Vulnerability Manager at BeyondTrust | CA | Rezi

Vulnerability Manager at BeyondTrust

Vulnerability Manager

BeyondTrust · CA

1 weeks ago

Vulnerability Manager

BeyondTrust · CA

12 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Vulnerability Manager role.

Rezi rewrites your resume against BeyondTrust's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Vulnerability Manager posting at BeyondTrust — free, in seconds.

About the Role

The Vulnerability Manager operates BeyondTrust's product vulnerability management program end to end. This is an operator role responsible for designing the process, driving automation, owning metrics, and reporting on open vulnerability risk. The primary focus is vulnerability management for FedRAMP 20x and standing up vulnerability management for new products. This role partners closely with Security Engineering to define integration requirements and owns the operational outcome.

Responsibilities

  • Design and operate the product vulnerability management process end to end: intake, triage, risk assessment, assignment, SLA tracking, exception handling, and closure verification.
  • Own vulnerability management for FedRAMP 20x, including continuous monitoring cadence, machine-readable evidence, Key Security Indicator reporting, and POA&M lifecycle.
  • Stand up vulnerability management for new products and services as they ship: define scan coverage, onboard them into the process, set SLAs, and establish reporting.
  • Assess and rank vulnerability risk using exploitability, exposure, asset criticality, and compensating controls, and defend that ranking.
  • Drive remediation with product engineering teams: assign ownership, agree timelines, escalate overdue findings, and record risk acceptances.
  • Automate the process wherever manual effort scales with finding volume, using scripting, workflow tooling, and AI-assisted analysis.
  • Define the requirements for platform integrations built by Security Engineering, covering scanners, ticketing, asset inventory, and dashboards.
  • Own the program metrics: SLA attainment, mean time to remediate, vulnerability aging, backlog trend, scan and asset coverage, and exception volume.
  • Monitor the vulnerabilities that matter most, maintaining a current view of critical exposure across the product portfolio.
  • Lead rapid response for actively exploited and zero-day vulnerabilities, including exposure assessment, mitigation tracking, and stakeholder communication.

Requirements

  • 5+ years in vulnerability management, product security, or security operations, with direct ownership of a vulnerability management process.
  • Demonstrated experience designing and operating a vulnerability management process in a regulated or audited environment.
  • Working knowledge of FedRAMP and NIST SP 800-53, specifically vulnerability scanning, flaw remediation, continuous monitoring, configuration management, and POA&M management.
  • Hands-on operation of enterprise vulnerability and exposure management platforms, cloud security posture tooling, container scanning, and software composition analysis.
  • Practical automation skill: scripting in Python or equivalent, workflow and reporting tooling, and use of AI assistants to reduce manual triage and reporting effort.
  • Ability to write clear technical requirements and partner with security engineering through design, delivery, and acceptance.
  • Strong understanding of CVSS, CISA Known Exploited Vulnerabilities (KEV), EPSS, and risk-based prioritization.
  • Working knowledge of cloud services (AWS preferred), containers, Kubernetes, CI/CD, web applications, and APIs, sufficient to assess a finding and evaluate a proposed fix.
  • Ability to drive remediation across engineering teams without direct authority.
  • Clear written and verbal communication with engineers, executives, auditors, and customers.

Skills

  • Python scripting
  • Workflow tooling
  • AI-assisted analysis
  • CVSS
  • CISA KEV
  • EPSS
  • Risk-based prioritization
  • AWS
  • Containers
  • Kubernetes
  • CI/CD
  • Web applications
  • APIs

Location

  • North America

Work Type

  • Fully remote

Experience Level

  • 5+ years

About the Company

  • BeyondTrust is the global identity security leader protecting Paths to Privilege™. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders.
  • BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners.
  • Learn more at www.beyondtrust.com.

Equal Opportunity

  • Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected.
  • We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.