More jobs:
Principal of Vulnerability Management Oversight
Job in
Chicago, Cook County, Illinois, 60602, USA
Listed on 2026-06-02
Listing for:
Early Warning Services, LLC
Full Time
position Listed on 2026-06-02
Job specializations:
-
IT/Tech
Cybersecurity, Information Security
Job Description & How to Apply Below
Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment.
Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.
Overall
Purpose:
The Principal of Vulnerability Management Oversight is responsible for ensuring the enterprise Vulnerability Management (VM) program is effective, risk-aligned, and defensible-through independent challenge, governance, and validation.
This role provides independent risk-based governance within a Three Lines of Defense (3
LOD) model, ensuring VM practices across the organization are effective, measurable, and aligned to risk appetite and regulatory expectations. The position partners closely with engineering, infrastructure, and application teams, acting as a credible challenger-not an operator. This role will support the Cybersecurity and Technology Risk Management team within the Second Line of Defense (2
LOD) and report directly to the 2
LOD VP of Information Security Risk.
Essential Functions:
* Provide independent challenge and oversight of vulnerability identification, prioritization, and remediation practices across enterprise environments.
* Define and maintain VM policies, standards, and risk-based remediation SLAs.
* Perform control validation and effectiveness testing of VM processes, tooling, and data quality.
* Assess and challenge risk acceptance decisions, compensating controls, and remediation timelines.
* Deliver risk-based reporting and insights on vulnerability exposure, trends, and systemic gaps.
* Provide oversight of VM tooling (e.g., Tenable, Qualys, Rapid7) to ensure coverage, configuration, and data integrity.
* Partner with First Line teams, Risk, Compliance, and Audit to ensure alignment with internal policies and regulatory expectations.
* Support regulatory exams and internal audits as the VM Second Line SME.
Minimum Qualifications:
* 15+ years of IT experience with 8+ years in Information Security
* Deep expertise in enterprise Vulnerability Management and risk-based prioritization.
* Experience operating in a Three Lines of Defense model and/or regulated environment (financial services preferred).
* Strong understanding of infrastructure, cloud, networking, and common vulnerability classes.
* Ability to translate technical findings into business risk and executive-level insights
* Experience in fintech or highly regulated industries
* Familiarity with CVSS, EPSS, threat intelligence, and KEV-based prioritization.
* Background in risk management, audit, or control validation.
* Background and drug screen.
The above job description is not intended to be an all-inclusive list of duties and standards of the position. Incumbents will follow instructions and perform other related duties as assigned by their supervisor.
Physical Requirements
Working conditions consist of a normal office environment. Work is primarily sedentary and requires extensive use of a computer and involves sitting for periods of approximately four hours. Work may require occasional standing, walking, kneeling and reaching. Must be able to lift 10 pounds occasionally and/or negligible amount of force frequently. Requires visual acuity and dexterity to view, prepare, and manipulate documents and office equipment including personal computers.
Requires the ability to communicate with internal and/or external customers.
Employee must be able to perform essential functions and physical requirements of position with or without reasonable accommodation.
The base pay scale for this position in:
Phoenix, AZ/ Chicago, IL / Washington, DC in USD per year is: $154,000 - $193,000.
New York, NY/ San Francisco, CA in…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×