USA remote
Senior Manager, Vulnerability Assessment
About this role
Nielsen is seeking a proactive Senior Manager within the Product Security organization to drive and expand our cloud and application security initiatives. This role requires a balance of operational discipline, high-agency, and technical vision. You will lead a group of skilled engineers and collaborate with development teams to transition our security framework toward a modern, automated, AI-driven DevSecOps model. You will be accountable for team performance, defining security policies, and ensuring compliance, while adapting departmental plans to address operational challenges.
Additionally, you will provide subject matter guidance to employees and colleagues operating within policy guidelines with moderate managerial oversight. Work Style & Mindset You prioritize business enablement over rigid perfectionism. You know how to make calculated risk trade-offs, focus on the 20% of risks that cause 80% of the impact, and keep engineering teams moving forward. You treat engineering teams as internal customers.
You measure success not by how many vulnerabilities you find, but by how easily developers can fix them with minimal friction. You possess the grit and diplomatic skills to drive cultural change. You comfortably navigate organizational inertia and win buy-in for AI automation through small, high-impact victories. You stay ahead of emerging tech trends, continuously evaluating how AI, cloud-native patterns, and modern tooling can simplify security operations.
You maintain a steady, analytical composure during high-severity events or pipeline blockers, focusing on automated prevention and root-cause solutions. Responsibilities Lead and mentor a high-performing Application Security engineering team, fostering professional development and aligning team priorities with organizational goals and operational challenges. Drive a forward-thinking Application and Pipeline Security strategy that transitions operations to an autonomous, AI-driven DevSecOps model, pioneering agentic security workflows for automated remediation while establishing robust architectural guardrails and validation standards for secure AI-assisted development.
Partner collaboratively with Platform Engineering to define cloud security baselines and Policy-as-Code (PaC) guardrails. Oversee application penetration testing initiatives ensuring findings are triaged, fed into pipeline guardrails, and remediated within SLA. Establish comprehensive observability and regulatory standards across the development lifecycle, including supply chain safeguards (SBOM), automated CI/CD security gates, and risk-approval protocols to drive rapid, friction-free remediation and ensure high-confidence visibility.