Vulnerability & Cloud Security Program Manager
$180,000–$220,000 year
HybridAustin, California, United States
Job Summary
Lead the enterprise vulnerability management and cloud security posture management (CSPM) programs, ensuring timely discovery, assessment, prioritization, and remediation of risks across on-premise, cloud, and application environments. Administer and optimize vulnerability management and CSPM platforms, including policies, integrations, reporting, and automation. Monitor cloud and infrastructure environments to identify misconfigurations, excessive permissions, and compliance drift, primarily in AWS, while partnering with engineering and DevOps teams to drive remediation efforts and provide technical guidance. Align security practices with frameworks such as FedRAMP, NIST CSF, ISO 27001, and CIS Controls. Track and report key KPIs and risk metrics to leadership, including SLA compliance and vulnerability trends. Automate detection, remediation workflows, and tool integrations to enhance efficiency. This role supports compliance obligations and advances the organization's overall security maturity within a collaborative, hybrid remote environment.
Required Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience
- 5+ years of experience in vulnerability management
- 2+ years in cloud security
- Hands-on experience with CSPM tools, vulnerability detection platforms, and automation
- Strong understanding of AWS security best practices and cloud-native architectures
- Familiarity with vulnerability scoring systems like CVSS and risk-based prioritization
- Excellent communication, collaboration, and stakeholder management skills
- Must be U.S. citizens or lawful permanent residents
- Reside outside the city limits of Chicago or be willing to self-relocate
Desired Qualifications
- Wiz
- AWS Inspector
- Nessus
- OpenSCAP
- CISSP
- AWS Security Specialty
- GIAC Cloud Security
- Preferred knowledge of regulatory and compliance frameworks such as PCI DSS, HIPAA, SOX, FedRAMP
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.