ForgeApply · Job listing
Vulnerability Management Team Lead
SailPoint
See all 12 open roles at SailPoint →
Tailor your resume for this SailPoint job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for SailPoint's site. Free trial, no card required.
About this role
SailPoint is seeking a Vulnerability Management (VM) Team Lead to oversee the daily operations of our VM program. As a critical member of our Cybersecurity organization, you will play a crucial role in protecting our systems and data by leading a team dedicated to the continuous discovery, accurate assessment, risk-based prioritization, and successful remediation of vulnerabilities across all company assets. This is a hands-on leadership role for someone who wants to help drive the cultural and technical shift from reactive vulnerability patching to proactive, threat-informed risk reduction.
You will lead a growing threat and vulnerability management team of both emerging and established talent and partner closely with our Attack Surface Management team lead as well as VM Architect. At SailPoint, we value our "4 I's" (Integrity, Individuals, Impact, and Innovation), and we're looking for someone who embodies these principles. By being your authentic self, you will be a positive and influential contributor to our already fantastic work culture. This is a challenging and high-impact role where you will build strong partnerships with colleagues across IT, DevOps, Security Engineering, and business units.
This role is fully remote and can be based anywhere in the United States.
What You'll Do (Core Responsibilities):
Lead Daily VM Operations: • Oversee the day-to-day operational activities of a team of Vulnerability Management Analysts. Provide technical guidance, mentorship, and support to elevate the overall skill set of the group.
• Manage the end-to-end vulnerability lifecycle, ensuring continuous discovery, triage, and assignment of vulnerabilities across cloud and corporate infrastructure.
Drive Risk-Based Prioritization: • Develop and enforce a prioritization framework that utilizes risk context beyond standard CVSS scores, factoring in asset criticality, internal threat intelligence, and active exploitation in the wild.
• Collaborate with the risk team and business leaders to establish risk acceptance criteria and service level objectives (SLOs), ensuring remediation efforts align with the organizational risk appetite.
Lead the Remediation Lifecycle: • Serve as an escalation point and subject matter expert to help VM analysts and asset owners (IT, DevOps, Engineering) understand risks, identify dependencies, and facilitate the remediation process.
• Track remediation progress across business units and ensure compliance with defined SLAs.
Automate and Improve Processes: • Drive continuous improvement in the efficiency of vulnerability operations by identifying opportunities for automation across the tech stack (e.g., automating data ingestion, ticketing system integration via Jira, and integrating VM data into SIEM/SOAR).
Reporting & Metrics: • Generate operational Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs), such as Mean Time to Remediate (MTTR), Remediation Compliance Rate, and overall vulnerability density.
• Provide program performance reporting, scorecards, and dashboards for different business units, translating technical data for non-technical stakeholders and executive leadership.
What You'll Need (Must-Have Experience & Skills):
• 5-7+ years in Cybersecurity, with 2-3+ years in a leadership, team lead, or senior operational role focused specifically on Vulnerability Management.
• E xpert-level, hands-on experience with enterprise vulnerability assessment tools and platforms (e.g., Qualys, CrowdStrike, Wiz, Orca, etc.).
• Deep technical understanding of vulnerability classification (CVSS, CVE, EPSS), risk vs. severity, and modern patching processes for Windows, Mac, Linux, and containerized environments.
• Strong familiarity with securing modern complex cloud environments (AWS, Azure, GCP) and corporate infrastructure.
What Will Set You Apart (Bonus Points):
• Demonstrable proficiency in a scripting language (Python or PowerShell strongly preferred) used for API integration, data analysis, and automation.
• Experience with regulatory frameworks and compliance requirements (e.g., NIST, ISO 27001, SOC2, FedRAMP).
• Background in penetration testing, threat intelligence, or attack surface management. Experience establishing or maturing a vulnerability management program from the ground up.
• Professional certifications such as CISSP, CISM, AWS
Leadership Qualities for This Role: • Pragmatic & Results-Oriented: You make informed, risk-based decisions that balance business priorities with security needs to achieve measurable outcomes.
• Influence & Collaboration: You have a proven ability to build strong, collaborative relationships across diverse technical teams and drive change without direct authority.
• An Analytical & Investigative Mindset: You possess an innate curiosity and a structured approach to problem-solving, with a talent for turning ambiguous data into a clear action plan.
• Clear Communicator: You can distill complex technical concepts into clear, concise language for a variety of audiences, from junior analysts to senior executives.
Note: Candidates are required to obtain the AWS Certified Cloud Practitioner or AWS Certified Security - Specialty certification within the first year of employment if they do not already possess it
The Path to Success (Milestones): 60-Day Milestones (The "Connecting" Phase): • Become fully comfortable with core processes and tools, including reporting, ticketing, and internal workflows.
• Solidify relationships with key members of the vulnerability management team and begin engaging with stakeholders in Engineering, IT, and Compliance.
• Begin performing routine vulnerability management tasks, such as validating scans and initiating remediation ticketing, with increasing independence with a keen eye for areas of improvement.
90-Day Milestones (The “Performance" Phase): • Begin overseeing day-to-day routine vulnerability management tasks accomplished by your team of analysts with minim
Tailor your resume for this SailPoint role before you apply.
Tailor my resume for this jobSimilar jobs
- Vulnerability Manager Lead — Darkwolfsolutions · Herndon, VA
- Vulnerability Management & Response Engineer — Starr · Destin, FL | Atlanta, GA | NY
- Vulnerability Management Subject Matter Expert — Guidehouse · US - VA, McLean
- Vulnerability Management Professional — Marvell · US-TX - Austin
- Manager, Vulnerability Management — Vanguard · Malvern, PA | North Carolina | Dallas/Ft. Worth, TX
- Manager, Vulnerability Management — Pfizer (Internaljobs) · New York City, New York, United States | Collegeville, Pennsylvania, United States
- Manager, Vulnerability Management — Pfizer · New York City, New York, United States | Collegeville, Pennsylvania, United States
- Staff Vulnerability Management Engineer — Chainguard · Remote
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)