Vulnerability Program Manager

NCV HOLDCO LLC Remote, US,
$75,000 - $100,000Hybrid

About The Position

The Vulnerability Program Manager owns how NetCov delivers vulnerability management and patching to its clients. This role is responsible for transforming the current account-specific practices into a unified program with defined processes, consistent reporting, and clear ownership from discovery to verified remediation. The Program Manager will be a hands-on role, directly involved in client vulnerability reviews, tooling, and defining standards, reporting to the Director of Security Services. Success relies on technical expertise and the ability to build strong working relationships with internal teams and clients, as remediation often involves multiple parties and client-controlled change windows.

Requirements

  • Demonstrated experience running vulnerability management and patching in a multi-client or multi-environment setting, ideally at an MSP or MSSP.
  • Hands-on proficiency with vulnerability management and patching platforms such as InsightVM, ConnectSecure, NinjaOne, Datto RMM, or equivalent.
  • Working knowledge of PSA and workflow tooling, HaloPSA preferred, including ticket design and reporting.
  • Practical understanding of risk-based prioritization, including CVSS, exploit intelligence, and business context, and the judgment to apply it rather than defaulting to severity alone.
  • Familiarity with compliance frameworks that drive vulnerability management requirements, including CMMC, PCI DSS, SOC 2, HIPAA, and NCUA examination expectations.
  • Strong written and verbal communication skills, with a track record of running client meetings and presenting technical findings to non-technical stakeholders.
  • Ability to drive work across teams without direct authority.

Nice To Haves

  • Relevant certifications such as Security+, GIAC, CISSP, or vendor-specific credentials are preferred but not required.

Responsibilities

  • Own the end-to-end vulnerability management and patching program, covering asset discovery, scanning, prioritization, remediation tracking, verification, and reporting.
  • Define and document the standard service: scan frequency, patch cadence, severity-based remediation targets, exception and risk-acceptance handling, and the criteria for emergency out-of-band work.
  • Establish and maintain the RACI for the program so it is clear which work belongs to the Vulnerability Analysts, security engineering, the service desk, and the client.
  • Define ticket types, templates, and workflows in HaloPSA so that patch work, remediation work, and scan evidence are captured consistently and can be reported on.
  • Set the standard for what constitutes acceptable evidence of remediation, including where a report rather than a ticket is the appropriate audit artifact.
  • Run the recurring vulnerability management cadence for assigned clients, including monthly or quarterly review meetings, and hold the follow-through between meetings.
  • Maintain a prioritized remediation backlog per client and drive it down, escalating stalled items rather than allowing them to age quietly.
  • Coordinate remediation execution across NetCov delivery teams and client staff, including scheduling around change windows and maintenance periods.
  • Manage exclusions, suppressions, and risk acceptances deliberately, ensuring that anything removed from a report is documented with a reason, an owner, and a review date.
  • Serve as the escalation point for emergency vulnerability response, including zero-day and actively exploited issues that require out-of-cycle patching.
  • Own the client-facing report catalog, including the recurring vulnerability review deck, aging and trend analysis, and executive summaries suitable for non-technical audiences.
  • Present program status to client stakeholders and translate scan output into a clear picture of risk, progress, and what NetCov needs from the client to keep moving.
  • Set and manage client expectations on scope, timelines, and division of responsibility, and document agreements so they survive staff changes on either side.
  • Support client audit and compliance needs, including evidence requests tied to frameworks such as CMMC, PCI DSS, SOC 2, HIPAA, and NCUA examinations.
  • Partner with Client Success and account teams during onboarding, escalations, and renewals, and provide the vulnerability management input those conversations require.
  • Own the operational configuration and health of the vulnerability management tool stack, including scanner coverage, credentialed scanning, agent deployment, and asset inventory accuracy.
  • Work with security engineering to integrate scanning, ticketing, and patching platforms so that findings flow into client-visible reporting without manual rework.
  • Identify and drive out sources of bad data, including stale assets, duplicate records, and unmanaged endpoints that distort client-facing counts.
  • Identify automation opportunities across reporting, ticket creation, and remediation validation, and define the requirements for engineering to build against.
  • Define and report program metrics, including remediation SLA attainment, vulnerability aging, patch compliance rate, scan coverage, and recurring findings.
  • Use those metrics to identify systemic problems rather than treating each client issue as isolated, and propose the process or tooling changes required to fix them.
  • Train and mentor Vulnerability Analysts and other delivery staff on the standard process as the team is built out.
  • Contribute to the ongoing definition and packaging of NetCov vulnerability management service offerings.
  • Perform other duties as assigned

Benefits

  • Innovative Solutions: Work with cutting-edge IT and cybersecurity services for the financial and regulated industries.
  • Professional Growth: Learn from experienced project managers and gain hands-on exposure to enterprise-level project execution.
  • Collaborative Culture: Join a supportive, people-first team that values structure, learning, and shared success.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service