远程工作雷达

高级经理,网络安全,CTEM 与漏洞情报 - 远程

Senior Manager, Cybersecurity, CTEM & Vulnerability Intelligence - Remote

开发工程职能支持限定地区(需当地身份)
公司Stryker
薪资$155,900 - $337,600/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Full Time
发布时间昨天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

工作灵活性:远程
优先考虑居住在东部或中部时区的候选人。

作为高级经理,CTEM与漏洞管理,您将领导企业连续威胁暴露管理(CTEM)和漏洞管理职能,涵盖企业IT、云、操作技术(OT)和产品环境。您将与产品安全、威胁情报、安全运营、基础设施、云和工程团队合作,通过基于风险的发现、优先级排序、验证和修复来降低暴露风险。

您将负责:

技术职责:

•领导企业CTEM和漏洞管理计划,包括其战略、路线图和运营模式。

•监督基础设施、云、终端、应用、身份、网络和OT环境中的漏洞扫描和评估。

•与产品安全团队管理产品安全漏洞生命周期,包括接收、分类、风险评估、修复跟踪、软件物料清单(SBOM)分析和协调漏洞披露支持。

•使用CVSS、EPSS、CISA已知被利用漏洞(KEV)、威胁情报、资产关键性及业务背景对漏洞和暴露进行优先级排序。

•领导攻击面管理、暴露验证和渗透与攻击模拟活动,以确认可利用性和控制有效性。

•评估影响企业系统、市场产品和嵌入式系统的新兴漏洞、利用方式和威胁情报。

•通过SOAR平台、API、Python或PowerShell推动漏洞发现、数据增强、工单处理、修复流程和报告的自动化。

•在网络安全事件调查中提供漏洞背景、暴露分析和修复专业知识支持。

领导力与人员管理职责:

•与基础设施、云、应用、产品安全和工程团队合作,建立基于风险的服务级别协议,推动修复并跟踪行动计划和里程碑。

•建立漏洞和暴露管理运营的治理标准、质量保证流程和文档。

•衡量并报告暴露减少、修复表现、验证结果和运营指标,向高管利益相关者汇报。

•领导漏洞管理、暴露管理或产品安全漏洞团队。

知识要求:

查看英文原文

Work Flexibility: Remote
Preference will be given to candidates residing in the Eastern or Central time zones.

As a Senior Manager, CTEM & Vulnerability Management, you will lead the enterprise Continuous Threat Exposure Management (CTEM) and Vulnerability Management function across enterprise IT, cloud, operational technology (OT), and product environments. You will partner with Product Security, Threat Intelligence, Security Operations, Infrastructure, Cloud, and Engineering teams to reduce exposure through risk-based discovery, prioritization, validation, and remediation.

What you will do:

Technical Responsibilities:

•Lead the enterprise CTEM and Vulnerability Management program, including its strategy, roadmap, and operating model.

•Oversee vulnerability scanning and assessment across infrastructure, cloud, endpoint, application, identity, network, and OT environments.

•Manage the product security vulnerability lifecycle with Product Security, including intake, triage, risk assessment, remediation tracking, software bill of materials (SBOM) analysis, and coordinated vulnerability disclosure support.

•Prioritize vulnerabilities and exposures using CVSS, EPSS, CISA Known Exploited Vulnerabilities (KEV), threat intelligence, asset criticality, and business context.

•Lead attack surface management, exposure validation, and breach and attack simulation activities to confirm exploitability and control effectiveness.

•Evaluate emerging vulnerabilities, exploits, and threat intelligence affecting enterprise systems, marketed products, and embedded systems.

•Drive automation for vulnerability discovery, data enrichment, ticketing, remediation workflows, and reporting through SOAR platforms, APIs, Python, or PowerShell.

•Support cyber incident investigations with vulnerability context, exposure analysis, and remediation expertise.

Leadership & People Management Responsibilities:

•Partner with Infrastructure, Cloud, Application, Product Security, and Engineering teams to establish risk-based service-level agreements, drive remediation, and track plans of action and milestones.

•Establish governance standards, quality assurance procedures, and documentation for vulnerability and exposure management operations.

•Measure and report exposure reduction, remediation performance, validation results, and operational metrics to executive stakeholders.

•Lead vulnerability management, exposure management, or product security vulnerability teams.

Knowledge and Capabilities:

•Analyze complex vulnerability data and large volumes of exposure telemetry to identify risk and guide response.

•Translate technical findings, remediation status, and risk trends into clear written, verbal, and presentation-ready updates for technical and executive audiences.

What You Need:

Required Qualifications

•Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related discipline.

•Minimum 10 years of experience in cybersecurity.

•Minimum 3 years of experience leading vulnerability management, exposure management, or product security vulnerability teams.

•Experience managing product vulnerabilities, including triage, coordinated vulnerability disclosure, SBOM analysis, and remediation with product engineering teams.

•Experience with Tenable, Qualys, Rapid7, Wiz, ServiceNow Vulnerability Response, or equivalent vulnerability and exposure management technologies.

•Experience implementing automation through SOAR platforms, APIs, Python, or PowerShell.

Preferred Qualifications

•Master's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related discipline.

•CISSP, CISM, GEVA, GPEN, GIAC, Tenable, Qualys, or equivalent professional certification.

United States of America Pay Ranges:

  • USN: $155,900 - $259,700 USD Annual
  • US5: $163,700 - $272,700 USD Annual
  • US10: $171,500 - $285,700 USD Annual
  • US15: $179,300 - $298,700 USD Annual
  • US20: $187,100 - $311,600 USD Annual
  • US30: $202,700 - $337,600 USD Annual

View the U.S. work location and transparency guide to find the pay range for your location.
Travel Percentage: NoneStryker Corporation is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, gender identity, sexual orientation, national origin, disability, or protected veteran status. Stryker is an EO employer – M/F/Veteran/Disability.Stryker Corporation will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor’s legal duty to furnish information.Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

高级经理, 传播事务

StrykerUnited States$135,600 - $293,700/年Full Time今天
市场运营限定地区(需当地身份)

← 返回全部职位