Find Jobs
Find Jobs Near You – Available Work in Your Location
Director, Vulnerability Management
Career Insights for Vulnerability Analyst / Penetration Tester
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Texas data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.
$116,062 / year median in Texas
+6% projected growth
Job Description
JOB SUMMARY
The Director of Vulnerability Management is the technical leader and owner of Cencora's vulnerability management program. This role sets the strategy, architecture, and operating model for how the organization discovers, prioritizes, and drives remediation of vulnerabilities across cloud, on-premise, endpoint, application, container, and third-party hosted environments. This hands-on technical leadership position leads the design of vulnerability scanning, reviewing detection logic, managing scan data, and defending remediation decisions across engineering teams and executive stakeholders.RESPONSIBILITIES
Own the strategy and continual development of the end-to-end vulnerability management program, including strategy, roadmap, operating model, policy, standards, and success metrics. Define and maintain risk-based remediation SLAs by asset criticality, exposure, and severity. Mature beyond reactive scanning towards continuous, risk-based exposure management, including attack surface management and validation of remediation effectiveness. Establish governance forums to review exposure trends, aging findings, systemic root causes, and escalations. Oversee comprehensive and accurate asset coverage by integrating scanning with CMDB, cloud inventories, and other asset discovery sources to reduce unscanned and unknown assets. Lead refinement of prioritization models to combine CVSS scoring with threat intelligence and exploitability signals, asset criticality, and compensating controls. Partner with penetration testing, red team, threat intelligence, and countermeasures teams to correlate findings and validate control effectiveness. Drive measurable reduction in mean time to remediate and aging critical exposures, working with IT operations, infrastructure, application, and cloud engineering teams. Lead technical response for zero-day and emerging critical vulnerabilities, including rapid impact assessments, containment guidance, and executive communication. Identify and address systemic root causes such as patch tooling gaps, unsupported software, base image drift, and legacy platform debt. Define and report KPIs and KRIs to executive leadership, translating technical exposure into business and financial risk. Recruit, develop, mentor, and retain a team of vulnerability management analysts, building technical depth and clear career paths. Set technical standards, review the team's work product, and cultivate a culture of data quality and continuous improvement.EDUCATION & QUALIFICATIONS
Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or equivalent work experience 8+ years of progressive experience in cybersecurity, with at least 5 years in vulnerability management, security engineering, offensive security, or infrastructure security. Experience leading technical teams with demonstrated success building or substantially maturing a vulnerability or exposure management program at enterprise scale. Hands-on expertise with enterprise vulnerability management tenable (Table, Qualys, Rapid7, Wiz, etc). Strong working knowledge of operating system internals, networking, patch and configuration management, and enterprise identity across Windows, Linux, and MacOS. Demonstrated Experience security public cloud environments and container technologies, including cloud-native vulnerability and posture management. Fluency in vulnerability scoring and prioritization frameworks (CVSS , EPSS, CISAKEV, SSVC
). Experience with application and software supply chain security concepts, including SAST, DAST, SCA, and SBOM. Familiarity with relevant security and risk frameworks (NISTCSF, ISO 27001, MITRE
ATT&CK, etc). Excellent written and verbal communication skills with proven ability to influence engineering teams without direct authority and to brief executive audiences credibly.PREFERRED CERTIFICATIONS
GIAC GEVA- Enterprise Vulnerability Assessor
GIAC GPEN
- Penetration Tester CISSP
- Certified Information Systems Security Professional CISM
- Certified Information Security Manager Bachelor's degree in cybersecurity, information technology, computer science, information systems, business administration, or a related field, or equivalent experience required.
Affiliated CompaniesAffiliated Companies:
AmerisourceBergen Services CorporationBenefits
- Professional Development
- Mentorships
- Health Insurance
- Dental Insurance