USA remote
Vulnerability Manager
About this role
BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cybersecurity SaaS portfolio. Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself. The Role The Vulnerability Manager operates BeyondTrust's product vulnerability management program end to end.
This is an operator role: you design the process, drive the automation that runs it, own the metrics, and are accountable for the answer when leadership asks what our open vulnerability risk is today. The primary focus is vulnerability management for FedRAMP 20x and standing up vulnerability management for new products as they ship. You partner closely with Security Engineering to define the integration requirements, partner with them closely through delivery, and own the operational outcome.
The ideal candidate has designed a vulnerability management process inside a regulated environment, uses automation and AI to remove manual work rather than absorbing it, and can hold a remediation conversation with an engineering lead and an evidence conversation with an assessor on the same day. Fully remote, must be North America based. What You’ll Do Design and operate the product vulnerability management process end to end: intake, triage, risk assessment, assignment, SLA tracking, exception handling, and closure verification.
Own vulnerability management for FedRAMP 20x, including continuous monitoring cadence, machine-readable evidence, Key Security Indicator reporting, and POA&M lifecycle from creation through closure. Stand up vulnerability management for new products and services as they ship: define scan coverage, onboard them into the process, set SLAs, and establish reporting from first release. Assess and rank vulnerability risk using exploitability, exposure, asset criticality, and compensating controls rather than CVSS alone, and defend that ranking to engineers, executives, and assessors.