) Oakton, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you ...
Summary Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring) Oakton, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you ...
Overview Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring) Oakton, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you ...
Overview Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring) Oakton, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you ...
Position Summary ECS is seeking a SOC-Vulnerability Management AESS Technician - Journeyman to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS ...
Position Summary ECS is seeking a SOC-Vulnerability Management AESS Technician - Journeyman to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS ...
Req ID: 40432 Summary Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring) Oakton, VA Are you ready to enhance your skills and build your career in a rapidly evolving business ...
Req ID: 40432 Summary Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring) Oakton, VA Are you ready to enhance your skills and build your career in a rapidly evolving business ...
Overview Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring) Oakton, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you ...
Overview Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring) Oakton, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you ...
RiVidium is seeking a Vulnerability Management Analyst to support our planned MODES III team supporting Military Community and Family Policy (MC&FP). This role supports IT, Cybersecurity, and Data ...
RiVidium is seeking a Vulnerability Management Analyst to support our planned MODES III team supporting Military Community and Family Policy (MC&FP). This role supports IT, Cybersecurity, and Data ...
Summary Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring) Oakton, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you ...
Summary Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring) Oakton, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you ...
Vulnerability Manager information
See Virginia salary details
$9.53 - $13.54
1% of jobs
$16.45 is the 25th percentile. Wages below this are outliers.
$13.54 - $17.55
33% of jobs
The median wage is $18.68 / hr.
$17.55 - $21.56
56% of jobs
$21.56 - $25.57
6% of jobs
$25.57 - $29.57
0% of jobs
$29.57 - $33.58
1% of jobs
$33.58 - $37.59
0% of jobs
$37.59 - $41.60
2% of jobs
$41.60 - $45.61
0% of jobs
$45.61 - $49.61
0% of jobs
$49.61 - $53.62
0% of jobs
$9
$21
$53
How much do vulnerability manager jobs pay per hour?
What are the key skills and qualifications needed to thrive as a Vulnerability Manager, and why are they important?
What is the difference between Vulnerability Manager vs Security Analyst?
| Aspect | Vulnerability Manager | Security Analyst |
|---|---|---|
| Certifications | Certified Vulnerability Assessor (CVA), CISSP, CEH | CISSP, Security+, CEH |
| Work Environment | Oversees vulnerability assessments, manages teams, develops strategies | Monitors security systems, analyzes threats, responds to incidents |
| Employer & Industry Usage | Used in cybersecurity teams across industries to manage vulnerabilities | Commonly employed in security operations centers (SOCs) to analyze threats |
While both roles focus on cybersecurity, Vulnerability Managers primarily oversee vulnerability assessments and strategy, whereas Security Analysts focus on monitoring and incident response. Both roles require relevant certifications and work within cybersecurity teams, but their daily responsibilities and focus areas differ.
What does a Vulnerability Manager do?
What are some common challenges faced by Vulnerability Managers when prioritizing remediation efforts?

Full-time
PTO
Posted 11 days ago
CarMax rating
8.0
Based on 368 frontline employees who took The Breakroom Quiz
27th of 719 rated retailers
Job description
CarMax, the way your career should be!
Position Overview
As a Senior Manager, Vulnerability Management and Application Security, you will lead CarMax's enterprise vulnerability management and application security programs and serve as a trusted subject matter expert responsible for strengthening the organization's security posture. You will mentor and guide a high-performing team, streamline processes, optimize program operations, and deliver actionable insights that influence decision-making across all levels, including executive leadership. This role is ideal for a collaborative, results-driven leader with a passion for building effective programs and improving the security, resilience, and reliability of technology environments and software delivery practices.
Why CarMax?
At CarMax, we are the nation's largest retailer of used cars with stores from coast to coast, and we are still growing. We're rethinking the way people buy cars - and it's our associates that help us do just that. We believe work should feel meaningful and rewarding, with opportunities to make an impact every day. This is where innovation meets passion - be inspired and supported to take us to the future.
Team Overview
The Vulnerability Management and Application Security team guides enterprise strategy for identifying, analyzing, and prioritizing remediation of risks across CarMax's systems, infrastructure, and applications. As the Senior Manager, you will shape program strategy, strengthen integration with cybersecurity and engineering partners, and enable teams to build and operate secure technology through clear communication, effective governance, thorough reporting, and trusted leadership.
Role Responsibilities
Oversee and continuously improve the enterprise vulnerability management and application security programs, ensuring effective alignment of processes, tools, and assessments.
Develop and manage program roadmaps, budgets, and priorities for security assessments across infrastructure, networks, cloud services, and applications.
Create and deliver executive-ready reporting with clear documentation, risk insights, program metrics, and prioritized mitigation recommendations.
Define and maintain vulnerability management and application security standards, SLAs, and governance practices in partnership with cybersecurity and technology leaders.
Lead risk-based remediation prioritization and ensure consistent progress across infrastructure, engineering, and product teams and partners.
Coordinate and communicate responses to emerging threats, zero-day vulnerabilities, and critical application security findings to drive timely remediation.
Lead the application security program, including secure development lifecycle practices, application security testing, and risk-based remediation strategies.
Partner with engineering, architecture, and product teams to embed security requirements, threat modeling, code scanning, and security reviews into the software development lifecycle - foster a culture of security.
Mature application security capabilities such as SAST, DAST, software composition analysis, secrets detection, and security testing for internally developed and third-party applications.
Provide guidance on secure coding practices, common vulnerabilities, and remediation approaches.
Adapt to and apply technology innovation, including AI, to the role and program overall.
Adapt the team and programs to ever-changing threat and regulatory landscape.
Required Qualifications
8+ years of cybersecurity experience with emphasis on vulnerability management, application security, risk analysis, and security assessment practices.
5+ years of experience designing, implementing, or supporting secure information systems and application security practices.
3+ years in a security leadership or management role guiding teams or programs.
One or more certifications such as CISA, CISM, CEH, CISSP, or SANS.
Experience with enterprise security technologies and application security tooling such as vulnerability scanners, SAST, DAST, software composition analysis, SIEM platforms, and network devices - firewalls, IDS/IPS, routers, and switches.
Strong ability to analyze complex security findings, communicate risk clearly to diverse audiences, and drive remediation across infrastructure, engineering, and business teams or partners.
Bachelor's Degree in a technology-related field or equivalent experience in Cybersecurity and Risk Management, preferred.
Work Location and Arrangement:This role will bebasedout oftheCarMax Home Office in Richmond, VAand Associates will work onsite 4 days per week.
Work Authorization: Applicants must be currently authorized to work in the United States on a full-time basis.Sponsorship will not be considered for this specific role.
About CarMax
At CarMax, we revolutionized the used car buying experience over 30 years ago by introducing transparency and integrity into the process. Our commitment to customer experience, innovation, and community has made us the nation's largest used car retailer. With over 250 store locations and over 30,000 associates, we are proud to have been recognized as one of the Fortune 100 Best Companies to Work For and are committed to helping our communities thrive.
As an associate, you are part of an innovative movement to empower the modern customer and drive progress. Your work fuels change-sparking ideas, overcoming challenges, and shaping what's next. Join us in creating a better future- for our company, our customers, and the communities we call home.
CarMax is an equal opportunity employer, and all qualified candidates will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, protected veteran status, disability status, or any other characteristic protected by law.
The annual salary for this position is:
$144,500.00 - $231,200.00May be eligible for bonus and equity.
Benefits:
Except as otherwise required by state law, CarMax Associates are entitled to the following paid sick, vacation, and holiday time.
Associates that are considered full-time hourly or commission/incentive eligible:
- To earn up to 48 hours of sick time per year accrued on a per pay period basis and between 80 hours and 200 hours per year of vacation time after a 90 day waiting period depending on years of continuous service with the Company.
- For 8 hours of pay for each of a total of 6 paid scheduled holidays per year plus 1 floating holiday. If such an Associate does work on a scheduled holiday due to business need, they are eligible for Holiday Premium Pay.
Associates considered full-time salaried are entitled to paid time away with no specified limit as needed for sick, vacation, bereavement, jury duty, holidays, floating holiday, etc. subject to manager approval.
For more details about benefits, please visit our CarMax Benefits website.
Upon an applicant's request, CarMax will consider reasonable accommodation to complete the CarMax Job Application.
About CarMax Enterprise Services
Sourced by ZipRecruiter
Industry
Finance and insurance
Company size
10,000+ Employees
Headquarters location
Carol Stream, IL, US