Cybersecurity Vulnerability & Exposure Management Lead
AxaltaAbout the role
JOB TITLE: Cybersecurity Vulnerability & Exposure Management Lead
Position Summary:
We are hiring an experienced candidate to lead the operation and advancement of our threat informed, risk-based vulnerability and exposure management program. This role is responsible for measurable reduction of enterprise exposure by driving accountability with technology teams in vulnerability remediation and configuration hardening. The primary focus of the role revolves around driving high-fidelity visibility into enterprise exposure using a combination of approaches including agents, network scanning, and integration of telemetry from cloud, endpoint, and infrastructure platforms with a continuous focus on implementing actionable risk reduction. This is a strategic, high-impact position focused on delivering clarity, driving action, and sustaining program momentum across a complex global enterprise.
We are an equal opportunity employer and will not be offering visa sponsorship nor relocation assistance for this role.
Key Responsibilities:
- Lead the operation and continuous improvement of the enterprise vulnerability and exposure management program.
- Leverage vulnerability management and configuration assessment technologies to evaluate infrastructure, cloud, and application risk.
- Drive risk-based prioritization remediation planning that incorporates KEV, EPSS, configuration hardening benchmarks, asset criticality, and business context.
- Own assessment of emerging threats and critical vulnerabilities partnering with GRC to document risk response, and Security Architecture, Engineering & SOC to operationalize mitigation strategies.
- Drive end-to-end visibility into vulnerability and configuration posture across endpoints, servers, network devices, and cloud assets by leveraging agent-based telemetry, authenticated scanning, and integration of data from external platforms via API integration.
- Continuously assess asset coverage and data fidelity, identifying and closing gaps in visibility that impact exposure reporting and remediation effectiveness.
- Develop and deliver strategic reporting, dashboards, and executive summaries for IT leadership.
- Develop tactical and prioritized remediation plans for technology teams aligned with asset ownership, feasibility, and risk reduction focus.
- Own exposure-related metrics, SLA tracking, and remediation accountability across technology teams and/or business owners.
- Drive program execution using both internal resources and external services; ensure external support is integrated, efficient, and aligned with internal vulnerability and risk reduction objectives.
- Build scalable workflows, governance, and exception handling models that integrate with existing IT processes.
- Lead project and program execution for continuous improvement of the vulnerability lifecycle, hardening posture, and partner with GRC for integrated risk reporting.
Requirements:
- Minimum 7 years of cybersecurity experience in a large, distributed environment with vulnerability management, exposure analysis, and technical risk remediation roles, including at least 3 years in a program lead capacity driving improved capability maturity.
- Hands on experience and deep understanding of operationalizing technical vulnerability management & security configuration hardening with tools including vulnerability scanners, CIS Benchmarks, and application security testing tools. With specific knowledge of the following preferred: Qualys VMDR; Policy Compliance for CIS Benchmark assessment per class of asset; Total AppSec for security testing of web applications and APIs.
- Strong knowledge of risk-based prioritization mechanisms including KEV, EPSS, MITRE ATT&CK, and CIS Critical Controls.
- Proficiency in reporting and data visualization using Word, Excel, PowerPoint and visualization platforms such as Power BI; able to distill technical exposure into concise, actionable business insights.
- Experience managing or integrating telemetry from endpoint agents, network scanners, CMDBs, or cloud asset APIs.
- Strong knowledge of and engineering experience with Windows, Linux, Databases, Web Applications, Cloud, DNS, PKI, and Encryption.
- Minimum of 5 years' experience implementing security strategy and protecting assets in hybrid cloud and on-prem environments; experience with Azure, M365, and E
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s