Con Edison

Vulnerability Management Manager

Vulnerability Management Manager
Notice info
LocationNew York, NY
Job Typeother
Salary$145,000-$195,000
On-site
Utilities

About This Job

Overview

The Systems Manager, Vulnerability Management leads the Vulnerability Management team and drives measurable risk reduction across systems, Cloud, applications and operational technology (OT) and reports to the Director, Cybersecurity Operations while partnering closely with engineering, platform, operations, application security, cloud teams, and OT stakeholders to strengthen cloud security work tied to resource misconfigurations, advance application security through shift left and runtime security and build OT security vulnerability management capability from scratch by defining scope, intake, prioritization, remediation paths and verification, while ensuring rapid and well-coordinated response to emerging critical vulnerabilities and risks such as secrets leakage.

This role will modernize the vulnerability management program towards Continuous Threat Exposure Management (CTEM), by connecting vulnerabilities to real exposure and threat context and tracking outcomes that reflect risk reduction over time. Stakeholder management is a core responsibility, including socializing new programs, desired outcomes and operating models with engineering, platform, operations and security leadership and aligning ownership and expectations so remediation becomes predictable and measurable. You will also train and develop a team of about 9 by building repeatable operating routines, improving escalation and incident coordination, and creating skills roadmap across cloud security, application security, vulnerability workflows, runtime protection, and OT fundamentals, and you will help futureproof the capability by recruiting, onboarding, and developing additional vulnerability management talent as the program grows. In addition, the Systems Manager will participate in industry working groups and forums to collaborate with peers on CTEM and vulnerability management programs and processes.

Responsibilities Core Responsibilities

- Manage a team of about 9, coach performance and continuously build capabilities through hiring, skills plans and targeted training.

- Provide clear updates to leadership and partner teams, including project status, emerging issues and remediation progress for high severity items.

- Evolve beyond vulnerability patching by connecting vulnerabilities to exposure and threat context.

- Lead end to end intake, triage, prioritization and remediation coordination for system wide vulnerabilities.

- Identify and drive automation opportunities across scan orchestration, remediation ticketing, SLA tracking, and CI/CD pipeline integration to reduce manual effort and improve response time.

- Lead end-to-end tracking, risk assessment, and escalation for emerging critical vulnerabilities, including managing risk exceptions, proposing and documenting compensating controls and maintaining clear status updates.

- Partner with Cloud, platform and engineering stakeholders to reduce cloud risk misconfigurations. Triage findings by business impact, exploitability and exposure.

- Work with Application and Engineering Teams to prevent vulnerable code and insecure configurations earlier in the lifecycle. Ensure findings are triaged correctly, assigned owners, and tracked to SLA for remediation, with escalation when remediation is at risk.

- Drive effective Web Application Firewall operations, including rule tuning, validation and quality improvements.

- Coordinate response to runtime risks and findings discovered during execution.

- Stand up OT intake, scope, asset coverage, remediation paths and verification.

- Train internal partners on how OT findings are prioritized and handled.


Qualifications

Required Education/Experience

- Bachelor's Degree and 8 years of relevant work experience. or - Master's Degree and 6 years of relevant work experience.


Preferred Education/Experience

- Master's Degree Majors preferred in IT, computer science, business administration, engineering or related. and 6 years of relevant work experience.


Relevant Work Experience

- 6+ years in vulnerability management, security operations, application security, system security, or a related field, with proven ownership of triage and remediation workflows, required.

- Proven people leadership experience, including coaching, performance management, hiring and skills development for technical teams, required.

- Strong cloud security fundamentals, especially reducing critical and high-risk resource misconfigurations with stakeholder partners, required.

- Strong application security fundamentals, including shift left and runtime risk management, required.

- Experience leading response for critical vulnerabilities and urgent events, including zero-day response, secrets leakage triage, escalation, containment and validation, required.

- Experience tracking vulnerability and remediation metrics and building dashboards to measure SLA performance, aging, risk reduction and trends over time, required.

- Ability to turn security strategy into measurable operations, including metrics and leadership reporting, required.

- Experience standing up new programs from scratch with clear scope, intake and success criteria, required.

- Experience with CTEM or equivalent exposure management models beyond patching metrics, preferred.

- Practical WAF experience, including rule tuning, validation and improving detection quality, preferred.

- OT environment experience, or strong ability to quickly build OT vulnerability management capability, preferred.

- Experience applying vulnerability management and remediation controls to regulatory and compliance requirements, such as NERC CIP for OT and critical infrastructure, preferred.

- Certifications such as CISSP, CISM, GIAC or equivalent, required.


Licenses and Certifications

- Driver's License Required

- Project Management Professional (PMP) Training and/or certification in Project Management is a plus. Preferred


Physical Demands

- Sit or stand to answer a phone for the duration of the workday

- Sit or stand to use a keyboard, mouse, and computer for the duration of the workday

- Ability to read small print and symbols


Additional Physical Demands

- The selected candidate will be assigned a System Emergency Assignment (i.e., an emergency response role) and will be expected to work non-business hours during emergencies, which may include nights, weekends, and holidays.

- Must be able and willing to travel within Company service territory, as needed.

Similar Jobs

company-logo

Vulnerability Management Manager

Con Edison
Job Typeother
Salary
$145000 - $195000
New York, NY
about 1 month ago
company-logo

Security Manager

CVR Energy, Inc.
Job Typefull time
 
Coffeyville, KS
6 months ago
G

Security Engineering Manager

GDT
Job Typefull time
 
Wisconsin, WI
3 months ago
company-logo

Information System Security Manager

Westinghouse Electric Company
Job Typefull time
 
Cranberry Township, PA
3 months ago
company-logo

Information System Security Manager

Westinghouse Electric Company, LLC
Salary
$103200 - $129000
Cranberry Township, PA
5 months ago
company-logo

Security Project Manager

Dominion Energy
Job Typefull time
 
Richmond, VA
25 days ago
company-logo

CORPORATE SECURITY MANAGER

Manitoba Hydro
 
Winnipeg, MB
28 days ago
company-logo

Corporate Security Manager

Manitoba Hydro
Job Typefull time
 
Winnipeg, MB
28 days ago
company-logo

Cybersecurity Operations Manager

Western Midstream
 
The Woodlands, TX
5 months ago
company-logo

Cyber Security Manager

Tri-State Generation and Transmission Association, Inc.
Job Typefull time
Salary
$131000 - $170000
Westminster, CO
5 months ago
company-logo

security service manager

Newmont Mining
Job Typefull time
 
Vancouver, BC
5 months ago
company-logo

Cyber Security Manager

BVD Group
Job Typefull time
 
Brampton, ON
5 months ago
company-logo

Senior Manager, Cyber Security Risk Management

Irving Oil
Job Typefull time
 
Saint John, NB
4 months ago
company-logo

Manager, Cybersecurity Architecture

Enterprise Products
 
Houston, TX
27 days ago
company-logo

Manager, Cybersecurity Engineering

Enterprise Products
 
Houston, TX
27 days ago
company-logo

Facilities & Security Manager

Lehigh County Authority
Job Typefull time
Salary
$90000 - $95000
Allentown, PA
27 days ago
company-logo

Corporate Manager of Security

Superior Propane
Job Typefull time
 
Calgary, AB
3 months ago
company-logo

Corporate Manager of Security

Superior Plus Propane
Job Typefull time
Salary
$102000 - $120000
Wayne, PA
3 months ago
company-logo

Risk Manager

Orano
Job Typefull time
 
Oak Ridge, TN
4 months ago
company-logo

Development Manager

Reactivate
Job Typecontract
Salary
$120000 - $135000
Chicago, IL
4 months ago

Trending Jobs

company-logo

Lead Software Engineer

Energy Hire
Job TypeFull time
Salary
$120000 - $180000
Dallas, Texas
10 months ago
LL

Field Landmen, Division Order Analysts & Lease Analysts

Liberty Land Management, LLC
Job TypeContract
 
Houston, Texas
2 months ago
company-logo

Armed Nuclear Security Officer

Ontario Power Generation
Job Typefull time
 
Pickering, ON
5 months ago
company-logo

Landman

Aaron Resources, LLC
Job Typefull time
 
00
5 months ago
company-logo

Industrial Craft Electricians for 2026 Start– Kennecott Copper

Rio Tinto
Job Typefull time
 
Salt Lake City, UT
5 months ago
company-logo

Deckhand 3

Marathon Petroleum Corporation
Job Typefull time
 
Catlettsburg, KY
5 months ago
company-logo

Title Landman

Norwood Land Services, LLC
Job Typecontract
 
00
5 months ago
company-logo

Title Landman

Perpetual Resource Partners LLC
Job Typefull time
 
Dallas, TX
5 months ago
TL

Independent Petroleum Landman

Texhoma Land Consultants, Inc
Job Typefull time, contract
Salary
$84500 - $104000
Oklahoma City, OK
5 months ago
company-logo

Nuclear Security Officer

Constellation
Job Typefull time
 
Cordova, IL
4 months ago
HE

Accounting Clerk II - Oahu

Hawaiian Electric Company, Inc.
Salary
$47840 - $47840
Honolulu, HI
5 months ago
company-logo

Haul Truck Operators – Kennecott Copper

Rio Tinto
Job Typefull time
 
Salt Lake City, UT
5 months ago
PR

Executive Coordinator

Perpetua Resources
Job Typefull time
Salary
$55000 - $75000
Boise, ID
5 months ago
company-logo

STOREKEEPER

Manitoba Hydro
 
Winnipeg, MB
5 months ago
company-logo

Surface Landman

Bison Oil & Gas IV, LLC
Job Typefull time
Salary
$83500 - $132400
Denver, CO
5 months ago
company-logo

Wastewater Treatment Plant Operator-Lower Jackson

Environmental Systems Service, Ltd.
Job Typefull time
Salary
$31200 - $52000
Eagle Rock, VA
3 months ago
company-logo

Hydro Operator

SANTEE COOPER
Job Typefull time
Salary
$74880 - $93600
Moncks Corner, SC
5 months ago
YH

Customer Support Specialist

Yeamans Hall Club
Job TypePart time
Salary
$24 - $36
Charleston, South Carolina
about 1 month ago
KO

SENIOR LANDMAN

Kaiser-Francis Oil Company
Job Typefull time, contract
 
Tulsa, OK
4 months ago
company-logo

Nuclear Document Mgmt Specialist I/II

Dominion Energy
 
Surry, VA
4 months ago