Forge the Future of Cloud Security: Manager, Vulnerability Management at Vult
Vultr isn't just a cloud provider; we are a foundational pillar for enterprises and AI innovators worldwide, making high-performance cloud infrastructure accessible, affordable, and globally distributed. With a staggering 33 global cloud data center locations, Vultr empowers hundreds of thousands of active customers across 185 countries with flexible, scalable solutions across Cloud Compute, Cloud GPU, Bare Metal, and Cloud Storage.
Propelled by a recent equity financing valuing us at $3.5 billion in December 2024, and proudly self-funded for over a decade by founder David Aninowsky, Vultr has grown to become the world’s largest privately-held cloud infrastructure company. This incredible scale and growth demand an equally robust security posture – and that's where you come in.
The Opportunity: Lead Our Vulnerability Management Program
Vultr is seeking a visionary and technically astute Manager of Vulnerability Management to take the helm of our defense strategy. This critical leadership role involves owning the infrastructure, processes, and a talented team dedicated to identifying, prioritizing, and driving the remediation of vulnerabilities across Vultr’s expansive technology stack. You will balance deep technical expertise with impactful organizational influence, ensuring our vulnerability management activities are executed flawlessly while continuously enhancing the systems that enable them. If you possess a profound understanding of vulnerability management program design and direction, and are ready to mentor and empower a team, this is your chance to make a monumental impact.
Your Impact & Key Responsibilities:
Team Leadership & Development: Empower, guide, and mentor a team of skilled vulnerability analysts, fostering their professional growth, overseeing performance, and setting daily operational priorities.
Strategic Remediation Ownership: Partner with critical internal stakeholders to drive complex remediation efforts to completion, skillfully negotiate priorities and timelines, escalate blocked remediations, and champion a risk-based approach to all remediation prioritization.
Continuous Program Evolution: Proactively identify opportunities for innovation and improvement, benchmark program maturity against leading industry frameworks, solicit and integrate feedback to refine remediation procedures, and embed lessons learned into our policies and processes.
Audit & Compliance Expertise: Serve as the primary subject matter expert during internal and external audits, providing meticulous remediation evidence, policy attestations, and translating audit findings into clear, actionable remediation plans.
Incident Response Authority: Act as the definitive vulnerability management authority, providing critical insights and guidance during security incidents and broader security operational engagements.
What You Bring:
Foundational Experience: A minimum of 5 years in cybersecurity, with at least 3 years specifically focused on vulnerability management. Experience within an IaaS Cloud Service Provider (CSP) or a similar technology provider is highly preferred.
Vulnerability Mastery: Comprehensive understanding and practical experience across the entire vulnerability lifecycle, including vulnerability scoring methodologies (CVSS, EPSS), robust remediation procedures, effective tracking mechanisms, and proficiency with common scanning tools such as Qualys, Tenable, and Rapid7.
Broad Technical Acumen: A strong general understanding of a wide array of software and technologies, including various Linux distributions, hypervisors, container orchestration tooling, network hardware, and communication protocols.
Compliance & Standards Prowess: Solid understanding of enterprise security standards and regulatory frameworks such as SOC 2, ISO 27001, NIST 800-53, FedRAMP, and GDPR.
Exceptional Communication: The ability to translate complex technical security concepts into clear, concise, and actionable narratives for diverse technical and non-technical stakeholders.
Educational Foundation: A Bachelor’s degree or equivalent practical experience in Computer Science, Cybersecurity, or a closely related field.
A Strategic & Operational Mindset: A methodical, detail-oriented, and self-starting individual capable of expertly managing multiple priorities under pressure in a fast-paced, dynamic environment.
Thrive at Vultr: Our Commitment to You
Comprehensive Health Coverage: 100% company-paid insurance premiums for employee medical, dental, and vision plans.
Retirement Savings: 401(k) plan with a 100% match up to 4%, with immediate vesting.
Professional Growth: Annual Professional Development Reimbursement of $2,500.
Work-Life Balance: 11 Paid Holidays + Generous Paid Time Off accrual with a rollover plan.
Rewarding Loyalty: Increased PTO at 3-year and 10-year anniversaries, a 1-month paid sabbatical every 5 years, and an Anniversary Bonus each year.
Remote Work Support: $500 stipend for remote office setup in the first year, followed by $400 each subsequent year.
Home Office Perks: Internet reimbursement up to $75 per month.
Wellness Investment: Gym membership reimbursement up to $50 per month, plus a company-paid Wellable subscription.
Compensation
$105,000 - $130,000
Final compensation will vary depending on years of experience, background/skill set, location, and applicable laws.
Inclusion & Privacy at Vultr
We are an equal opportunity employer and are committed to creating an inclusive environment for all employees. We welcome applications from individuals of all backgrounds and experiences, and we prohibit discrimination based on race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected status under applicable laws. Vultr will consider qualified applicants with arrest or conviction records in accordance with applicable laws and will not conduct a background check until after an offer of employment has been extended and accepted.
We also take your privacy seriously. We handle personal information responsibly and follow applicable laws, including U.S. privacy rules and India’s Digital Personal Data Protection Act, 2023. Your data is used only for legitimate business purposes and is protected with proper security measures.
Where allowed by law, applicants may request details about the data we collect, access or delete their information, withdraw consent for its use, and opt out of nonessential communications. For more details, please see our Privacy Policy.