Vulnerability Manager

Guild Mortgage,
$109,114 - $156,510Onsite

About The Position

The Vulnerability Manager is responsible for leading the enterprise vulnerability management program, ensuring the timely identification, assessment, prioritization, remediation, and reporting of security vulnerabilities across the organization's technology environment. This role partners closely with Infrastructure, Cloud, Application Development, DevOps, IT Operations, and business stakeholders to reduce cyber risk while supporting organizational objectives. The Vulnerability Manager develops and maintains vulnerability management processes, drives remediation efforts, establishes risk-based prioritization methodologies, manages security scanning technologies, and delivers executive-level reporting on the organization's security posture.

Requirements

  • Minimum five years experience.
  • Minimum three years supervisory or leadership experience.
  • Ability to organize and manage multiple priorities simultaneously.
  • Ability to work well independently or within a team.
  • Excellent interpersonal communication skills required.
  • Must be able to handle confidential matters with discretion.
  • Excellent verbal and written communication skills required.
  • Highly organized and detail-oriented; ability to work in a fast-paced, metrics-driven environment required.
  • Proficiency in Microsoft Office Suite, Word, Excel, Wiki, collaborative cloud-based programs, and third-party software applications required.
  • Commitment to company values.
  • Customer Service - Proactive attention to each person.
  • Integrity - Do and say what's right.
  • Respect - Treat others with dignity.
  • Collaboration - Listen and work together.
  • Learning - Seek knowledge and strive for improvement.
  • Excellence – Deliver the unexpected.
  • Work is primarily sedentary; mobility in an office setting.
  • Ability to operate standard office equipment and keyboards.
  • Ability to accurately interpret sounds and associated meanings at a volume consistent with interpersonal conversation.
  • Office environment – moderate noise, no substantial exposure to adverse environmental conditions.
  • Travel 5% or less.
  • Must be able to adhere to process protocol. Must be able to apply established protocols in a timely manner.
  • Work is primarily performed during the business week, Monday - Friday.

Nice To Haves

  • Bachelor's Degree directly related to the position or equivalent, preferred.

Responsibilities

  • Develop, implement, and continuously improve the enterprise vulnerability management program.
  • Establish and maintain existing vulnerability management policies, standards, procedures, and governance processes.
  • Define risk-based remediation priorities based on asset criticality, exploitability, threat intelligence, and business impact.
  • Lead vulnerability review meetings and remediation governance forums.
  • Develop vulnerability management roadmaps and maturity improvement initiatives.
  • Oversee vulnerability scanning activities across: Servers, Workstations, Network devices, Cloud platforms, Containers, Applications, Databases
  • Validate and triage identified vulnerabilities to reduce false positives.
  • Assess vulnerability severity using CVSS, threat intelligence, exploit availability, and environmental factors.
  • Monitor emerging threats, zero-day vulnerabilities, and security advisories.
  • Coordinate remediation efforts with IT Operations, Infrastructure, Engineering, Cloud, and Development teams.
  • Establish remediation timelines and service-level objectives (SLOs).
  • Track remediation progress against established metrics.
  • Manage exception processes and risk acceptance workflows.
  • Escalate critical vulnerabilities and overdue remediation items to leadership.
  • Manage vulnerability scanning and management platforms such as: Tenable, Microsoft Defender Vulnerability Management, Wiz
  • Ensure scanning coverage, tuning, maintenance, and integration effectiveness.
  • Develop executive dashboards and operational reporting.
  • Report vulnerability trends, remediation effectiveness, and exposure reduction progress.
  • Track and report key performance indicators (KPIs) and key risk indicators (KRIs).
  • Support enterprise risk management initiatives.
  • Evaluate vulnerabilities within the context of business risk.
  • Facilitate risk-based decision-making regarding remediation versus risk acceptance.
  • Align vulnerability management activities to regulatory and security frameworks.
  • Incorporate internal and external threat intelligence into vulnerability prioritization.
  • Monitor CISA Known Exploited Vulnerabilities (KEV) catalog and other threat intelligence sources.
  • Prioritize remediation activities based on active exploitation trends.

Benefits

  • medical
  • dental
  • vision
  • life insurance
  • AD&D
  • LTD
  • 401(k) with employer match
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service