This job is no longer available
The position may have been filled or the posting has expired. Browse similar opportunities below.
Link copied to clipboard!
Back to Jobs
Manager, Vulnerability Management at Vanguard
Vanguard
No longer available
Administration
Posted 18 hours ago
JOB DESCRIPTION
We are seeking an experienced and strategic cybersecurity leader to manage a team responsible for Vulnerability Management across a rapidly evolving hybrid and multi-cloud environment.As the Manager for Vulnerability Management, you will lead a high-performing team to reduce Vanguard’s attack surface through continuous threat exposure management (CTEM), hyper-prioritization, AI-enabled automation, and scalable security guardrails.You’ll operate at the intersection of security risk, automation, and emerging AI-driven capabilities—driving outcomes that protect Vanguard and its clients while minimizing friction for technology teams.This is a unique opportunity to lead a growing function, optimize vulnerability management practices, and partner across the enterprise to deliver measurable risk reduction.Core Responsibilities (In this role you will)Drive the evolution of Vulnerability Management program, adopting VulnOps concepts to defend against human & AI-driven threats – while infusing AI into team operationsLead and develop a high-performing Vulnerability Management team that monitors Vanguard onprem & multi-cloud assets for vulnerabilities and security configuration weaknesses. Provide mentorship, coaching, and professional development to team members. Assess performance and make informed compensation decisions in accordance with HR policies and proceduresPartner with the SOC, Cyber Threat Intel, Offensive Security/Red Team, PatchOps, and other stakeholders to refine prioritization, to validate impact of suspected attack paths, to advise owners on mitigation strategies or compensating controls, and to enable remediation outcomesEnsure timely resolution of false-positives investigations, requests for risk-acceptance or risk-rating adjustment of security findingsCoordinate implementation of hardening security controls for Operating Systems, databases, and critical telecom infrastructure – ensuring compliance with industry security standardsShape remediation SLAs, build-breaking policies, and other enforcement controls & guardrailsDevelops metrics, KPIs, and OKRs to measure the effectiveness of the program and team’s operationsCoordinate with Engineering platform teams to tune scanning tools to improve visibility and to meet additional security objectivesLead continuous process improvement and ensure the team is identifying opportunities for automation, fusion of disparate sources of security findings, and consistency of remediation owner experienceProvide latest industry expertise in emerging security practices and standardsWhat it Takes (Qualifications)Critical thinker with a minimum of 6 years related work experience, including experience in vulnerability management, DevSecOps, cloud security engineering, or general cyber security domains. At least 2 years of experience managing vulnerabilities at scaleExcellent leadership and team management skills, with a track record of building and leading high-performing teams.Solid understanding of CVSS, exploitability, and risk-based prioritization frameworksExperience with AWS, Azure, or GCP – with a good understanding of cloud security principlesUnderstanding of CI/CD pipelines and modern AI-assisted code developmentUndergraduate degree in a related field or the equivalent combination of training and experienceSuperb analytical and problem-solving skills, with the ability to assess and mitigate complex security risksExcellent communication and collaboration skills, with the ability to influence stakeholders multiple levels upWays to stand out:Demonstrated passion for continuous learningExperience with Claude Code/Codex or Threat ModelingExperience leading structured process improvementExperience with Aqua, Palo Alto Prisma, Wiz, CrowdStrike, Tenable, or QualysExperience with security data aggregators such as Brinqa, Kenna, Vulcan, Wiz UVM, or ArmorCodeExperience with risk controls and interacting with internal/external auditSpecial FactorsSponsorshipVanguard is not offering visa sponsorship for this position.About VanguardAt Vanguard, we don't just have a mission—we're on a mission.To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.How We WorkVanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.SummaryLocation: Malvern, PA; North Carolina; Dallas/Ft. Worth, TXType: Full time