# Vulnerability Manager at BeyondTrust

- Company: BeyondTrust
- What the company does: Backed by Insight.
- Company website: http://www.beyondtrust.com
- Type: Startups
- Level: Senior
- Location: Remote Canada | Remote United States
- Work setup: Remote
- Posted: 2026-09-11
- Apply by: 2026-10-26
- Apply: https://job-boards.greenhouse.io/beyondtrust/jobs/8191339
- Page: https://www.1752.vc/careers/jobs/beyondtrust-vulnerability-manager/

## About the role

BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cybersecurity SaaS portfolio. Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself.

## What they're looking for

- Design and operate the product vulnerability management process end to end: intake, triage, risk assessment, assignment, SLA tracking, exception handling, and closure verification
- Own vulnerability management for FedRAMP 20x, including continuous monitoring cadence, machine-readable evidence, Key Security Indicator reporting, and POA&M lifecycle from creation through closure
- Stand up vulnerability management for new products and services as they ship: define scan coverage, onboard them into the process, set SLAs, and establish reporting from first release
- Assess and rank vulnerability risk using exploitability, exposure, asset criticality, and compensating controls rather than CVSS alone, and defend that ranking to engineers, executives, and assessors
- Drive remediation with product engineering teams: assign ownership, agree timelines, escalate overdue Critical and High findings, and record risk acceptances as time-bound decisions with an expiry
- Automate the process wherever manual effort scales with finding volume, using scripting, workflow tooling, and AI-assisted analysis for triage, deduplication, enrichment, summarization, and evidence collection

Tags: Product Security
