Vulnerability Manager
Posted 1hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Vulnerability Manager leading Guild Mortgage’s enterprise vulnerability management program. Prioritizing remediation, managing security scanning platforms, and reporting cyber-risk exposure to leadership.
Responsibilities:
- Develop, implement, and continuously improve the enterprise vulnerability management program
- Establish and maintain vulnerability management policies, standards, procedures, and governance processes
- Define risk-based remediation priorities based on asset criticality, exploitability, threat intelligence, and business impact
- Lead vulnerability review meetings and remediation governance forums
- Develop vulnerability management roadmaps and maturity improvement initiatives
- Oversee vulnerability scanning across servers, workstations, network devices, cloud platforms, containers, applications, and databases
- Validate and triage identified vulnerabilities to reduce false positives
- Assess vulnerability severity using CVSS, threat intelligence, exploit availability, and environmental factors
- Monitor emerging threats, zero-day vulnerabilities, and security advisories
- Coordinate remediation with IT Operations, Infrastructure, Engineering, Cloud, and Development teams
- Establish remediation timelines and service-level objectives
- Track remediation progress against established metrics
- Manage exception processes and risk acceptance workflows
- Escalate critical vulnerabilities and overdue remediation items to leadership
- Manage vulnerability scanning and management platforms
- Ensure scanning coverage, tuning, maintenance, and integration effectiveness
- Develop executive dashboards and operational reporting
- Report vulnerability trends, remediation effectiveness, and exposure reduction progress
- Track and report KPIs and KRIs
- Support enterprise risk management initiatives
- Evaluate vulnerabilities in the context of business risk
- Facilitate risk-based decisions regarding remediation versus risk acceptance
- Align vulnerability management activities to regulatory and security frameworks
- Incorporate internal and external threat intelligence into vulnerability prioritization
- Monitor the CISA Known Exploited Vulnerabilities catalog and other threat intelligence sources
- Prioritize remediation based on active exploitation trends
Requirements:
- Bachelor's Degree directly related to the position or equivalent, preferred
- Minimum five years experience
- Minimum three years supervisory or leadership experience
- Ability to organize and manage multiple priorities simultaneously
- Ability to work independently or within a team
- Excellent interpersonal communication skills
- Ability to handle confidential matters with discretion
- Excellent verbal and written communication skills
- Highly organized and detail-oriented; able to work in a fast-paced, metrics-driven environment
- Proficiency in Microsoft Office Suite, Word, Excel, Wiki, collaborative cloud-based programs, and third-party software applications
- Commitment to company values
- Ability to operate standard office equipment and keyboards
- Ability to accurately interpret sounds and associated meanings at interpersonal-conversation volume
- Ability to adhere to process protocol and apply established protocols in a timely manner
- Availability primarily Monday through Friday during the business week
- Travel 5% or less
Benefits:
- Medical insurance
- Dental insurance
- Vision insurance
- Life insurance
- AD&D insurance
- LTD insurance
- 401(k) with employer match
- Competitive compensation
- Pleasant work environment




















