VIPR & VMDR Expert
Job in
Town of Poland, Jamestown, Chautauqua County, New York, 14701, USA
Listed on 2026-08-11
Listing for:
Armis
Full Time
position Listed on 2026-08-11
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
The VIPR & VMDR Expert serves as an architect,, strategic analyst and technical operator — combining vulnerability lifecycle management with exploit intelligence, detection automation, and cross-functional coordination (ITSM).
You’ll lead how Armis detects, prioritizes, and responds to vulnerabilities across customer environments, infrastructure, SaaS ecosystems, and the Armis platform — ensuring our customers stay ahead of emerging exploits, threats, and exposures.
Key Responsibilities- Own the end-to-end vulnerability and detection lifecycle — from discovery, triage, and prioritization through remediation and reporting.
- Lead the Vulnerability Intelligence, Prioritization & Detection Response (VIPR/VMDR) function, integrating threat intel, exploit data, and asset context to drive data-backed decisions.
- Correlate internal vulnerability telemetry with external feeds (NVD, CISA KEV, EPSS, Mandiant, Shodan, VulnDB, Centrix for Early Warning) to assess exploitability and exposure.
- Operate and tune vulnerability and detection tools (e.g., Tenable, Qualys, Rapid7, Wiz, Prisma Cloud, Service Now VR) across hybrid customer environments.
- Automate vulnerability scoring, detection correlation, and reporting pipelines using Python, Power Shell, REST APIs, or automation rules within AMS/VIPR.
- Partner with Customer Success, Security Engineering, and Cloud Infrastructure teams to track remediation SLAs, exposure metrics, and MTTR improvements.
- Build and publish risk dashboards, customer-facing reports, and executive briefings using Splunk, Power BI, Elastic, or AMS/VIPR.
- Develop and maintain the Armis Vulnerability Prioritization Model (VPM) — aligning exploit intelligence, CVSS/EPSS scoring, Armis Proprietary Risk Scoring, and business criticality to guide customer risk posture.
- Support penetration test remediation, red team findings, and customer security audits.
- Author weekly vulnerability intelligence reports, zero-day summaries, and leadership briefings for APJ/APAC stakeholders.
- Collaborate with Product Security and Threat Intelligence teams to integrate vulnerability and detection data into Armis platform insights.
- Deliver training sessions and enablement workshops for customers, engineers, and analysts on vulnerability trends, tools, and operational best practices.
- 6–10+ years of experience in Vulnerability Management, Threat Intelligence, or Security Detection Engineering.
- Deep expertise in CVSS, CWE/CVE, NVD, KEV, and exploit prediction (EPSS) frameworks.
- Hands-on experience with vulnerability and detection management platforms (Tenable, Qualys, Rapid7, Wiz, Prisma Cloud, Service Now VR, Centrix for VMDR).
- Proven ability to develop automation scripts and data pipelines (Python, Power Shell, Bash, REST APIs, JSON).
- Familiarity with risk-based vulnerability management (RBVM) and prioritization scoring models.
- Strong understanding of cloud-native security, container scanning, and hybrid infrastructure (AWS, Azure, GCP).
- Exceptional data storytelling skills — turning technical findings into actionable executive insights.
- Demonstrated ability to work independently and as part of a team.
- Exceptional communication skills across all levels of technical, middle management, and executive leadership personnel.
- Bachelor’s or Master’s degree in Information Security, Computer Science, or related discipline.
- Previous experience operating in a "Voice of the Customer" (VoC) technical role directly embedded with Product Engineering pods.
- A track record of mentoring senior technical staff (TCMs, TAMs, or Solutions Engineers) and developing scalable knowledge-sharing frameworks.
- Prior experience in enterprise SaaS, cybersecurity, or customer-facing technical programs.
- Familiarity with Armis Centrix™ or similar asset intelligence and exposure management tools.
- Certifications such as CISSP, GCCC, GCTI, CEH, or CySA+.
- Experience supporting compliance frameworks (SOC 2, ISO 27001, FedRAMP) in enterprise environments.
- Strong cross-cultural communication and collaboration skills across global and regional teams (APJ/APAC).
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×