Insight Global logo

Vulnerability & Risk Management Manager

Insight Global

Waller, TXJobNo compensation foundPosted 2mo agoSeen in employer's feed 4 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
No compensation found
Location
Waller, TX
Work Authorization
Not specified

Requirements

Credentials this posting asks for.

CISSP CertificationCRISC CertificationCISM CertificationGIAC CertificationsCloud/Security Platform Certifications

Job overview

Insight Global is hiring a Vulnerability & Risk Management Manager. The Vulnerability & Risk Management Manager will lead and mature the enterprise vulnerability management and risk reduction program across infrastructure, cloud, and applications. This role involves owning the full vulnerability management lifecycle, transitioning to risk-based prioritization, establishing SLAs, and correlating vulnerability data with threat intelligence. The manager will also drive remediation efforts, build program SOPs, reporting frameworks, and KPIs, and support audit and compliance requirements.

Key focus areas include Own the full vulnerability management lifecycle, Transition the program from volume-based CVE tracking to risk-based prioritization, and Establish and enforce SLAs by severity and asset criticality.

Successful candidates bring 8+ Years Cybersecurity Experience, Vulnerability Management Program Experience, and CISSP/CRISC/CISM Certification. Important skills include Vulnerability Management, Risk Governance, Vulnerability Scanning Methodologies, CVE/CVSS Scoring, Contextual Risk Scoring, and Operating Systems. Preferred (not required): Tenable, Qualys, Defender, and Threat Intelligence.

Skills & qualifications

RequiredNice to have

Skills

Vulnerability ManagementRisk GovernanceVulnerability Scanning MethodologiesCVE/CVSS ScoringContextual Risk ScoringOperating SystemsNetworkingAWSAzureGCPVulnerability Data AnalysisFalse Positive IdentificationDuplicate IdentificationRisk PrioritizationIntegrating Security Tool DataAsset InventoryCMDBPatch ManagementCSPMCNAPPApplication Security PipelinesCollaborationAccountability DrivingExecutive-Level CommunicationRisk-Focused SummariesTechnical ReportingRisk ManagementRisk Acceptance ProcessesException TrackingAudit/Compliance DocumentationEnterprise Risk Register InputApplication Security ConceptsBuilding DashboardsEstablishing Training and GuidanceTenableQualysDefenderThreat IntelligenceCISA KEVsJ-SOX

Qualifications

8-12+ Years in CybersecurityExperience Standing Up or Maturing a Vulnerability Management ProgramCISSP CertificationCRISC CertificationCISM CertificationGIAC CertificationsCloud/Security Platform Certifications

Full job description

Job Description

This role is a senior, hands-on Vulnerability & Risk Management Manager responsible for leading and maturing the enterprise vulnerability management and risk reduction program across infrastructure, cloud, and applications. Day to day, this person will own the full vulnerability management lifecycle — scanning, ingestion, normalization, prioritization, remediation tracking, and reporting — while transitioning the program from volume-based CVE tracking to risk-based prioritization aligned with business impact and exploitability. They will establish and enforce SLAs by severity and asset criticality, correlate vulnerability data with threat intelligence (active exploitation, CISA KEVs), asset exposure, and business impact, and lead risk acceptance and exception processes with proper documentation. A major part of the role is driving remediation at scale by working cross-functionally with infrastructure, endpoint, cloud/platform, application, and incident response teams to remove blockers and improve cycle time. This individual will also build out the program's SOPs, reporting frameworks, KPIs (MTTR, SLA adherence, risk reduction trends), and dashboards, while acting as the central coordinator for vulnerability-related risk reporting to leadership — translating technical findings into clear business risk statements for stakeholders. They'll support audit and compliance requirements (e.g., J-SOX, internal audits), evaluate and optimize tooling (Tenable, Qualys, Defender, etc.), and partner with security architecture and engineering to drive systemic fixes beyond just patching.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to [email protected] learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Skills and Requirements

8–12+ years in cybersecurity with strong emphasis on vulnerability management and risk governance

Experience standing up or maturing a vulnerability management program at scale

Strong understanding of vulnerability scanning methodologies and tooling, CVE/CVSS scoring (including its limitations), and contextual risk scoring beyond CVSS

Proficiency with operating systems, networking, and cloud architectures (AWS/Azure/GCP)

Ability to analyze vulnerability data at scale, identify false positives/duplicates, and prioritize realistically based on environment and exposure

Experience integrating data from multiple security tools into a cohesive risk view (asset inventory/CMDB, patch management, CSPM/CNAPP, application security pipelines)

Strong cross-functional collaboration skills — ability to drive accountability across IT and engineering teams without friction

Executive-level communication skills — able to deliver risk-focused summaries for leadership and detailed technical reporting for remediation teams

Experience with risk management and governance — risk acceptance processes, exception tracking, audit/compliance documentation, and enterprise risk register input CISSP, CRISC, or CISM certification

GIAC certifications (e.g., GMON, GPEN — not required but helpful for context)

Cloud/security platform certifications (AWS, Azure)

Familiarity with application security concepts

Experience building dashboards and reporting that clearly show risk posture, trends over time, and areas requiring leadership attention

Experience establishing training and guidance for IT and engineering teams to improve remediation quality

You've read the whole posting — now see how you match it.