Manager, Vulnerability Management (Medellín)

Manager, Vulnerability Management (Medellín)

02 mar
|
MPS Group
|
Medellín

02 mar

MPS Group

Medellín

Location: Colombia
Language Requirement: Fluent Spanish and English
Engagement: Contract – full time
About the Role
We are seeking an experienced Vulnerability Manager to lead and mature our enterprise vulnerability management program. This role is responsible for overseeing the full vulnerability lifecycle across on-prem, cloud, and application environments, ensuring risks are accurately identified, prioritized, tracked, and remediated. The idóneo candidate will act as both a strategic advisor and hands-on leader, partnering closely with IT, Engineering, and Security stakeholders to reduce risk and strengthen the organization's overall security posture.
Key Responsibilities
The Vulnerability Manager will:
Lead and manage the end-to-end enterprise vulnerability management lifecycle, continuously maturing processes related to scanning, triage, risk scoring, remediation tracking, and continuous improvement.
Optimize and govern the vulnerability management platform and supporting tools, ensuring accurate, automated, and scalable coverage across infrastructure, applications, and cloud environments.
Develop, maintain, and present meaningful metrics, dashboards, and executive-level reporting to drive accountability, measure remediation progress, and clearly communicate risk posture to leadership.
Act as a subject matter expert and thought leader in vulnerability risk management, influencing remediation strategies, prioritization decisions, and long-term technology lifecycle planning.
Lead and facilitate technical investigations and cross-functional discussions to ensure timely and effective response to critical and high-risk vulnerabilities.




Partner closely with IT, Engineering, and other stakeholders to identify, track, and mitigate risks associated with end-of-life systems, unsupported technologies, and legacy microservices, driving proactive upgrade, re-platforming, or decommissioning strategies.
Manage Cloud Security Posture Management (CSPM) tracking, providing visibility into cloud misconfigurations, over-permissioned identities, and cloud-native vulnerabilities, and driving remediation in collaboration with cloud and platform teams.
Establish and enforce risk-based prioritization models aligned with business impact, exploitability, and threat context rather than patching alone.
Support audits, compliance initiatives, and security assessments by providing accurate vulnerability data, evidence, and risk narratives when required.
REQUIRED QUALIFICATIONS
Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
8+ years of experience in cybersecurity, with at least 5 years focused on vulnerability management, risk management, or closely related security functions.
Hands-on experience with vulnerability management platforms such as Tenable, Qualys, Rapid7, Vulcan,



or Kenna.
Experience working with cloud security tools and CSPM/CNAPP solutions such as Wiz, Prisma Cloud, or Orca.
Strong technical understanding of operating systems (Windows, Linux, macOS), networking concepts, and cloud platforms (AWS, Azure, GCP).
Demonstrated experience tracking, prioritizing, and mitigating risks related to end-of-life technologies and legacy microservices.
Strong knowledge of vulnerability scoring frameworks (CVSS), patch management processes, and risk-based vulnerability prioritization.
Excellent analytical, problem-solving, and communication skills, with the ability to influence stakeholders at technical and executive levels.
Proven ability to manage competing priorities, lead initiatives, and drive remediation in partnership with IT, Engineering, and Compliance teams.
DESIRED SKILLS & EXPERIENCE
Experience with container security and cloud-native environments, including Docker, Kubernetes, and serverless architectures.
Knowledge of security frameworks and regulatory standards such as NIST CSF, PCI DSS, SOC 2, and ISO 27001.
Experience automating remediation workflows or integrating vulnerability data into ticketing and workflow platforms such as Jira or ServiceNow.
Background in threat modeling, risk assessment, and security analysis beyond traditional patching activities.
Relevant industry certifications such as CISSP, CISM, OSCP, GIAC/GVMS, or cloud security certifications.
Nivel de antigüedad
Intermedio
Tipo de empleo
Jornada completa
Función laboral
Tecnología de la información
Sectores
Desarrollo de software

📌 Manager, Vulnerability Management (Medellín)
🏢 MPS Group
📍 Medellín
Suscribete a esta alerta:
Escribe tu dirección de correo electrónico, te permitirá de estar al tanto de los últimos empleos por: manager, vulnerability management (medellín)

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:
Escribe tu dirección de correo electrónico, te permitirá de estar al tanto de los últimos empleos por: manager, vulnerability management (medellín)