Remote (Global)

CNA is hiring a Director of Vulnerability Management

About the Role

Oversee the strategy and execution of vulnerability management initiatives to protect organizational assets by identifying, prioritizing, and resolving security flaws across technology environments.

Responsibilities

  • Develop and maintain a company-wide vulnerability management framework
  • Lead teams responsible for identifying and tracking system vulnerabilities
  • Establish risk-based prioritization protocols for remediation efforts
  • Collaborate with IT and security teams to integrate vulnerability scanning into operations
  • Monitor emerging threats and adjust detection methods accordingly
  • Report vulnerability metrics and trends to executive stakeholders
  • Ensure compliance with internal policies and external regulatory requirements
  • Evaluate and deploy advanced vulnerability assessment tools and technologies
  • Drive automation to improve detection and response efficiency
  • Coordinate with third-party vendors for security assessments
  • Oversee patch management coordination across business units
  • Lead incident response activities related to critical vulnerabilities
  • Develop training materials for security best practices
  • Foster a culture of proactive risk management across technical teams
  • Manage budgets and resources for vulnerability programs
  • Assess cloud environment security configurations for weaknesses
  • Implement continuous monitoring strategies for dynamic infrastructure
  • Work with developers to integrate security into software delivery pipelines
  • Maintain documentation of policies, procedures, and controls
  • Support audits and security certifications with accurate reporting
  • Evaluate third-party risk through vulnerability data analysis
  • Align vulnerability strategy with overall cybersecurity roadmap
  • Promote cross-functional collaboration to resolve complex security issues
  • Stay current with industry standards and threat intelligence
  • Ensure timely escalation of critical findings to leadership

Compensation

Competitive salary and benefits package commensurate with experience

Work Arrangement

Hybrid work model with flexibility based on role and location

Team

Part of the enterprise cybersecurity leadership team focused on threat reduction and resilience

Why This Role Matters

This position plays a critical role in reducing the organization's attack surface by leading efforts to find and fix security weaknesses before they can be exploited.

What We Value

We prioritize proactive risk management, data-driven decision-making, and collaboration across technical and business units to strengthen security resilience.

Not available for this position

Required Skills
GCPAWSMicrosoft AzureWindowsLinuxUNIXRisk ManagementTeam LeadershipProject ManagementCompliance
About company
CNA
CNA is an insurance company focused on creating a culture that values employee potential and professional growth.
All jobs at CNA Visit website
Job Details
Category management
Posted 10 months ago