Director, Vulnerability Management

New York 29 days agoFull-time External
Negotiable
A financial firm is looking for a Director of Vulnerability Management to join their team in Iselin, NJ or New York, NY. Compensation: $170-210k base No visa sponsorship and candidates MUST be local Responsibilities: Develop and lead the enterprise vulnerability management strategy, roadmap, and program. Act as delegate sponsor for the Vulnerability Management project as part of the Information Security Transformation program. Oversee vulnerability scanning, risk assessments, and prioritization processes across infrastructure, applications, containers, and cloud environments and critical third parties. Manage vulnerability management platforms and ensure optimal configuration, tuning, and coverage. Partner with Technology, cloud, SecOps, CTI, application teams, and asset owners to drive remediation and track progress. Provide threat-based prioritization of vulnerabilities using CVSS, threat intelligence, exploitability data, and business context. Lead the response to high-profile vulnerabilities (e.g., zero-days, critical CVEs) with timely impact analysis and coordinated remediation actions. Develop and present executive-level reporting on vulnerability trends, KRIs, KPIs, and risk posture. Maintain compliance with relevant standards and frameworks (e.g., NIST CSF, ISO 27001). Own governance for exception handling and risk acceptance processes related to un-remediated vulnerabilities. Lead, mentor, and grow a team of vulnerability analysts, engineers, and program managers. Qualifications: Required Bachelor's degree or higher in Computer Science, Information Security, Engineering, or related field. 10+ years of experience in cybersecurity, with at least 5 years in a leadership or management capacity. Proven experience building or leading a mature vulnerability management program at scale. Deep understanding of vulnerability scanning technologies, CVSS scoring, and threat modelling. Strong knowledge of cloud platforms (AWS, Azure), and container security. Familiarity with compliance frameworks and standards (NIST, ISO, etc.). Experience managing and mentoring technical teams and working cross-functionally with non-security teams. Excellent communication and stakeholder engagement skills with the ability to convey complex risk topics to executive audiences. Preferred Relevant certifications (e.g., CISSP, CISM, OSCP, or similar). Experience integrating vulnerability management with SIEM, ticketing, and asset management tools. Strong understanding of risk management and cyber risk quantification. About the Company: Open Systems Technologies At OST, we’re a bit like what you may call a machine, but with a more human touch. Day in and day out for the last 28 years we’ve been more than just a staffing company. Throughout this time we’ve built relationships, we’ve grown together internally and externally, and have created a system that allows us to personally cater to the needs of our clients and candidates. As we celebrate this occasion, it important to note that for us, 28 years is more than just a number or an anniversary. It is 28 years of relationships, 28 years of trust, and 28 years of total reliability. We’ve been a mentor for some, a team builder for others, but most importantly we’ve been there. We know there is no substitute for experience, so let us help you navigate through the ever changing web of talent. Operating in a crowded marketplace, we have succeeded by staying ahead of the curve. No two projects are the same, and neither are our solutions. We’ve got the connections. We know the people. We have the opportunities. How soon can you start? Company Size: 500 to 999 employees Industry: Staffing/Employment Agencies Founded: 1990 Website: http://www.opensystemstech.com/