Vulnerability Management Manager

New York, NY

Summary

The Vulnerability Management Manager, working closely with the information security team, leads the enterprise vulnerability management program, overseeing the continuous identification, assessment, prioritization, and remediation of vulnerabilities across operating systems, applications, and infrastructure components. This role designs and governs program strategy, collaborates cross-functionally with security and operations teams, and ensures remediation efforts align with Firm’s risk tolerance, regulatory obligations, and industry best practices.

Responsibilities

  • Lead the assessment, prioritization, and remediation tracking of vulnerabilities across enterprise endpoints, servers, and cloud environments, collaborating with information security, and IT teams to align remediation activities with identified threats.
  • Evaluate vulnerability criticality using risk-based frameworks (CVSS, EPSS, CISA KEV) in conjunction with threat intelligence and business context to drive informed remediation decisions
  • Design and maintain vulnerability remediation and patching schedules, phased rollout plans, and maintenance windows that minimize business impact while satisfying security and compliance requirements
  • Ensure timely patching of enterprise desktops, servers, and applications by coordinating with product owners and patch management teams, tracking deployment status, enforcing remediation SLAs, and ensuring exceptions are documented and risk-accepted through a formal process
  • Correlate vulnerability scan findings with patch deployment status to identify coverage gaps, report on compliance rates, and escalate systemic gaps or high-risk exceptions to the information security team
  • Lead emergency and out-of-band patching efforts for actively exploited or critical vulnerabilities, coordinating rapid deployment with minimal business disruption
  • Perform advanced troubleshooting for complex or high-risk vulnerabilities, working with system administrators, application owners, and engineering teams on remediation or compensating controls
  • Enforce patch compliance standards, ensuring patching activities align with organizational policy and frameworks such as NIST and CIS Controls
  • Document vulnerability management procedures, baselines, exception handling, and reporting methods to support audits and continuous improvement
  • Develop and deliver reporting on vulnerability trends, program KPIs, and risk exposure for both technical teams and executive leadership

Requirements

  • Bachelor’s degree in IT, Computer Science, or a related field, or equivalent relevant experience
  • 3–5 years of experience in vulnerability management, patch management, or related infrastructure security roles in medium to large enterprises
  • Strong understanding of vulnerability and patch management principles and experience with tools such as Tenable, Qualys, or Rapid7, and familiarity with endpoint patch management platforms including WSUS, SCCM, and Intune
  • Proven problem solving, analytical, communication, and interpersonal skills with the ability to manage multiple priorities effectively
  • Experience with assessments, audits, and implementing automated vulnerability management solutions, including SLA tracking and compliance reporting
  • Familiarity with security and compliance frameworks such as NIST CSF or ISO 27001
  • Ability to obtain and maintain a Secret clearance; U.S. citizenship required
  • Relevant certifications such as CISSP, CISM, CISA, or similar security certifications are a plus

Compensation: $200,000.00-$215,000.00, plus bonus

 

 

Job Type: Full-time, Hybrid

Salary: $200,000.00-$215,000.00, plus bonus

Date Active: 8/6/2026

Exempt/Not Exempt: Exempt

Apply for this Position

  • Accepted file types: docx, doc, pdf, Max. file size: 25 MB.