Jobs and Careers
CL

Director, Vulnerability Management

Cloudflare, Inc.
UKRemotefull_timeVerifiedPosted 30 Jun 2025

About the role

About Us

At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company. 

We realize people do not fit into neat boxes. We are looking for curious and empathetic individuals who are committed to developing themselves and learning new skills, and we are ready to help you do that. We cannot complete our mission without building a diverse and inclusive team. We hire the best people based on an evaluation of their potential and support them throughout their time at Cloudflare. Come join us! 

Available Locations: London, England | Lisbon, Portugal | Austin, Texas

About the role 

We are seeking an experienced Director of Vulnerability Management to lead and mature our security program in this critical area. This role is responsible for defining, implementing, and overseeing the comprehensive strategy for identifying, assessing, prioritizing, and remediating vulnerabilities across our entire technology stack, including applications throughout the software development lifecycle.

What You’ll Do

  • Develop and lead teams of skilled professionals in the areas of vulnerability management and application security. 
  • Enhance and execute comprehensive strategies for vulnerability management and application security that align with the company's risk appetite and business objectives.
  • Define and track key performance indicators (KPIs) and metrics to measure the effectiveness of security programs and report on progress to executive leadership.
  • Stay abreast of emerging threats, vulnerabilities, and security technologies to continuously evolve and improve security posture.
  • Advocate for and secure resources (budget, personnel, tools) necessary to achieve program objectives.
  • Recruit, mentor, and develop a high-performing team of security engineers and analysts.
  • Foster a culture of continuous learning, collaboration, and accountability within the security team.
  • Provide strong technical leadership and guidance to direct reports and cross-functional teams.
  • Contribute to the development and enforcement of security policies, standards, and procedures.
  • Support internal and external audits by providing evidence of security controls and processes.
  • Ensure compliance with internal policies, relevant industry regulations and frameworks.
  • Partner closely with engineering, product, IT, and legal teams to embed security best practices throughout the organization.
  • Communicate complex security concepts and risks effectively to both technical and non-technical stakeholders.
  • Mature the existing vulnerability management program covering infrastructure, networks, containers, cloud environments, and endpoints.
  • Oversee the selection, implementation, and optimization of vulnerability scanning tools (e.g. DAST, SAST, SCA, secrets detections, and web application and infrastructure vulnerability scanners) and platforms, and integration into CI/CD pipelines and infrastructure.
  • Ensure security technology strategies are aligned with companies' business goals.
  • Enforce policies and procedures for vulnerability identification, assessment, prioritization, remediation, and tracking.
  • Collaborate with IT operations, engineering, and development teams to ensure timely and effective remediation of identified vulnerabilities.
  • Develop security policies, procedures, and guidelines and recommend necessary changes to a given project team to ensure the company’s systems are fully compliant with all applicable regulatory requirements and privacy laws.
  • Utilize open communication and managerial courage to ensure the standards, expectations and goals of the organization are respected and upheld.
  • Manage the bug bounty program and external application penetration testing engagements.
  • Ensure the application security program is integrated into every phase of the software development lifecycle.
  • Define and implement secure coding standards, guidelines, and best practices.
  • Collaborate closely with develop

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Cloudflare, Inc.

View company profile →