Ryder
Vulnerability Management Lead
USA - Coral Gables FL 33134 · USA - Remote GA · USA - Remote FL
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →hirly's read of this role
- Seniority
- Lead / management
- Country
- US
- Work mode
- On-site / unstated
- First seen by hirly
- 30 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Job Seekers can review the Job Applicant Privacy Policy by clicking here .
Job Description :
- Summary
- The Vulnerability Management Lead will ensure continuous vulnerability lifecycle management within the Ryder environment including monitoring, collection, reporting, and assessment of impact for vulnerability related data from vendors and internal resources. This individual will be responsible for configuring vulnerability assessment tools, performing scans, analyzing vulnerabilities, identifying relevant threats, recommending corrective actions, and summarizing results for relevant operational teams. This individual will lead by forming strong partnerships with technical teams and provide vision, strategy, and prioritization to control vulnerabilities in the environment in a timely and effective manner.
Essential Functions
Leads the Proactive assessment and remediation of security vulnerabilities within applications and infrastructure software and/ or other Information assets.
Establishes strategies and frameworks for performing validation of scanning results. Performs asset and network discovery activities, helping ensure full coverage of vulnerability management environment.
Recommend Fixes, Security Patches and other measures required in the event of a security breach. Reviews penetration test findings with system owners in line with vulnerability and asset risk ratings.
Define key performance indicators (KPIs) and metrics across business units to illustrate effectiveness with vulnerability management.
Implement or coordinates remediation required by vulnerability scans, and audits, and documents exceptions as necessary.
Produces vulnerability, configuration, and coverage metrics and reporting to demonstrate assessment coverage and remediation effectiveness
Generates reports on assessment findings and prioritizes remediation schedules
Maintains Health and effectiveness of Application and device scanning applications and systems within the security.
Additional Responsibilities
Reviews security scans and leads/manages resolution of issues.
Ensures compliance with all applicable configuration standards
Oversees enterprise vulnerability assessment and configuration assessment tools
Periodically attend and participate in change management policy discussions and meetings.
Regularly research and learn new TTPs in public and closed forums, and work with colleagues to assess risk and implement/validate controls as necessary
Leverage vulnerability database sources to understand each weakness, its probability and remediation options, including vendor-supplied fixes and workarounds.
Communicate vulnerability results in a manner understood by technical and non-technical business units based on risk tolerance and threat to the business, and gain support through influential messaging.
Work closely with infrastructure teams to advise and support remediation efforts to close vulnerability exposure to new threats in the wild and verify the organization’s security posture against them.
Perform other duties as assigned.
Skills and Abilities
Strong decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one
An ability to effectively influence others to modify their opinions, plans, or behaviors
An understanding of business needs and commitment to delivering high-quality, prompt, and efficient service to the business
An understanding of organizational mission, values, and goals and consistent application of this knowledge
Excellent time management and organizational skills
Excellent written and verbal communication skills, interpersonal and collaborative skills
Skilled at recommending, implementing, and delivering security solutions based on analysis and business requirements
Ability to obtain and maintain technical team and business support to influence a collaborative effort to reduce attack surface
Proven trustworthiness and history of acting with integrity, taking pride in work, seeking to excel, being curious and adaptable, and communicating well
Self-starter requiring minimal supervision
Technical expertise in system security vulnerabilities and remediation techniques, network and web-related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, etc.) advanced required
Technical expertise in security engineering, system and network security, authentication and security protocols, cryptography, and application security advanced required
Knowledge of Microsoft Windows and Linux systems intermediate required
Broad understanding of various IT risk and threat assessment methodologies intermediate required
Knowledge with prioritizing remediation activities with operational teams through risk ratings of vulnerabilities and assets, intermediate required
Sound Knowledge of common infrastructure and web application vulnerabilities and common vulnerability categorizations such as CVE,CVSS,CWE intermediate required
Experience with vulnerability management across Amazon Web Services (AWS), Microsoft Azure or Google Cloud Platform (GCP)intermediate preferred
Knowledge of one or more compliance standards, including Payment Card Industry (PCI), Health Information Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act (GLBA), National Institute of Standards (NIST) or International Standards Organization (ISO)advanced required
Proficient with vulnerability management solutions such as Qualys, Nexpose, Nessus, Kenna Security, Tanium and open source, intermediate required
Understanding of OWASP, CVSS, the MITRE ATT&CK framework and the software development life cycle, intermediate required
Strong Knowledge of technology and security topics including network security, wireless security, application security, infrastructure hardening, security baselines, and web server and database security, advanced required
Qualifications
Bachelor's degree required Computer Science, Information Security, or related field or additional 4 years of required work experience
Five (5) years or more experience in information security, especially in a vulnerability analysis role on a Computer Incident Response Team (CIRT), Computer Emergency Response Team (CERT), Computer Security Incident Response Center (CSIRC) or a Security Operations Center (SOC) required
Five (5) years or more experience in deploying and operating vulnerability scanning infrastructure and services. required
Five (5) years or more experience and direct working knowledge of Information Security control frameworks such as ISO/IEC 27001, NIST CSF, CobIT, etc. required
Technical expertise in system security vulnerabilities and remediation techniques, network and web-related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, etc.) advanced required
Technical expertise in security engineering, system and network security, authentication and security protocols, cryptography, and application security advanced required
Knowledge of Microsoft Windows and Linux systems intermediate required
Broad understanding of various IT risk and threat assessment methodologies intermediate required
Knowledge with prioritizing remediation activities with operational teams through risk ratings of vulnerabilities and assets. intermediate required
Sound Knowledge of common infrastructure and web application vulnerabilities and common vulnerability categorizations such as CVE,CVSS,CWE intermediate required
Experience with vulnerability management across Amazon Web Services (AWS), Microsoft Azure or Google Cloud Platform (GCP). intermediate preferred
Knowledge of one or more compliance standards, including Payment Card Industry (PCI), Health Information Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act (GLBA), National Institute of Standards (NIST) or International Standards Organization (ISO). advanced require
Similar jobs
- Vulnerability Management ManagerConEd · New York, NY, United StatesFirst seen 3d ago
- Windows Systems Administrator and Vulnerability Management CoordinatorGuidehouse · 3 LocationsFirst seen 3d ago
- Staff Security Engineer - Vulnerability ManagementUber · Seattle, WA, United States; New York City, NY, United States; Sunnyvale, CA, United States; San Francisco, CA, United StatesFirst seen 4d ago
- Tech Risk and Controls Lead-Vulnerability Management, Network security controlsJPMorgan Chase · Columbus, OH, United States; Plano, TX, United States; Jersey City, NJ, United StatesFirst seen 4d ago
- Cyber - AI-Enabled Vulnerability Management - Manager - ConsultingEY · Los Angeles, CA, USFirst seen 4d ago
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job