×
Register Here to Apply for Jobs or Post Jobs. X

Senior Product Vulnerability Manager

Job in Lubbock, Lubbock County, Texas, 79401, USA
Listing for: HID Global Corporation
Full Time position
Listed on 2026-05-30
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security
Salary/Wage Range or Industry Benchmark: 125000 - 150000 USD Yearly USD 125000.00 150000.00 YEAR
Job Description & How to Apply Below

Senior Product Vulnerability Manager

Location: Remote (US & Europe)

Job : 47562

As part of the Product Security and Privacy team, you will own and operate the corporate‑wide Product Vulnerability Management program. You will establish the organization’s technical and operational capabilities to detect, triage, prioritize, and respond to product vulnerabilities across a diverse portfolio of products and technologies. You will be accountable for the consistency, scalability, and defensibility of vulnerability management practices and ensure processes, tooling, and outputs are standardized, audit‑ready, and aligned with regulatory expectations, including the EU Cyber Resilience Act (CRA).

You will operate at a strategic level, enabling product teams to execute vulnerability management activities effectively through defined standards, tooling, and governance.

Responsibilities
  • Defining and maintaining the enterprise Product Vulnerability Management framework, including processes for intake, triage, prioritization, remediation tracking, and disclosure.
  • Establishing standardized vulnerability triage and risk prioritization methodologies that work across the organization.
  • Defining and implementing the corporate‑wide vulnerability management policies and standards ensuring our Product Security Incident Response processes are appropriate with the organization’s expectations and regulatory requirements.
  • Owning the Coordinated Vulnerability Disclosure (CVD) program, including external intake channels, researcher engagement, and coordination.
  • Translating regulatory requirements (e.g., EU Cyber Resilience Act) into operational processes, controls, and reporting obligations.
  • Defining and managing the enterprise tooling strategy for vulnerability detection (e.g., SAST, DAST, SCA, container scanning), including selection, configuration, and integration into CI/CD pipelines.
  • Establishing minimum tooling and coverage baselines across product types and ensure consistent adoption.
  • Defining and operationalize SBOM‑driven vulnerability management practices, including monitoring and response to third‑party component vulnerabilities.
  • Developing scalable playbooks, guidance, and decision frameworks enabling product teams to independently triage and respond to vulnerabilities.
  • Defining training requirements and developing enablement materials for product teams on vulnerability identification, triage, and response processes.
  • Establishing metrics, reporting, and dashboards to measure vulnerability management effectiveness, including SLA adherence, backlog, and remediation timelines.
  • Providing executive‑level reporting and insights on product vulnerability risk posture.
  • Defining governance processes, including exception handling, risk acceptance, and escalation pathways.
  • Leading audit and assessment readiness related to vulnerability management processes and outputs.
  • Building and leading a small team responsible for program operations, tooling, and disclosure coordination.
  • Partnering with Product Security Architects, Engineering, Legal, and Compliance teams to ensure alignment and effective execution across the organization.
  • Acting as the central authority for product vulnerability management practices across the organization.
  • Enabling a federated operating model where product teams own remediation while adhering to centralized standards and processes.
  • Driving consistency in vulnerability handling across a large and diverse product portfolio.
  • Ensuring vulnerability management practices scale effectively across hundreds of products and multiple technology domains.
  • Providing strategic direction for continuous improvement of vulnerability management capabilities, tooling, and processes.
  • Supporting regulatory audits and customer inquiries related to vulnerability management and disclosure practices.
Experience and Background
  • Experience designing, building, or scaling a vulnerability management or PSIRT program within a product security or application security context.
  • Strong understanding of the vulnerability lifecycle, including detection, triage, prioritization, remediation tracking, and disclosure.
  • Working knowledge of application security…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary