conEdison logo

Vulnerability Management Manager

conEdison

New York, NYJobSeen 2 days agoSeen in employer's feed 2 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
No compensation found
Location
New York, NY
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Requirements

Credentials this posting asks for.

CISSP CertificationCISM CertificationGIAC CertificationBachelor's degreeDriver's License

Job overview

The Vulnerability Management Manager will lead security teams in triage, remediation, and metrics-driven vulnerability programs, overseeing cloud and application security, OT environments, and compliance initiatives while coaching staff and coordinating emergency response efforts.

Skills & qualifications

RequiredNice to have

Skills

Vulnerability ManagementSecurity OperationsApplication SecuritySystem SecurityCloud SecurityCTEMWAFOT EnvironmentNERC CIP ComplianceMetrics and DashboardsLeadershipProject Management

Qualifications

Bachelor's DegreeMaster's Degree6+ Years Vulnerability Management ExperienceCISSP CertificationCISM CertificationGIAC CertificationDriver's LicensePMP Training or Certification

Full job description

Required Education/Experience

  • Bachelor's Degree and 8 years of relevant work experience. or

  • Master's Degree and 6 years of relevant work experience.

Preferred Education/Experience

  • Master's Degree Majors preferred in IT, computer science, business administration, engineering or related. and 6 years of relevant work experience.

Relevant Work Experience

  • 6+ years in vulnerability management, security operations, application security, system security, or a related field, with proven ownership of triage and remediation workflows, required.

  • Proven people leadership experience, including coaching, performance management, hiring and skills development for technical teams, required.

  • Strong cloud security fundamentals, especially reducing critical and high-risk resource misconfigurations with stakeholder partners, required.

  • Strong application security fundamentals, including shift left and runtime risk management, required.

  • Experience leading response for critical vulnerabilities and urgent events, including zero-day response, secrets leakage triage, escalation, containment and validation, required.

  • Experience tracking vulnerability and remediation metrics and building dashboards to measure SLA performance, aging, risk reduction and trends over time, required.

  • Ability to turn security strategy into measurable operations, including metrics and leadership reporting, required.

  • Experience standing up new programs from scratch with clear scope, intake and success criteria, required.

  • Experience with CTEM or equivalent exposure management models beyond patching metrics, preferred.

  • Practical WAF experience, including rule tuning, validation and improving detection quality, preferred.

  • OT environment experience, or strong ability to quickly build OT vulnerability management capability, preferred.

  • Experience applying vulnerability management and remediation controls to regulatory and compliance requirements, such as NERC CIP for OT and critical infrastructure, preferred.

  • Certifications such as CISSP, CISM, GIAC or equivalent, required.

Licenses and Certifications

  • Driver's License Required

  • Project Management Professional (PMP) Training and/or certification in Project Management is a plus. Preferred

Physical Demands

  • Sit or stand to answer a phone for the duration of the workday

  • Sit or stand to use a keyboard, mouse, and computer for the duration of the workday

  • Ability to read small print and symbols

Additional Physical Demands

  • The selected candidate will be assigned a System Emergency Assignment (i.e., an emergency response role) and will be expected to work non-business hours during emergencies, which may include nights, weekends, and holidays.

  • Must be able and willing to travel within Company service territory, as needed.

EEO Statement:

Consolidated Edison Company of New York, Inc. (Con Edison), Orange & Rockland Utilities (O&R), and Consolidated Edison Transmission (CET) are equal opportunity employers. All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of the individual’s actual or perceived disability, protected veteran status, race, color, creed, religion, sex, age, national origin, gender, gender identity, gender expression, genetic information, marital status, sexual orientation, citizenship, domestic violence victim status, or any other actual or perceived status protected by law.

Technical Difficulty Statement:

For technical issues, please contact us at [email protected]

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.