hirly

Nxp

Senior Restricted Secure / High Secure Exposure Management Lead

Bucharest

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Nxp first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Lead / management
Country
RO
Work mode
On-site / unstated
First seen by hirly
4 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

Job Title: Senior Restricted Secure / High Secure Exposure Management Lead

Location: Bucharest Romania

Job Position: Senior Restricted Secure / High Secure Exposure Management Lead

Role Summary

The Senior Restricted Secure / High Secure Exposure Management Lead serves as the senior technical and operational lead for exposure management across Restricted Secure and High Secure (RS/HS) environments. The role is responsible for ensuring vulnerabilities, misconfigurations, exposed services, unsupported technologies, and attack-path risks are continuously identified, validated, prioritized, and driven through remediation in accordance with the heightened protection requirements of RS/HS environments.

This is a hands-on technical leadership role requiring deep expertise in vulnerability and exposure management, scanning platforms, risk-based prioritization, remediation governance, and secure-environment operations. The role coordinates with system owners, infrastructure engineering, application teams, cloud and platform teams, Security Operations, Threat Intelligence, Incident Response, and governance stakeholders to reduce exploitable exposure while maintaining availability, integrity, segmentation, and change-control requirements.

Success in this role requires sound technical judgment, disciplined handling of sensitive exposure data, strong program execution, and the ability to translate complex findings into clear remediation priorities and measurable risk reduction for technical and leadership audiences.

Job Responsibility

RS/HS Exposure Management Leadership

  • Lead the day-to-day technical and operational execution of exposure management for Restricted Secure and High Secure environments.
  • Establish a consistent operating model for identifying, validating, prioritizing, assigning, tracking, and closing security exposures across RS/HS assets.
  • Maintain an authoritative view of vulnerabilities, misconfigurations, exposed services, unsupported technologies, and attack-path risks affecting RS/HS environments.
  • Ensure exposure-management activities align with applicable security architecture, segmentation, access-control, data-handling, and change-management requirements.
  • Define and continuously improve exposure-reduction processes, technical standards, control objectives, and operating procedures.

Vulnerability Detection & Platform Operations

  • Operate and maintain enterprise vulnerability detection capabilities supporting RS/HS infrastructure, endpoints, applications, network devices, and approved cloud or container platforms.
  • Maintain scanner configuration, credentialed assessment coverage, agent deployment, scan scheduling, policy alignment, and platform health.
  • Use platforms including Rapid7 InsightVM, Rapid7 InsightAppSec, and CrowdStrike Falcon Spotlight / Exposure Management where approved for the target environment.
  • Validate findings, investigate false positives, reconcile duplicate records, and ensure accurate association between findings, assets, owners, and business services.
  • Identify assessment blind spots and coordinate approved methods to improve coverage without introducing unacceptable operational or confidentiality risk.
  • Maintain visibility into RS/HS attack surfaces, trust boundaries, privileged pathways, remote access points, security appliances, and externally reachable components.
  • Identify exposed services, weak configurations, unmanaged assets, unsupported software, certificate issues, and control gaps that increase attack-path risk.
  • Ensure newly introduced or materially changed RS/HS assets receive appropriate assessment and are incorporated into ongoing exposure monitoring.
  • Coordinate assessment of approved cloud platforms, containers, Kubernetes environments, and CI/CD components used within the RS/HS scope.
  • Partner with architecture and engineering teams to reduce systemic weaknesses and embed exposure-management requirements into design and deployment processes.

Archer Governance & Risk Management

  • Support governance through the Archer IT Security Vulnerabilities Program and applicable RS/HS risk-management processes.
  • Ensure risk acceptances, remediation exceptions, compensating controls, and mitigation plans are documented, approved, time-bound, and tracked to closure.
  • Maintain audit-ready evidence for exposure identification, ownership, remediation, verification, exception decisions, and management review.
  • Support risk reporting on material exposure, overdue remediation, recurring weaknesses, and accepted residual risk.

Threat-Informed Risk Prioritization

  • Implement risk-based prioritization incorporating technical severity, exploit intelligence, known exploitation, asset criticality, reachability, control effectiveness, and RS/HS impact.
  • Collaborate with Security Operations, Threat Intelligence, and Incident Response teams to identify vulnerabilities and exposures associated with active or relevant threat activity.
  • Prioritize remediation of exposures that create credible attack paths to sensitive assets, privileged functions, administrative boundaries, or critical services.
  • Document prioritization rationale and ensure urgent exposures receive clear ownership, escalation, and verification.

Remediation Engineering & Automation

  • Coordinate remediation across infrastructure, endpoint, network, application, database, identity, cloud, and platform teams responsible for RS/HS assets.
  • Establish and enforce remediation service levels aligned with exposure risk, asset criticality, operational constraints, and approved risk tolerance.
  • Integrate exposure workflows with patch management, configuration management, infrastructure automation, and change-control processes where authorized.
  • Reduce backlog and mean time to remediate through root-cause analysis, recurring-finding elimination, workflow improvements, and safe automation.
  • Ensure remediation is verified through rescanning, technical validation, or approved evidence before closure.

Metrics, Reporting & Executive Communication

  • Develop and maintain exposure-management dashboards using approved data from ServiceNow Vulnerability Response, Rapid7, CrowdStrike, Archer, and Power BI.
  • Track metrics including coverage, backlog, remediation aging, service-level compliance, mean time to remediate, recurrence, exception status, and exposure reduction.
  • Provide concise risk-posture updates, material exposure escalations, remediation forecasts, and decision support to security leadership and RS/HS stakeholders.
  • Protect sensitive asset and vulnerability details by applying need-to-know access, appropriate classification, and approved distribution practices.

Leadership & Stakeholder Collaboration

  • Provide technical leadership, mentoring, standards, and quality oversight for engineers and analysts supporting RS/HS exposure management.
  • Build effective partnerships with system owners, IT operations, application teams, cloud and platform teams, architects, governance functions, and engineering leadership.
  • Lead working sessions for material exposures, overdue remediation, recurring weaknesses, exceptions, and control improvements.
  • Promote risk-based remediation practices and clear accountability across the organization.

Job Qualification

Professional Experience

  • 8+ years of experience in cybersecurity, vulnerability management, exposure management, security engineering, infrastructure security, or related disciplines.
  • 4+ years of experience operating or leading vulnerability or exposure management capabilities in a complex enterprise environment.
  • Demonstrated experience coordinating remediation across infrastructure, endpoints, applications, networks, cloud platforms, and security teams.
  • Experience supporting restricted, regulated, high-assurance, sensitive, or otherwise tightly controlled technology environments.
  • Proven ability to lead complex exposure investigations, make risk-based decisions, and co
Original posting on Nxp's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job