Jobs and Careers
CN

Director of Vulnerability Management

CNA Insurance
US-USXX-USA- Work at Home, United States, United StatesRemotefull_timeVerifiedPosted 19 Aug 2025
💰 $189,000/yr($97,000/yr$189,000/yr)

About the role

You have a clear vision of where your career can go. And we have the leadership to help you get there. At CNA, we strive to create a culture in which people know they matter and are part of something important, ensuring the abilities of all employees are used to their fullest potential. 

Leadership position responsible for transforming and accelerating Vulnerability Management (VM) into a core information security strength. This position plays a pivotal role in safeguarding CNA’s assets by leading an enterprise-wide VM program and team, developing strategy, driving priorities and initiatives with partners, and managing vulnerabilities per organizational risk tolerance across on-premises and cloud environments. This role blends deep technical expertise (70%) with strategic leadership (30%), ensuring vulnerabilities across our environment are identified, prioritized, and remediated in a timely manner. This role demands a strategic mindset, robust technical aptitude, and the ability to communicate risk and remediation status effectively throughout the business. The ideal candidate will thrive in a fast-paced environment, demonstrate exceptional technical depth, and possess strong leadership skills to influence across technical and business teams.

JOB DESCRIPTION:

Essential Duties & Responsibilities 

Performs a combination of duties in accordance with departmental guidelines: 

 

Technical (70%) 

  • Leads and executes a comprehensive Vulnerability Management program throughout a global technology organization leveraging legacy and modern assets and applications located on-premises and in the cloud. 

  • Own and operate the enterprise vulnerability management program, including vulnerability scanning, reporting, and remediation tracking. 

  • Builds and nurtures strong partnerships with asset owners and managed service providers to drive vulnerability remediation, mitigation, reduce exposure and potential business impact, and ensure secure asset configurations. 

  • Oversee and technically validate the MSP’s delivery of vulnerability scanning and assessments using Tenable tools. 

  • Accountable for the vulnerability remediation process within CNA, which may include vulnerabilities discovered through, but not limited to, vulnerability scanning, ethical hacking, threat intelligence, application security, responsible disclosure, etc. 

  • Holistically owns the secure configuration management process within CNA, which may include working with various teams in developing secure technical specifications for technologies, assessing the environment against those specifications, and continuously improving the posture through governance and technical leadership.  

  • Develops enterprise policy, standards, plans, strategy, and procedures with specific regard to vulnerability management and secure configuration in alignment with business, industry, and regulatory requirements ensuring adherence across the enterprise to avoid audit findings and compliance gaps. 

  • Develops and presents VM program metrics, KPIs, KRIs, and other applicable performance reporting measures to communicate risk and program effectiveness to governance and leadership. 

  • Perform detailed analysis of vulnerability data to identify trends, recurring issues, and systemic weaknesses, and use this analysis to prioritize remediation efforts based on risk and business impact. 

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

CNA Insurance

View company profile →