We're looking for a Senior Vulnerability Management Consultant to lead the operation and tuning, of an enterprise vulnerability assessment program. This role involves managing scan policies, prioritizing findings based on business risk, coordinating remediation, and delivering executive-level reporting
- Lead the configuration, health monitoring, and lifecycle management of the Vulnerability Assessment (VA) platform and related components.
- Define and manage scan schedules, credential rotation, and scan windows for authenticated scanning across infrastructure.
- Review, interpret, and prioritize vulnerability scan results based on severity, business impact, and risk.
- Provide actionable remediation guidance to application, infrastructure, and network teams; follow up for completion.
- Deliver vulnerability and compliance dashboards and executive summary reports on a weekly and monthly basis.
- Coordinate and support platform upgrades, patching, and version control of VA tools and agents.
- Maintain up-to-date asset inventories and ensure alignment with in-scope scanning targets.
- Host regular governance and remediation review meetings with client stakeholders.
- Contribute to the development and refinement of vulnerability prioritization logic
- Review and approve ad-hoc scan requests in support of audit, compliance, or incident response.
- Guide the development of VA processes, SOPs, and reporting standards to support internal audit and risk requirements.
- Support the training and knowledge transfer of internal teams on platform usage and vulnerability lifecycle processes.
Experience:
- Strong knowledge of vulnerability management tools (Tenable, Qualys, Rapid7).
- Experience with compliance scanning, risk assessment frameworks (NIST, ISO 27001), and remediation workflows.
- Proven experience leading vulnerability management programs in enterprise environments.
Soft Skills:
- Strong analytical and problem-solving abilities with keen attention to detail.
Preferred Certifications
- CISSP, CYSA, CEH, GCIH, CISM
- Certified Vulnerability Management Specialist (or equivalent certification from Tenable, Qualys, or Rapid7)
- ITIL® Foundation (optional but beneficial)