Principal Technology Compliance Program Manager - Vulnerability Management
$141,250–$211,900 year
On-siteSeaTac, Washington, United States
Job Summary
Lead the enterprise vulnerability management program as the sole subject matter expert, defining long-term strategy for identifying, assessing, prioritizing, and remediating security vulnerabilities across the technology environment. Ensure the program aligns with regulatory requirements such as PCI-DSS, HIPAA, NIST, and ISO 27001 while integrating with SIEM, CMDB, and ticketing systems. Manage and optimize tools like Tenable, Qualys, and Rapid7 to improve internal audit and risk management reviews. Oversee regular vulnerability scanning, facilitate third-party penetration tests, and coordinate scope definition and rules of engagement with stakeholders. Analyze findings, validate results, and work with relevant teams to prioritize remediation efforts. Define and track key performance indicators to measure program effectiveness, manage execution of timely reports to leadership, and maintain documentation for compliance audits.
Required Qualifications
- 7 years of experience in IT Security and Compliance, or related area
- Bachelor's degree in Information Security, Information Technology, Computer Science or related field, or an additional two years of relevant training/experience in lieu of this degree
- Experience in project management, including all elements of scope, schedule, budgeting, risk evaluation, quality, integration, staffing, and communications
- Knowledge of security regulations (e.g., Sarbanes-Oxley, Payment Card Industry Data Security Specification [PCI DSS], Health Insurance Portability and Accountability Act [HIPAA]) and standards (e.g. ISO 27001, NIST SP800-series)
- Excellent verbal and written communication skills
- High school diploma or equivalent
- Minimum age of 18
- Must be authorized to work in the U.S.
- Must be able to submit to post-offer and/or pre-employment drug testing to determine the presence of marijuana, cocaine, opioids, phencyclidine (PCP) and amphetamines or a metabolite of these drugs
Desired Qualifications
- Industry certification in security (e.g. CISA, CISSP, and/or GIAC)
- Industry certification in project management (e.g. PMP)
- 2 years of experience leading people
- Demonstrated knowledge and experience in information security, software development and/or network security for large organizations
- Detailed technical knowledge in security engineering, system and network security, authentication and security protocols
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.