Contribute to and help mature our vulnerability management program, ensuring identified risks are remediated according to SLAs across the enterprise and business units
Identify and report known vulnerabilities across infrastructure (cloud and on-prem), applications, software, AI systems, and external attack surface
Monitor external attack surface exposures and contribute to remediation prioritization
Produce vulnerability metrics, trending reports, and risk summaries for security leadership and business unit stakeholders
Support alignment of the VM program with industry regulations and standards (PCI-DSS, SOC2, NIST CSF, ISO 27001)
Collaborate with Security, IT, and BU Engineering teams to drive effective and measurable vulnerability and risk exposure outcomes
Contribute to risk management and governance functions (e.g., risk register, key metrics, vulnerability reports)
Develop and contribute to AI-assisted HITL (Human in the Loop) automation and workflows for Proactive Security initiatives
Collaborate with and learn alongside other Proactive Security team members
Requirements
8+ years of Information Technology / Security experience with 2-4+ years of hands-on experience in vulnerability management, attack surface management, or related security functions
Working knowledge of security tools such as Wiz, Snyk, Qualys, Nessus, MS Defender, or similar platforms
Experience with vulnerability prioritization frameworks (CVSS, EPSS, risk-based scoring)
Experience with application security testing concepts and tools (SAST, DAST, IAST, Burp Suite, Postman, GitHub, etc.)
Basic scripting or programming experience in any language, or a strong desire to develop this skill
Ability to produce clear, actionable security reporting for both technical and non-technical audiences