Lead Infosec Engineer Vulnerability Management positions focus on delivering results in their domain. This page aggregates open Lead Infosec Engineer Vulnerability Management roles and what employers typically expect.
# **About the Role:** **Grade Level (for internal use):** 11**The Team:**Our Information Security team is a growing corporate enterprise function that operates cross-divisionally to enable business success through proactive security practices. We're transforming our approach from reactive response to proactive risk management, building technology-enabled environments that support innovation while maintaining a strong security posture. As a collaborative team, we partner across all divisions to ensure security becomes an enabler rather than a barrier to business objectives. **Responsibilities and Impact:** - Lead enterprise-wide vulnerability management lifecycle across infrastructure, cloud, and application environments, providing strategic oversight and risk-based prioritization to protect critical business assets - Drive cross-functional collaboration with application teams, IT managers, and business stakeholders to ensure timely vulnerability remediation while balancing security requirements with business priorities - Develop comprehensive reporting and metrics programs using multiple data sources to provide executive leadership with clear visibility into organizational security posture and risk trends - Mentor and guide junior security professionals while contributing to program maturity through process improvements, governance frameworks, and tooling strategy development - Support regulatory compliance and audit activities by ensuring alignment with enterprise security policies, industry standards, and emerging technology risk management requirements - Establish and monitor key performance indicators for vulnerability remediation, creating accountability frameworks that drive measurable improvements in security outcomes **What We're Looking For:** **Basic Required Qualifications:** - 7+ years of operational security experience in vulnerability management, application security testing, or technical project management within large-scale, distributed enterprise environments - Deep expertise in vulnerability assessment frameworks including CVE, CVSS, CWE, and experience with enterprise vulnerability management platforms such as Qualys, Tanium, Rapid7, or similar solutions - Strong application security knowledge with ability to assess risk, map vulnerabilities to exploitation techniques, and translate complex technical findings into actionable business recommendations - Experience with application security testing tools including DAST/SAST platforms such as Fortify, Checkmarx, Veracode, or equivalent application security testing solutions - Bachelor's degree in Computer Science, Cybersecurity, Information Technology or equivalent professional experience in information security roles - Proven leadership and influence capabilities with demonstrated ability to drive cross-functional initiatives and stakeholder alignment without direct authority - Excellent analytical and communication skills with the ability to present security risks and recommendations to both technical teams and executive audiences - Relevant information security certifications such as CISSP, CISM, CEH, GCIH, or equivalent industry-recognized credentials **Additional Preferred Qualifications:** - Advanced vulnerability management expertise with experience leading complex assessments across on-premises and cloud environments, including network, application, and configuration scanning with a deep understanding of remediation strategies - Proficiency in security reporting and analytics tools such as Power BI, Tableau, or similar platforms for developing executive-level dashboards and security metrics visualization - Strong knowledge of information security frameworks including NIST Cybersecurity Framework, ISO 27001, and risk management methodologies with experience supporting audit and regulatory compliance activities - Foundational understanding of emerging technologies including cloud platforms, AI/ML systems, and associated security risks such as model vulner…