Manage vulnerability remediation processes, track remediation status, and provide recommendations for process improvements. Ensure vulnerabilities are categorized and prioritized based on risk and align with NIST guidance. Develop and document remediation timelines and track progress.
Key Highlights
Key Responsibilities
Technical Skills Required
Benefits & Perks
Job Description
Information Security Manager 3
Austin, TX (100% Remote)
Vulnerability Inventory and Baseline Establishment:
1. Review the Agency’s existing vulnerability data, including vulnerabilities identified through scanning, assessments, or other security tools.
2. Establish and maintain a consolidated vulnerability baseline.
3. Develop and document a remediation timeline for all identified vulnerabilities, reflecting current risk posture and aging.
Risk Classification and Prioritization:
1. Ensure that vulnerabilities are categorized and prioritized based on risk, severity, exploitability, and potential impact to Agency operations.
2. Align vulnerability classification and prioritization to applicable NIST guidance.
Remediation Coordination and Communication:
1. Validate that remediation timeframes align with Agency established expectations for different vulnerability risk levels.
2. Coordinate remediation activities with system, server, and application owners.
3. Communicate clear remediation expectations, risk context, and required timelines to responsible parties.
4. Track remediation progress and identify blockers, dependencies, or delays impacting closure.
Interested in remote work opportunities in Cyber Security? Discover Cyber Security Remote Jobs featuring exclusive positions from top companies that offer flexible work arrangements.
5. Escalate overdue, high risk, or critical vulnerabilities to appropriate Agency governance or oversight bodies, in accordance with Agency processes.
Tracking, Metrics, and Reporting:
1. Maintain ongoing tracking of vulnerability remediation status.
2. Produce periodic status reports summarizing.
Validation and Closure:
1. Validate remediation actions through available evidence, including vulnerability scan results or other supporting artifacts.
2. Confirm closure of vulnerabilities in tracking systems once remediation is completed and validated.
3. Ensure vulnerabilities that cannot be remediated within required timeframes are formally documented and supported by approved risk acceptance or exception documentation, in accordance with Agency policy.
Program Improvement Support:
1. Identify process gaps, systemic issues, or control weaknesses affecting vulnerability remediation effectiveness.
2. Provide recommendations for improving vulnerability remediation processes and accountability, aligned with NIST standards and Agency governance requirements.
Candidate Skills and Qualifications:
Browse our curated collection of remote jobs across all categories and industries, featuring positions from top companies worldwide.
Years
Required/Preferred
Experience
8
Required
Experience in Vulnerability Inventory and Baseline Establishment
8
Required
Experience in Risk Classification and Prioritization
8
Required
Experience in tracking vulnerability remediation
8
Required
Experience in producing status reports
8
Required
Experience in validating remediation actions through available evidence, including vulnerability scan results
Similar Jobs
Explore other opportunities that match your interests
Alignerr
Cybersecurity & Identity Protection Engineer
BLACKCLOAK