The role We are seeking a Staff Vulnerability Management Engineer to lead the most complex technical work in SoFi's Vulnerability Management program. You will design and build scalable systems that ...
The role We are seeking a Staff Vulnerability Management Engineer to lead the most complex technical work in SoFi's Vulnerability Management program. You will design and build scalable systems that ...
The role We are seeking a Staff Vulnerability Management Engineer to lead the most complex technical work in SoFi's Vulnerability Management program. You will design and build scalable systems that ...
The role We are seeking a Staff Vulnerability Management Engineer to lead the most complex technical work in SoFi's Vulnerability Management program. You will design and build scalable systems that ...
Principal Technology Compliance Program Manager - Vulnerability Management
Seattle, WA ยท On-site
$141K - $211K/yr
Role Summary The Technology Compliance Program Manager Vulnerability Management is the sole subject matter expert in the technology compliance and vulnerability management domain. As an individual ...
Principal Technology Compliance Program Manager - Vulnerability Management
Seattle, WA ยท On-site
$141K - $211K/yr
Role Summary The Technology Compliance Program Manager Vulnerability Management is the sole subject matter expert in the technology compliance and vulnerability management domain. As an individual ...
The Technology Compliance Program Manager Vulnerability Management is the sole subject matter expert in the technology compliance and vulnerability management domain. As an individual contributor ...
New
The Technology Compliance Program Manager Vulnerability Management is the sole subject matter expert in the technology compliance and vulnerability management domain. As an individual contributor ...
New
We are seeking a Staff Security Engineer, Vulnerability Management to lead the evolution of our Vulnerability Management Platform. In this role, you will architect the next generation of our Risk ...
We are seeking a Staff Security Engineer, Vulnerability Management to lead the evolution of our Vulnerability Management Platform. In this role, you will architect the next generation of our Risk ...
We are seeking a Staff Security Engineer, Vulnerability Management to lead the evolution of our Vulnerability Management Platform. In this role, you will architect the next generation of our Risk ...
We are seeking a Staff Security Engineer, Vulnerability Management to lead the evolution of our Vulnerability Management Platform. In this role, you will architect the next generation of our Risk ...
Principal Technology Compliance Program Manager - Vulnerability Management
Seatac, WA ยท On-site
$141K - $211K/yr
Role Summary The Technology Compliance Program Manager Vulnerability Management is the sole subject matter expert in the technology compliance and vulnerability management domain. As an individual ...
Principal Technology Compliance Program Manager - Vulnerability Management
Seatac, WA ยท On-site
$141K - $211K/yr
Role Summary The Technology Compliance Program Manager Vulnerability Management is the sole subject matter expert in the technology compliance and vulnerability management domain. As an individual ...
Vulnerability Response Manager - Apple Information Security
Seattle, WA ยท On-site
$180 - $240/hr
Vulnerability Response Manager - Apple Information Security Austin, Texas, United States Corporate Functions Apple Information Security is seeking an experienced security engineering manager to lead ...
New
Vulnerability Response Manager - Apple Information Security
Seattle, WA ยท On-site
$180 - $240/hr
Vulnerability Response Manager - Apple Information Security Austin, Texas, United States Corporate Functions Apple Information Security is seeking an experienced security engineering manager to lead ...
New
Our Vulnerability Management team plays a pivotal role in identifying, assessing, and mitigating security risks across our entire infrastructure. We take a systemic approach to security and strive to ...
Our Vulnerability Management team plays a pivotal role in identifying, assessing, and mitigating security risks across our entire infrastructure. We take a systemic approach to security and strive to ...
Our Vulnerability Management team plays a pivotal role in identifying, assessing, and mitigating security risks across our entire infrastructure. We take a systemic approach to security and strive to ...
Our Vulnerability Management team plays a pivotal role in identifying, assessing, and mitigating security risks across our entire infrastructure. We take a systemic approach to security and strive to ...
Vulnerability Operations Engineer
Seattle, WA ยท Hybrid
$79K - $107K/yr
... Vulnerability Operations (VulnOps) practice, serving as a subject matter expert who owns the ... You will drive risk-based exposure management, mentor junior team members, and shape how Fred Hutch ...
Vulnerability Operations Engineer
Seattle, WA ยท Hybrid
$79K - $107K/yr
... Vulnerability Operations (VulnOps) practice, serving as a subject matter expert who owns the ... You will drive risk-based exposure management, mentor junior team members, and shape how Fred Hutch ...
Experience using tools such as BigFix, Microsoft Endpoint Configuration Manager, Red Hat Satellite ... Executing vulnerability and patch management tasks across infrastructure, middleware, and ...
Experience using tools such as BigFix, Microsoft Endpoint Configuration Manager, Red Hat Satellite ... Executing vulnerability and patch management tasks across infrastructure, middleware, and ...
Embark on a Mission to Fortify Amazon's Defenses as a Security Engineer II with the Vulnerability Management & Remediation Operations team! Amazon Security is seeking an experienced and innovative ...
Embark on a Mission to Fortify Amazon's Defenses as a Security Engineer II with the Vulnerability Management & Remediation Operations team! Amazon Security is seeking an experienced and innovative ...
Embark on a Mission to Fortify Amazon's Defenses as a Security Engineer II with the Vulnerability Management & Remediation Operations team! Amazon Security is seeking an experienced and innovative ...
Embark on a Mission to Fortify Amazon's Defenses as a Security Engineer II with the Vulnerability Management & Remediation Operations team! Amazon Security is seeking an experienced and innovative ...
Embark on a Mission to Fortify Amazon's Defenses as a Security Engineer II with the Vulnerability Management & Remediation Operations team! Amazon Security is seeking an experienced and innovative ...
Embark on a Mission to Fortify Amazon's Defenses as a Security Engineer II with the Vulnerability Management & Remediation Operations team! Amazon Security is seeking an experienced and innovative ...
Embark on a Mission to Fortify Amazon's Defenses as a Security Engineer II with the Vulnerability Management & Remediation Operations team! Amazon Security is seeking an experienced and innovative ...
Embark on a Mission to Fortify Amazon's Defenses as a Security Engineer II with the Vulnerability Management & Remediation Operations team! Amazon Security is seeking an experienced and innovative ...
... Vulnerability Management across a complex, hybrid technology ecosystem. This role combines deep ... This role reports directly to the hiring manager and is accountable for delivering measurable ...
... Vulnerability Management across a complex, hybrid technology ecosystem. This role combines deep ... This role reports directly to the hiring manager and is accountable for delivering measurable ...
Leading vulnerability and patch management operations across infrastructure, middleware, and applications * Prioritizing remediation activities using threat intelligence, exploitability, attack paths ...
Leading vulnerability and patch management operations across infrastructure, middleware, and applications * Prioritizing remediation activities using threat intelligence, exploitability, attack paths ...
... Vulnerability Management across a complex, hybrid technology ecosystem. This role combines deep ... This role reports directly to the hiring manager and is accountable for delivering measurable ...
... Vulnerability Management across a complex, hybrid technology ecosystem. This role combines deep ... This role reports directly to the hiring manager and is accountable for delivering measurable ...
Embark on a Mission to Fortify Amazon's Defenses as a Security Engineer II with the Vulnerability Management & Remediation Operations team! Amazon Security is seeking an experienced and innovative ...
Embark on a Mission to Fortify Amazon's Defenses as a Security Engineer II with the Vulnerability Management & Remediation Operations team! Amazon Security is seeking an experienced and innovative ...
Vulnerability Manager information
See Seattle, WA salary details
$10.94 - $15.54
1% of jobs
$18.88 is the 25th percentile. Wages below this are outliers.
$15.54 - $20.14
33% of jobs
The median wage is $21.45 / hr.
$20.14 - $24.74
56% of jobs
$24.74 - $29.35
6% of jobs
$29.35 - $33.95
0% of jobs
$33.95 - $38.55
1% of jobs
$38.55 - $43.15
0% of jobs
$43.15 - $47.75
2% of jobs
$47.75 - $52.35
0% of jobs
$52.35 - $56.95
0% of jobs
$56.95 - $61.55
0% of jobs
$10
$24
$61
How much do vulnerability manager jobs pay per hour?
What are the key skills and qualifications needed to thrive as a vulnerability manager, and why are they important?
What is the difference between Vulnerability Manager vs Security Analyst?
| Aspect | Vulnerability Manager | Security Analyst |
|---|---|---|
| Certifications | Certified Vulnerability Assessor (CVA), CISSP, CEH | CISSP, Security+, CEH |
| Work Environment | Oversees vulnerability assessments, manages teams, develops strategies | Monitors security systems, analyzes threats, responds to incidents |
| Employer & Industry Usage | Used in cybersecurity teams across industries to manage vulnerabilities | Commonly employed in security operations centers (SOCs) to analyze threats |
While both roles focus on cybersecurity, Vulnerability Managers primarily oversee vulnerability assessments and strategy, whereas Security Analysts focus on monitoring and incident response. Both roles require relevant certifications and work within cybersecurity teams, but their daily responsibilities and focus areas differ.
What does a vulnerability manager do?
What are some common challenges faced by vulnerability managers when prioritizing remediation efforts?

Job description
The role
We are seeking a Staff Vulnerability Management Engineer to lead the most complex technical work in SoFi's Vulnerability Management program. You will design and build scalable systems that identify, enrich, prioritize, route, and track vulnerabilities across applications, cloud and infrastructure, containers, software supply chains, and specialized hardware or firmware surfaces. This is a hands-on engineering role with broad technical influence: you will write production code, make architecture decisions, establish vulnerability management standards, and improve how teams understand and reduce vulnerability risk.
You will partner with Engineering, Infrastructure, SRE, Compliance, Legal, and business stakeholders to accelerate remediation while protecting engineering velocity and customer trust. You will also serve as a senior technical responder for embargoed disclosures and zero-day events, lead root-cause analysis for high-impact vulnerability incidents, and mentor engineers. The ideal candidate combines deep vulnerability management expertise with strong software engineering judgment, systems thinking, and a bias for durable, measurable outcomes.
What you'll do
- ย Lead high-complexity vulnerability management initiatives and make architecture decisions for assigned program areas, from detection and assessment through ticket routing, remediation, exception handling, and closure validation.
- Design, build, and productionize scalable triage and prioritization automation, including scanner and asset integrations, enrichment pipelines, decision logic, deduplication, ownership resolution, service-level tracking, observability, and failure recovery.
- Develop risk-based prioritization models that combine CVSS, EPSS, CISA Known Exploited Vulnerabilities, threat intelligence, asset criticality, exposure, compensating controls, business context, and compliance obligations.
- Engineer and improve vulnerability workflows across application security, cloud and infrastructure, containers and Kubernetes, open-source dependencies, secrets, software supply chain, and hardware-adjacent surfaces such as GPU, DPU/BlueField, BMC, and firmware.
- Own or materially advance software supply chain capabilities, including SBOM inventory, dependency visibility, SLSA-aligned controls, and integration of SAST, SCA, secret scanning, and container scanning into CI/CD.
- Act as a senior technical responder for critical vulnerabilities, embargoed disclosures, and zero-day events; coordinate technical assessment, containment, mitigation, patch deployment, validation, and executive communication with service owners and incident response teams.
- Partner directly with development and platform teams to define practical remediation paths and, when appropriate, review or contribute secure changes in Python, Go, JavaScript/TypeScript, or infrastructure code.
- Define technical standards for vulnerability severity, remediation service levels, exceptions, evidence, and closure criteria; ensure workflows support audit-ready reporting for applicable regulatory and compliance frameworks.
- Produce actionable metrics, dashboards, and risk insights for technical and executive audiences, with clear accountability, trend analysis, compliance posture, and execution risks.
- Lead root-cause analysis for high-impact vulnerability incidents and convert lessons learned into durable improvements to tooling, architecture, controls, and operating practices.
- Evaluate and responsibly apply AI/ML and LLM-assisted techniques to security triage and decision support, with human-in-the-loop validation, measurable quality controls, and safe failure modes.
- Build AI-assisted remediation workflows that partner with engineering teams to proactively identify, validate, and apply security patches, with appropriate testing, human oversight, rollback mechanisms, and measurable risk reduction.
- Communicate complex security tradeoffs and program risks clearly to stakeholders across Engineering, Product, Operations, Legal, Compliance, and executive leadership.
What you'll need
- Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related field, or equivalent practical experience.
- Deep expertise in vulnerability management, security engineering, and modern infrastructure, including cloud, containers, and distributed systems.
- Strong programming or scripting skills in Python, Go, Java, or similar languages, with experience building automation at scale.
- Deep knowledge of vulnerability management methods and standards, including CVSS, EPSS, CISA KEV, threat intelligence integration, asset and exposure context, remediation SLAs, exception governance, and risk-based prioritization.
- Hands-on experience with modern vulnerability and application security tooling such as Wiz, Semgrep, Snyk, Socket, Rapid7, Tenable, Checkmarx, or equivalent platforms, plus experience tuning SAST, SCA, secret scanning, container, or cloud findings.
- Experience designing end-to-end workflows that integrate scanners, asset inventories or CMDBs, ticketing systems, CI/CD platforms, data stores, dashboards, and alerting systems.
- Working knowledge of cloud-native and software supply chain environments, including AWS, GCP, or Azure; Kubernetes and containers; build systems and package managers; SBOMs; and Infrastructure as Code.
- Demonstrated ability to lead cross-functional technical initiatives, influence without direct authority, make sound decisions amid ambiguity, and drive work from concept through production operation and measurable outcomes.
- Experience mentoring senior and developing engineers and raising engineering quality through design reviews, code reviews, standards, and incident leadership.
- Strong written and verbal communication, business judgment, and the ability to explain how security choices affect engineering velocity, regulatory obligations, customer trust, and business risk.
Nice to have
- Experience managing security partnerships with hardware or software vendors, including embargoed disclosures, coordinated vulnerability disclosure, and pre-release remediation collaboration.
- Production experience with security orchestration platforms such as Tines and serverless frameworks such as AWS Lambda or Google Cloud Functions.
- Experience scaling vulnerability management in a high-growth, cloud-native environment or operating within FedRAMP, PCI DSS, SOC 2, ISO 27001, NIST, or comparable regulated environments.
About SoFi
Sourced by ZipRecruiter
Industry
Finance and insurance
Company size
1,001 - 5,000 Employees
Headquarters location
San Francisco, CA, US
Year founded
2011