Associate Director of Vulnerability Management Job at Dale WorkForce Solutions, New York, NY

Wlg0STdYNkZ1VXFXVUNwU01Bc2VTN2RuYnc9PQ==
  • Dale WorkForce Solutions
  • New York, NY

Job Description

Associate Director, Vulnerability Management

Permanent, Direct Hire

Hybrid - onsite 3x per week

New York City

Job Description

The Associate Director, Vulnerability Management is responsible for developing and managing a risk-based cyber threat and vulnerability management program and will lead a team that provides continuous vulnerability scanning, configuration monitoring, testing, patch management, and reporting. They will collaborate with IT teams and business process owners to ensure gaps are quickly remediated.

The ideal candidate is a technical, hands-on leader with the ability to drive consensus and collaboration among many diverse teams, individuals, and business stakeholders to achieve desired results. They can explain technical concepts in non-technical terms and have excellent interpersonal, leadership, presentation, and collaborative skills. The candidate must be detail-oriented with the ability to adapt rapidly to new challenges, think creatively and holistically, and quickly resolve unforeseen issues.

Responsibilities

  • Establish, update, and maintain a vulnerability management program based on industry standards & best practices that includes asset discovery, vulnerability scanning, secure configuration monitoring, and remediation or mitigation activity
  • Deliver continuous scanning, identification, and reporting of internal and external attack surface throughout on-prem and cloud-based environments across Firm products, technologies, and networks
  • Recommend, socialize, and gain consensus on minimum patching and vulnerability management standards and policies across Firm IT teams and business stakeholders
  • Lead vulnerability response efforts to address imminent threats and zero-day vulnerabilities
  • Monitor vulnerability remediation progress and partner with IT teams to provide recommendations for efficient risk remediation or mitigation
  • Provide regular reporting on the current state of vulnerabilities and configurations throughout the entire environment including acquisitions
  • Monitor, mitigate, and report on additional threats, including supply chain attacks, vulnerabilities in code, unencrypted protocols, digital footprint issues, and other cybersecurity control gaps
  • Manage internal and external penetration testing, red team activities, active port audits, and software audits to identify EOL hardware and software, insecure legacy applications, and otherwise unsafe or unauthorized software
  • Manage a portfolio of scanning, vulnerability management, breach simulation, and reporting tools and ensure that security agents and vulnerability monitoring tools are deployed correctly and operating properly
  • Develop cyber health scoring algorithms and measurement criteria, and build consumable reporting for technical and non-technical stakeholders, Firm leadership, and external clients
  • Responsible for staying informed of industry leading vulnerability and software security vendors, latest threats & risks, and continuously updating program based on business priorities and available cyber threat intelligence

Education

  • Bachelor's degree in information security, IT, related discipline, or equivalent experience required
  • Professional certifications such as CISSP, CCSP, CISM, or similar

Skills and Experience

  • 15+ years of experience in an IT or Information Security role, with at least 5 years managing or leading an Information Security vulnerability management function
  • Demonstrated success in program development, project execution, and operational delivery
  • Demonstrated knowledge and expertise in vulnerability assessment, risk management, and cybersecurity frameworks such as NIST, CIS, and OWASP
  • Expert familiarity with the Mitre attack framework & CVE/CVSS scoring system
  • Strong technical knowledge of vulnerability scanning and attack surface management tools (e.g., Qualys, Nexpose, Metasploit, AttackIQ, Shodan, etc.)
  • Working knowledge of cloud computing systems (SaaS, PaaS, and IaaS), containers, cloud orchestration
  • Experience working in a global organization and broad knowledge of security domains, technology risk management concepts, and a working knowledge of security and risk frameworks
  • Knowledge of core networking concepts including TCP/IP, firewalls, and network security products
  • Knowledge of common application architectures, design, protocols, and agile deployment methodology and best practices
  • Ability to create and execute a clear strategic vision for vulnerability management that supports and enables businesses functions
  • Ability to manage multiple concurrent objectives and activities, and make effective judgments in prioritizing and time allocation
  • Must be able to execute with limited information and ambiguity
  • Must have a continuous learning mindset and a demonstrated aptitude for understanding new vulnerabilities, threats, and attack vectors
  • Must be able to build collaborative relationships and is comfortable interacting frequently with leadership and internal/external stakeholders

Salary Range NY Only: The estimated base salary range for this position is $220,000 to $260,000 at the time of posting. The actual salary offered will depend on a variety of factors, including without limitation, the qualifications of the individual applicant for the position, years of relevant experience, level of education attained, certifications or other professional licenses held, and if applicable, the location in which the applicant lives and/or from which they will be performing the job. This role is exempt meaning it is not overtime pay eligible.

Job Tags

Permanent employment,

Similar Jobs

Na Hoaloha Ekolu

Musician Job at Na Hoaloha Ekolu

 ..."on stage" presence throughout shift Embraces change Has Aloha Aura Is able to adapt and adjust to blend with fellow musicians Strives to improve and practice their music Has an interest and enthusiasm in the Hawaiian Culture Is community minded... 

Allied Universal Security Services

Security Guard Full Time Job at Allied Universal Security Services

$11.41 / Hour. Monday through Friday 3:00 PM to 11:00 PM - Secure Your Future: We have Opportunities for Security Officers, No Experience Necessary! Ready to Work? Join Us Today! As a Security Guard in Dalton, Georgia, you will serve and safeguard cl Security Guard, Security... 

Maxion Corp

Work At Home Data Entry - Remote - Admin Assistant Job at Maxion Corp

 ...Join Our Team as a Work-From-Home Data Entry Research Panelist! Are you ready to earn money from the comfort of your own home...  ...anywhere, and on a schedule that fits your life. No Experience? No Problem! Comprehensive training is provided to set you... 

Endeavor Schools, LLC

Lead Primary Teacher-Spanish Job at Endeavor Schools, LLC

 ...at: $58,000-$64,000 Annually, Depending on Education and Experience. Are You Qualified? If you have the following, we would love to speak with you: Lead Teacher Montessori Training and Certificate 2-5 Years of Experience required/preferred 12 ECE Units and College degree... 

Tony's Fresh Market

Assistant Store Director Job at Tony's Fresh Market

 ...expectations and guidance to implement business solutions. Qualifications/Requirements: High school diploma/GED, 3-5 years in supermarket industry and completion of management training program, or equivalent combination of education/experience Effective leadership...