BeyondTrust
Vulnerability Manager
Remote work allowed only within certain countries or regions.
Employer listed it 12 days ago · Added 4 days ago
First listed 12 days ago and still open.
Salary
Not stated
Location
Timezone
US East
Contract
Full-time
Experience
Mid
Category
Software
This employer didn't state pay. Jobs like this usually pay around $165k–$255k a year, a typical range taken from 594 mid-level software roles on Nomaders that do state pay. It's a guide, not an offer.
Remote flexibility
Region Restricted
Remote work is allowed, but only for candidates based in Canada, United States.
What the employer says
- Source listing states candidate location: "Remote Canada | Remote United States, Remote Canada, Remote United States"
What Nomaders makes of it
- Applications outside the listed area are usually rejected
- Timezone overlap with the listed area is often expected
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cybersecurity SaaS portfolio.
Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself.
The Role
The Vulnerability Manager operates BeyondTrust's product vulnerability management program end to end. This is an operator role: you design the process, drive the automation that runs it, own the metrics, and are accountable for the answer when leadership asks what our open vulnerability risk is today. The primary focus is vulnerability management for FedRAMP 20x and standing up vulnerability management for new products as they ship. You partner closely with Security Engineering to define the integration requirements, partner with them closely through delivery, and own the operational outcome. The ideal candidate has designed a vulnerability management process inside a regulated environment, uses automation and AI to remove manual work rather than absorbing it, and can hold a remediation conversation with an engineering lead and an evidence conversation with an assessor on the same day. Fully remote, must be North America based.
What You’ll Do
Design and operate the product vulnerability management process end to end: intake, triage, risk assessment, assignment, SLA tracking, exception handling, and closure verification.
Own vulnerability management for FedRAMP 20x, including continuous monitoring cadence, machine-readable evidence, Key Security Indicator reporting, and POA&M lifecycle from creation through closure.
Stand up vulnerability management for new products and services as they ship: define scan coverage, onboard them into the process, set SLAs, and establish reporting from first release.
Assess and rank vulnerability risk using exploitability, exposure, asset criticality, and compensating controls rather than CVSS alone, and defend that ranking to engineers, executives, and assessors.
Drive remediation with product engineering teams: assign ownership, agree timelines, escalate overdue Critical and High findings, and record risk acceptances as time-bound decisions with an expiry.
Automate the process wherever manual effort scales with finding volume, using scripting, workflow tooling, and AI-assisted analysis for triage, deduplication, enrichment, summarization, and evidence collection.
Define the requirements for platform integrations built by Security Engineering, covering scanners, ticketing, asset inventory, and dashboards. Partner with that team through delivery and validate the result against the operational need.
Own the program metrics: SLA attainment, mean time to remediate, vulnerability aging, backlog trend, scan and asset coverage, and exception volume. Report them on a fixed cadence to security and engineering leadership.
Monitor the vulnerabilities that matter most. Maintain a current view of critical exposure across the product portfolio and serve as the authoritative answer to what is open, what it means, and when it closes.
Lead rapid response for actively exploited and zero-day vulnerabilities, including exposure assessment across the product fleet, mitigation tracking, and stakeholder communication.
What You’ll Bring
5+ years in vulnerability management, product security, or security operations, with direct ownership of a vulnerability management process rather than participation in one.
Demonstrated experience designing and operating vulnerability management process in a regulated or audited environment, and sustaining it through assessment cycles.
Working knowledge of FedRAMP and NIST SP 800-53, specifically vulnerability scanning, flaw remediation, continuous monitoring, configuration management, and POA&M management.
Hands-on operation of enterprise vulnerability and exposure management platforms, cloud security posture tooling, container scanning, and software composition analysis.
Practical automation skill: scripting in Python or equivalent, workflow and reporting tooling, and use of AI assistants to reduce manual triage and reporting effort. This role automates its own process; it does not build platform software.
Ability to write clear technical requirements and partner with security engineering through design, delivery, and acceptance.
Strong understanding of CVSS, CISA Known Exploited Vulnerabilities (KEV), EPSS, and risk-based prioritization, with the judgment to separate a high score from a real exposure.
Working knowledge of cloud services (AWS preferred), containers, Kubernetes, CI/CD, web applications, and APIs, sufficient to assess a finding and evaluate a proposed fix.
Requirements
- ·5+ years in vulnerability management, product security, or security operations, with direct ownership of a vulnerability management process rather than participation in one.
- ·Demonstrated experience designing and operating vulnerability management process in a regulated or audited environment, and sustaining it through assessment cycles.
- ·Working knowledge of FedRAMP and NIST SP 800-53, specifically vulnerability scanning, flaw remediation, continuous monitoring, configuration management, and POA&M management.
- ·Hands-on operation of enterprise vulnerability and exposure management platforms, cloud security posture tooling, container scanning, and software composition analysis.
- ·Ability to write clear technical requirements and partner with security engineering through design, delivery, and acceptance.
Benefits
No benefits package published with this listing. Ask about it at first interview.
How to apply
- 1Check the flexibility label above, region restricted, matches where you plan to live and work.
- 2Tailor your CV to the role at BeyondTrust, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 5d ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
Typically $165k–$255k · You'll be taken to the employer's careers page.