Talent.com
Cybersecurity Vulnerability & Exposure Management Lead

Cybersecurity Vulnerability & Exposure Management Lead

Axalta Coating SystemsUSA, Pennsylvania, Philadelphia
job_description.job_card.30_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

JOB TITLE : Cybersecurity Vulnerability & Exposure Management Lead

Position Summary :

We are hiring an experienced candidate to lead the operation and advancement of our threat informed, risk-based vulnerability and exposure management program. This role is responsible for measurable reduction of enterprise exposure by driving accountability with technology teams in vulnerability remediation and configuration hardening. The primary focus of the role revolves around driving high-fidelity visibility into enterprise exposure using a combination of approaches including agents, network scanning, and integration of telemetry from cloud, endpoint, and infrastructure platforms with a continuous focus on implementing actionable risk reduction. This is a strategic, high-impact position focused on delivering clarity, driving action, and sustaining program momentum across a complex global enterprise.

We are an equal opportunity employer and will not be offering visa sponsorship nor relocation assistance for this role.

Key Responsibilities :

  • Lead the operation and continuous improvement of the enterprise vulnerability and exposure management program.
  • Leverage vulnerability management and configuration assessment technologies to evaluate infrastructure, cloud, and application risk.
  • Drive risk-based prioritization remediation planning that incorporates KEV, EPSS, configuration hardening benchmarks, asset criticality, and business context.
  • Own assessment of emerging threats and critical vulnerabilities partnering with GRC to document risk response, and Security Architecture, Engineering & SOC to operationalize mitigation strategies.
  • Drive end-to-end visibility into vulnerability and configuration posture across endpoints, servers, network devices, and cloud assets by leveraging agent-based telemetry, authenticated scanning, and integration of data from external platforms via API integration.
  • Continuously assess asset coverage and data fidelity, identifying and closing gaps in visibility that impact exposure reporting and remediation effectiveness.
  • Develop and deliver strategic reporting, dashboards, and executive summaries for IT leadership.
  • Develop tactical and prioritized remediation plans for technology teams aligned with asset ownership, feasibility, and risk reduction focus.
  • Own exposure-related metrics, SLA tracking, and remediation accountability across technology teams and / or business owners.
  • Drive program execution using both internal resources and external services; ensure external support is integrated, efficient, and aligned with internal vulnerability and risk reduction objectives.
  • Build scalable workflows, governance, and exception handling models that integrate with existing IT processes.
  • Lead project and program execution for continuous improvement of the vulnerability lifecycle, hardening posture, and partner with GRC for integrated risk reporting.

Requirements :

  • Minimum 7 years of cybersecurity experience in a large, distributed environment with vulnerability management, exposure analysis, and technical risk remediation roles, including at least 3 years in a program lead capacity driving improved capability maturity.
  • Hands on experience and deep understanding of operationalizing technical vulnerability management & security configuration hardening with tools including vulnerability scanners, CIS Benchmarks, and application security testing tools. With specific knowledge of the following preferred : Qualys VMDR; Policy Compliance for CIS Benchmark assessment per class of asset; Total AppSec for security testing of web applications and APIs.
  • Strong knowledge of risk-based prioritization mechanisms including KEV, EPSS, MITRE ATT&CK, and CIS Critical Controls.
  • Proficiency in reporting and data visualization using Word, Excel, PowerPoint and visualization platforms such as Power BI; able to distill technical exposure into concise, actionable business insights.
  • Experience managing or integrating telemetry from endpoint agents, network scanners, CMDBs, or cloud asset APIs.
  • Strong knowledge of and engineering experience with Windows, Linux, Databases, Web Applications, Cloud, DNS, PKI, and Encryption.
  • Minimum of 5 years' experience implementing security strategy and protecting assets in hybrid cloud and on-prem environments; experience with Azure, M365, and Entra / Azure AD preferred.
  • Proven ability to drive cross-functional accountability across IT, cloud, and application teams.
  • Exceptional communication skills, with the ability to translate technical security risk into business-relevant language for technical teams and IT leadership.
  • Demonstrated experience managing or integrating managed service providers as part of a vulnerability management program.
  • Strong project and program management capabilities, with excellent organizational, problem-solving, and stakeholder engagement skills; able to manage multiple initiatives, drive accountability, and influence cross-functional teams.
  • Proven ability to operate effectively in a matrixed environment by partnering with Security GRC and Security Engineering / Operations teams to align on risk response, hardening strategies, exception handling, and program execution.
  • Education & Certification :

  • Bachelor's degree required in Information Technology, Computer Science, Cybersecurity, Computer Engineering, Security Risk Analysis, Information Security & Assurance or other relevant focus area.
  • Possess a minimum of one of the following certifications : CISSP, CISM, GSOM, GCCC, GCED, GPEN, ISSAP or ISSEP. If not currently certified, required to obtain certification(s) within the first 12 months of employment.
  • Our Company :

    Axalta has remained at the forefront of the coatings industry by continually investing in innovative solutions. We engineer technologies that protect customers' products - whether they are battling heat, light, corrosion, abrasion, moisture, or chemicals - and add dimension and beauty with colorful finishes. We have a vast and ever-evolving portfolio of brands primed to play an important part in everything from modernizing infrastructure around the world to enabling the next generation of electric and autonomous vehicles.

    Axalta operates its business in two segments : Performance Coatings and Mobility Coatings, which serve four end markets, including Refinish, Industrial, Light Vehicle and Commercial Vehicle, across North America, EMEA, Latin America and Asia-Pacific. Our diverse global footprint allows us to deliver solutions in over 140+ countries and coat 30 million vehicles per year. We've recently set an exciting 2040 carbon neutrality goal, in addition to 10 other sustainability initiatives, and we take pride in working with our customers to optimize their businesses and achieve their goals.

    1.2 - First / Mid Level Officials and Managers (EEO-1 Job Categories-United States of America)

    serp_jobs.job_alerts.create_a_job

    Lead Cybersecurity • USA, Pennsylvania, Philadelphia

    Job_description.internal_linking.related_jobs
    • serp_jobs.job_card.promoted
    Senior Security Engineer

    Senior Security Engineer

    VirtualVocationsPhiladelphia, Pennsylvania, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Security Engineer to ensure the security of their cloud infrastructure and software systems. Key Responsibilities Design, implement, and maintain secure cloud arc...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Vice President - Global Solutions Leader - Cloud, Applications & Infrastructure

    Vice President - Global Solutions Leader - Cloud, Applications & Infrastructure

    Unisys CorporationBlue Bell, PA, United States
    serp_jobs.job_card.full_time
    What success looks like in this role : .CA&I Solution executive leader responsible for shaping, building and enabling solutions by connecting market, clients, partners, and delivery.Responsible to le...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Cloud Incident Response Consultant

    Cloud Incident Response Consultant

    VirtualVocationsPhiladelphia, Pennsylvania, United States
    serp_jobs.job_card.full_time
    A company is looking for a Consultant, Cloud Incident Response (Remote).Key Responsibilities Serve as part of the technical team on incident response engagements Develop and use new methods to h...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Cyber Security Engineer

    Senior Cyber Security Engineer

    VirtualVocationsPhiladelphia, Pennsylvania, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Cloud Security Engineer to join their team.Key Responsibilities Manage enterprise-wide security tools and platforms, including SIEM, DLP, and vulnerability manag...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Cybersecurity Analyst

    Senior Cybersecurity Analyst

    VirtualVocationsPhiladelphia, Pennsylvania, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Cybersecurity Analyst to enhance its cyber threat intelligence capabilities.Key Responsibilities Monitor the threat landscape to identify new tactics and techniq...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Director of Security Engineering

    Director of Security Engineering

    VirtualVocationsPhiladelphia, Pennsylvania, United States
    serp_jobs.job_card.full_time
    A company is looking for a Director of Cyber Defense Engineering.Key Responsibilities Lead the development and deployment of an AI-enhanced Security Operations Center (SOC) Define architecture f...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Security Solutions Manager

    Security Solutions Manager

    Unisys CorporationBlue Bell, PA, United States
    serp_jobs.job_card.full_time
    What success looks like in this role : .Design and develop full stack security architectures covering application security, API security, zero trust, identity & access management, cloud security, sec...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Director of Incident Response

    Director of Incident Response

    VirtualVocationsPhiladelphia, Pennsylvania, United States
    serp_jobs.job_card.full_time
    A company is looking for a Director of Incident Response.Key Responsibilities Lead engagement scoping and coordinate with victims of ransomware and forensic partners Manage workload distribution...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Cybersecurity Product Owner

    Cybersecurity Product Owner

    VirtualVocationsPhiladelphia, Pennsylvania, United States
    serp_jobs.job_card.full_time
    A company is looking for a Cybersecurity Product Owner.Key Responsibilities Collaborate with cross-functional teams to deliver value through customer-focused experiences Maintain and prioritize ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Cyber Risk Advisor

    Cyber Risk Advisor

    VirtualVocationsPhiladelphia, Pennsylvania, United States
    serp_jobs.job_card.full_time
    A company is looking for a Cyber Risk Advisor.Key Responsibilities Serve as a trusted advisor, simplifying vulnerabilities and guiding customers in cyber risk mitigation Lead advisory sessions t...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Cloud Cybersecurity Expert

    Cloud Cybersecurity Expert

    VirtualVocationsPhiladelphia, Pennsylvania, United States
    serp_jobs.job_card.full_time
    A company is looking for a Cloud Cybersecurity Subject Matter Expert.Key Responsibilities Develop, assess, and maintain cybersecurity controls across cloud systems Ensure RMF, STIG, NIST SP 800-...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Manager, Application Security

    Senior Manager, Application Security

    VirtualVocationsPhiladelphia, Pennsylvania, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Manager, Application Security to lead teams in Product Security, Vulnerability Management, and Security Assessments. Key Responsibilities : Manage and mentor teams...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Cybersecurity Analyst

    Cybersecurity Analyst

    VirtualVocationsPhiladelphia, Pennsylvania, United States
    serp_jobs.job_card.full_time
    A company is looking for a Joint Cybersecurity Analyst to support the Federal Electronic Health Records Modernization office. Key Responsibilities Coordinate cyber operational processes across DoD...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Threat Hunter

    Threat Hunter

    VirtualVocationsPhiladelphia, Pennsylvania, United States
    serp_jobs.job_card.full_time
    A company is looking for a Threat Hunter to proactively identify and mitigate threats using advanced SPL queries in Splunk. Key Responsibilities Develop SPL queries to detect IOCs, anomalies, and ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Senior Incident Response Analyst

    Senior Incident Response Analyst

    VirtualVocationsPhiladelphia, Pennsylvania, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Incident Response Analyst who will be responsible for cybersecurity incident response and threat analysis. Key Responsibilities Monitor, identify, investigate, an...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Cybersecurity A&A Subject Matter Expert

    Cybersecurity A&A Subject Matter Expert

    VirtualVocationsPhiladelphia, Pennsylvania, United States
    serp_jobs.job_card.full_time
    A company is looking for a Cybersecurity Assessment & Authorization (A&A) SME.Key Responsibilities Serve as a DOD cybersecurity SME for information systems undergoing A&A Apply NIST 800-53 secur...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Cybersecurity Technical Assessor

    Cybersecurity Technical Assessor

    VirtualVocationsPhiladelphia, Pennsylvania, United States
    serp_jobs.job_card.full_time
    A company is looking for a Technical Assessor - Cybersecurity.Key Responsibilities Assess the effectiveness of security controls and recommend vulnerability remediation strategies Document devia...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Lead Security Engineer - Cyber Security

    Lead Security Engineer - Cyber Security

    RelativityPhiladelphia, PA, United States
    serp_jobs.job_card.full_time
    As a Lead Cyber Security Engineer, you will ensure the security of Relativity's network and infrastructure.In this role, the main responsibilities will be to investigate and analyze emerging threat...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30