The Manager, Vulnerability Management is responsible for leading the execution of vulnerability management activities to identify, assess, prioritize, and reduce security weaknesses across the ...
New
The Manager, Vulnerability Management is responsible for leading the execution of vulnerability management activities to identify, assess, prioritize, and reduce security weaknesses across the ...
New
The Manager, Vulnerability Management is responsible for leading the execution of vulnerability management activities to identify, assess, prioritize, and reduce security weaknesses across the ...
New
Director of Vulnerability Management II Our client is committed to safeguarding your valuable assets through comprehensive cybersecurity strategies. Our client is currently looking for a skilled and ...
Director of Vulnerability Management II Our client is committed to safeguarding your valuable assets through comprehensive cybersecurity strategies. Our client is currently looking for a skilled and ...
Position Summary The Vulnerability Remediation Engineer is responsible for improving the organization's security posture through the identification, prioritization, remediation, and prevention of ...
Position Summary The Vulnerability Remediation Engineer is responsible for improving the organization's security posture through the identification, prioritization, remediation, and prevention of ...
Overview Vulnerability Researcher Location:On-Site (Annapolis Junction, MD) Clearance Required:TS/SCI with Poly Do you have a passion for uncovering hidden vulnerabilities and pushing the boundaries ...
Overview Vulnerability Researcher Location:On-Site (Annapolis Junction, MD) Clearance Required:TS/SCI with Poly Do you have a passion for uncovering hidden vulnerabilities and pushing the boundaries ...
CyberLinx Solutions, LLC is seeking a Vulnerability Management Analyst to support our cybersecurity services by managing vulnerability scanning, risk prioritization, and remediation tracking across ...
CyberLinx Solutions, LLC is seeking a Vulnerability Management Analyst to support our cybersecurity services by managing vulnerability scanning, risk prioritization, and remediation tracking across ...
Position Summary The Vulnerability Remediation Engineer is responsible for improving the organization's security posture through the identification, prioritization, remediation, and prevention of ...
Position Summary The Vulnerability Remediation Engineer is responsible for improving the organization's security posture through the identification, prioritization, remediation, and prevention of ...
Washington, DC · Remote
$110K - $130K/yr
SkyePoint Decisions is seeking a Vulnerability Management Analyst to support a cybersecurity program by identifying, analyzing, tracking, and reporting security vulnerabilities across enterprise ...
Quick apply
Washington, DC · Remote
$110K - $130K/yr
SkyePoint Decisions is seeking a Vulnerability Management Analyst to support a cybersecurity program by identifying, analyzing, tracking, and reporting security vulnerabilities across enterprise ...
Description Tharros is seeking a Cyber Security Vulnerability Researcher - Intermediate to conduct research into fundamental computer and information science in support of NAWCAD Cyber Warfare ...
Description Tharros is seeking a Cyber Security Vulnerability Researcher - Intermediate to conduct research into fundamental computer and information science in support of NAWCAD Cyber Warfare ...
Company Description Vulnerability Management Analyst Location: Alpharetta, GA (3 days onsite minimum) Contract Job Summary: Stand up vulnerability management reporting and tracking for Equity Zen to ...
Quick apply
Company Description Vulnerability Management Analyst Location: Alpharetta, GA (3 days onsite minimum) Contract Job Summary: Stand up vulnerability management reporting and tracking for Equity Zen to ...
Vulnerability Management Analyst Job Location - Alpharetta, GA Duration - 11 Months Experience level - 3+ Mandatory Skills - Vulnerability Management Analyst - Vulnerability Management Analyst Key ...
Vulnerability Management Analyst Job Location - Alpharetta, GA Duration - 11 Months Experience level - 3+ Mandatory Skills - Vulnerability Management Analyst - Vulnerability Management Analyst Key ...
Alpharetta, GA · On-site
$48 - $50/hr
Vulnerability Management Analyst Location: Alpharetta, GA (3 days onsite minimum) Duration: 11 months Contract Experience Level: Intermediate (7 - 10) Job Summary: Stand up vulnerability management ...
Quick apply
Alpharetta, GA · On-site
$48 - $50/hr
Vulnerability Management Analyst Location: Alpharetta, GA (3 days onsite minimum) Duration: 11 months Contract Experience Level: Intermediate (7 - 10) Job Summary: Stand up vulnerability management ...
The Vulnerability Management Specialist is a hands-on individual contributor responsible for executing Core Specialty's vulnerability management program across endpoints, servers, cloud resources ...
The Vulnerability Management Specialist is a hands-on individual contributor responsible for executing Core Specialty's vulnerability management program across endpoints, servers, cloud resources ...
Vulnerability Management Engineer- Hybrid | Cary, NC We're a leader in data and AI. Through our software and services, we inspire customers around the world to transform data into intelligence - and ...
New
Vulnerability Management Engineer- Hybrid | Cary, NC We're a leader in data and AI. Through our software and services, we inspire customers around the world to transform data into intelligence - and ...
New
Title and Summary Principle, Vulnerability Analyst Overview The AI Vulnerability Operations team is responsible for turning AI-identified security findings into validated, prioritized, and remediated ...
New
Title and Summary Principle, Vulnerability Analyst Overview The AI Vulnerability Operations team is responsible for turning AI-identified security findings into validated, prioritized, and remediated ...
New
Oak Ridge, TN · On-site
Boston Government Services, LLC. (BGS) has created this Evergreen Talent Pool post for gathering qualified candidates for a position relating to Vulnerability Analyst which would support our clients.
Oak Ridge, TN · On-site
Boston Government Services, LLC. (BGS) has created this Evergreen Talent Pool post for gathering qualified candidates for a position relating to Vulnerability Analyst which would support our clients.
Tharros is seeking a Cyber Security Vulnerability Researcher - Intermediate to conduct research into fundamental computer and information science in support of NAWCAD Cyber Warfare Division programs ...
Tharros is seeking a Cyber Security Vulnerability Researcher - Intermediate to conduct research into fundamental computer and information science in support of NAWCAD Cyber Warfare Division programs ...
Job Summary -- Essential Functions/Duties The Vulnerability Management Technician provides technical support to end users while supporting the organization's cybersecurity and vulnerability ...
Job Summary -- Essential Functions/Duties The Vulnerability Management Technician provides technical support to end users while supporting the organization's cybersecurity and vulnerability ...
The Vulnerability Management Analyst plays a key role in enhancing the security posture of mission systems by providing actionable insights, collaborating with engineering teams, and maintaining ...
The Vulnerability Management Analyst plays a key role in enhancing the security posture of mission systems by providing actionable insights, collaborating with engineering teams, and maintaining ...
Andrews, MD · On-site
Prepare and deliver vulnerability reports, compliance dashboards, and metrics for leadership and inspection readiness (e.g., CCRI/CORA). * Support the development and maintenance of asset groupings ...
Andrews, MD · On-site
Prepare and deliver vulnerability reports, compliance dashboards, and metrics for leadership and inspection readiness (e.g., CCRI/CORA). * Support the development and maintenance of asset groupings ...
Position Summary The Vulnerability Remediation Engineer is responsible for improving the organization's security posture through the identification, prioritization, remediation, and prevention of ...
Position Summary The Vulnerability Remediation Engineer is responsible for improving the organization's security posture through the identification, prioritization, remediation, and prevention of ...
$37.5K - $47.1K
1% of jobs
$47.1K - $56.7K
5% of jobs
$56.7K - $66.3K
3% of jobs
$66.3K - $75.9K
0% of jobs
$75.9K - $85.5K
9% of jobs
$91K is the 25th percentile. Wages below this are outliers.
$85.5K - $95K
11% of jobs
$95K - $104.6K
5% of jobs
$104.6K - $114.2K
1% of jobs
The median wage is $117.2K / yr.
$114.2K - $123.8K
46% of jobs
$123.8K - $133.4K
13% of jobs
$133.4K - $143K
5% of jobs
$37.5K
$107.9K
$143K
| Aspect | Vulnerability | Penetration Tester |
|---|---|---|
| Primary Focus | Identifying security weaknesses and vulnerabilities in systems | Simulating cyberattacks to exploit vulnerabilities and test defenses |
| Certifications | CompTIA Security+, CEH, OSCP (for some roles) | OSCP, CEH, GPEN, CISSP (often overlapping) |
| Work Environment | Security analysis, vulnerability scanning, reporting | Active testing, exploitation, reporting |
| Industry Usage | Security assessment, risk management | Security testing, red teaming |
Vulnerability specialists focus on identifying weaknesses in systems, while penetration testers actively exploit those vulnerabilities to assess security effectiveness. Both roles require similar certifications and work in cybersecurity, but their methods and objectives differ: vulnerability analysts aim to find issues, whereas penetration testers simulate attacks to evaluate defenses.

Full-time
Medical, Dental, Vision, Retirement, PTO
Posted 2 days ago
New
8.3
Based on 124 frontline employees who took The Breakroom Quiz
24th of 86 rated pharmaceutical
ROLE SUMMARY
Our Global Cyber Defense team is responsible for safeguarding Pfizer's digital assets and infrastructure through proactive threat detection, response, and risk mitigation across on-premises, cloud, and hybrid environments.
The Manager, Vulnerability Management is responsible for leading the execution of vulnerability management activities to identify, assess, prioritize, and reduce security weaknesses across the enterprise. This role oversees daytoday vulnerability management operations, including scanning, analysis, prioritization, and remediation coordination. The role partners closely with engineering, infrastructure, cloud services, application, and security teams to ensure vulnerabilities are addressed in a timely, riskbased, and compliant manner to reduce overall cyber exposure.
ROLE RESPONSIBILITIES
Lead the daytoday execution of the vulnerability management program, ensuring consistent identification, assessment, and prioritization of vulnerabilities across enterprise environments.
Manage and develop a team of vulnerability management analysts, providing technical guidance, prioritization, coaching, and performance feedback.
Oversee vulnerability scanning activities across infrastructure, endpoints, cloud platforms, and applications, ensuring coverage and data quality.
Translate vulnerability findings into clear, actionable remediation guidance for technical owners, aligned to risk, exploitability, and business impact.
Coordinate remediation efforts with Infrastructure, Cloud Services, Engineering, Endpoint Security, and other technology teams to drive timely risk reduction.
Partner with Threat Intelligence, Threat Remediation, and Incident Response teams to incorporate threat context and active exploitation signals into prioritization decisions.
Track remediation progress, validate closure, and identify recurring issues or systemic control gaps requiring escalation or broader corrective action.
Ensure vulnerability management activities align with internal policies, regulatory requirements, and audit expectations.
Maintain reporting and metrics on vulnerability trends, remediation performance, and risk posture for Cyber Defense leadership.
Drive continuous improvement of vulnerability management processes, tooling, and workflows to increase efficiency, accuracy, and impact.
BASIC QUALIFICATIONS
Applicant must have a bachelor's degree in Information Security, Computer Science, Engineering, Information Technology, or a related field with at least 4 years of experience in cybersecurity, with a strong focus on vulnerability management, security operations, or exposure management; OR a master's degree with at least 2 years of experience; OR as associate's degree with 8 years of experience; OR a high school diploma (or equivalent) and 10 years of relevant experience.
Demonstrated responsibility for executing or overseeing vulnerability scanning, assessment, prioritization, and remediation tracking across infrastructure, endpoints, cloud platforms, or applications.
Experience translating vulnerability findings into riskbased remediation guidance for infrastructure, cloud, application, or platform engineering teams.
Prior responsibility for coordinating remediation activities, including tracking ownership, validating fixes, managing exceptions, and escalating blocked or overdue items.
Familiarity with vulnerability severity, exploitability concepts, and compensating controls used to manage risk when immediate remediation is not feasible.
Experience leading analysts or serving as a technical lead responsible for task prioritization, quality assurance, and daytoday delivery.
Strong analytical, organizational, and problemsolving skills.
Demonstrated experience in an agile work environment possessing qualities such as a collaborative mindset, adaptability to change, and a proactive problem-solving approach.
PREFERRED QUALIFICATIONS
Familiarity with vulnerability management in cloud or hybrid enterprise environments.
Understanding of integrating threat context, exploitability, or attack paths into vulnerability prioritization.
Exposure to operating in regulated or highly controlled environments such as healthcare, life sciences, or manufacturing.
Experience supporting audit, compliance, or regulatory activities related to vulnerability management.
Ability to identify trends and drive process or control improvements over time.
Relevant professional certifications in cybersecurity or vulnerability management (e.g., CISSP, CISM, Security+, etc.)
PHYSICAL/MENTAL REQUIREMENTS
No special physical requirements.
Applicants should be capable of working through a personal laptop computer or mobile device for extended periods.
NON-STANDARD WORK SCHEDULE, TRAVEL OR ENVIRONMENT REQUIREMENTS
Travel as required by the business (less than 5% domestic and/or international)
Work Location Assignment: Must be able to work in assigned Pfizer office 2-3 days per week, or as needed by the business
This role is NOT remote
OTHER JOB DETAILS
Last Date to Apply for Job: August 17. 2026
Work Location Assignment:Must be able to work from assigned Pfizer office 2-3 days per week, or as needed by the business
Relocation assistance may be available based on business needs and/or eligibility.
Candidates must be authorized to be employed in the U.S. by any employer.
U.S. work visa sponsorship (such as TN, O-1, H-1B, etc.) is not available for this role now or in the future.
Sunshine Act
Pfizer reports payments and other transfers of value to health care providers as required by federal and state transparency laws and implementing regulations. These laws and regulations require Pfizer to provide government agencies with information such as a health care provider's name, address and the type of payments or other value received, generally for public disclosure. Subject to further legal review and statutory or regulatory clarification, which Pfizer intends to pursue, reimbursement of recruiting expenses for licensed physicians may constitute a reportable transfer of value under the federal transparency law commonly known as the Sunshine Act. Therefore, if you are a licensed physician who incurs recruiting expenses as a result of interviewing with Pfizer that we pay or reimburse, your name, address and the amount of payments made currently will be reported to the government. If you have questions regarding this matter, please do not hesitate to contact your Talent Acquisition representative.
EEO & Employment Eligibility
Pfizer is committed to equal opportunity in the terms and conditions of employment for all employees and job applicants without regard to race, color, religion, sex, sexual orientation, age, gender identity or gender expression, national origin, disability or veteran status. Pfizer also complies with all applicable national, state and local laws governing nondiscrimination in employment as well as work authorization and employment eligibility verification requirements of the Immigration and Nationality Act and IRCA. Pfizer is an E-Verify employer. This position requires permanent work authorization in the United States.
Pfizer endeavors to makewww.pfizer.com/careersaccessible to all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process and/or interviewing, please emaildisabilityrecruitment@pfizer.com. This is to be used solely for accommodation requests with respect to the accessibility of our website, online application process and/or interviewing. Requests for any other reason will not be returned.
To learn more about acceptable and prohibited uses of AI during the recruitment process, please review our candidate AI-use guidelines available onPfizer Careers.
Information & Business TechSourced by ZipRecruiter
All over the world, Pfizer colleagues work together to positively impact health for everyone, everywhere. Our colleagues have the opportunity to grow and develop a career that offers both individual and company success; be part of an ownership culture that values diversity and where all colleagues are energized and engaged; and the ability to impact the health and lives of millions of people. Pfizer, a global leader in the biopharmaceutical industry, is continuously seeking top talent who are inspired by our purpose to innovate to bring therapies to patients that significantly improve their lives. Our Health and Science System Specialists Team provides leadership across patient care settings in the complex Hospital, Health System, and Key Medical Group environment to bring value to our customers and patients in this dynamic ecosystem.
Pharmaceutical and medicine manufacturing
10,000+ Employees
New York, NY, US
1849