- Company Name
- PRI Technology
- Job Title
- Vulnerability Operations Lead
- Job Description
-
**Job Title:** Vulnerability Operations Lead
**Role Summary:**
Lead the enterprise vulnerability management program, executing scans, validating findings, and driving remediation across IT, OT, and cloud environments. Serve as the second line of defense, coordinate with asset owners, and ensure compliance with security policies and SLAs.
**Expectations:**
- Work 4 days onsite and 1 day remote.
- Maintain timely remediation of vulnerabilities and escalations per SLA.
- Provide leadership on critical vulnerability response and continuous improvement of processes.
**Key Responsibilities:**
- Perform authenticated and unauthenticated vulnerability scans on IT, OT, and cloud assets using enterprise tools (e.g., Tenable, Rapid7, Qualys).
- Triage and validate scan results to reduce false positives.
- Analyze vulnerabilities with threat intelligence and business impact scoring (CVSS).
- Collaborate with asset owners to assess exposure and recommend remediation or mitigation.
- Track remediation progress, create and manage tickets in ServiceNow, Jira, or similar platforms.
- Escalate overdue issues according to defined SLA thresholds.
- Lead company‑wide response efforts for critical vulnerabilities.
- Generate and maintain dashboards, reports, and KPIs on vulnerability trends and exceptions.
- Support internal and external audits by providing evidence of scanning, remediation, and compliance.
- Contribute to automation, workflow enhancements, playbooks, SOPs, and knowledge‑base documentation.
**Required Skills:**
- Strong experience with vulnerability management tools (Tenable, Rapid7, Qualys).
- Deep understanding of CVSS scoring, patch management, and exploitability metrics.
- Knowledge of cloud, container, and OT vulnerability landscapes.
- Proficiency with CMDB/ticketing systems (ServiceNow, Jira) and familiarity with SIEM/SOAR platforms.
- Ability to analyze threat intelligence and communicate risk to technical and business stakeholders.
- Strong organizational, reporting, and documentation skills.
**Required Education & Certifications:**
- Bachelor’s degree in Cybersecurity, Computer Science, Engineering, or related field.
- Relevant security certifications preferred (e.g., Security+, SANS GIAC, OSCP).
- Additional certifications or experience in OT security considered a strong plus.