×
Register Here to Apply for Jobs or Post Jobs. X

Senior Manager, Vulnerability Management and Application Security

Remote / Online - Candidates ideally in
Richmond, Henrico County, Virginia, 23214, USA
Listing for: CarMax
Remote/Work from Home position
Listed on 2026-07-08
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Project Manager
Salary/Wage Range or Industry Benchmark: 144500 - 231200 USD Yearly USD 144500.00 231200.00 YEAR
Job Description & How to Apply Below

8901 - Corp Office West Crk - 12800 Tuckahoe Creek Parkway, Richmond, Virginia, 23238

Position Overview

As a Senior Manager, Vulnerability Management and Application Security, you will lead Car Max’s enterprise vulnerability management and application security programs and serve as a trusted subject matter expert responsible for strengthening the organization’s security posture. You will mentor and guide a high‑performing team, streamline processes, optimize program operations, and deliver actionable insights that influence decision‑making across all levels, including executive leadership.

Team

Overview

The Vulnerability Management and Application Security team guides enterprise strategy for identifying, analyzing, and prioritizing remediation of risks across Car Max’s systems, infrastructure, and applications. As the Senior Manager, you will shape program strategy, strengthen integration with cybersecurity and engineering partners, and enable teams to build and operate secure technology through clear communication, effective governance, thorough reporting, and trusted leadership.

Role Responsibilities
  • Oversee and continuously improve the enterprise vulnerability management and application security programs, ensuring effective alignment of processes, tools, and assessments.
  • Develop and manage program roadmaps, budgets, and priorities for security assessments across infrastructure, networks, cloud services, and applications.
  • Create and deliver executive‑ready reporting with clear documentation, risk insights, program metrics, and prioritized mitigation recommendations.
  • Define and maintain vulnerability management and application security standards, SLAs, and governance practices in partnership with cybersecurity and technology leaders.
  • Lead risk‑based remediation prioritization and ensure consistent progress across infrastructure, engineering, and product teams and partners.
  • Coordinate and communicate responses to emerging threats, zero‑day vulnerabilities, and critical application security findings to drive timely remediation.
  • Lead the application security program, including secure development lifecycle practices, application security testing, and risk‑based remediation strategies.
  • Partner with engineering, architecture, and product teams to embed security requirements, threat modeling, code scanning, and security reviews into the software development lifecycle – foster a culture of security.
  • Mature application security capabilities such as SAST, DAST, software composition analysis, secrets detection, and security testing for internally developed and third‑party applications.
  • Provide guidance on secure coding practices, common vulnerabilities, and remediation approaches.
  • Adapt to and apply technology innovation, including AI, to the role and program overall.
  • Adapt the team and programs to ever‑changing threat and regulatory landscape.
Required Qualifications
  • 8+ years of cybersecurity experience with emphasis on vulnerability management, application security, risk analysis, and security assessment practices.
  • 5+ years of experience designing, implementing, or supporting secure information systems and application security practices.
  • 3+ years in a security leadership or management role guiding teams or programs.
  • One or more certifications such as CISA, CISM, CEH, CISSP, or SANS.
  • Experience with enterprise security technologies and application security tooling such as vulnerability scanners, SAST, DAST, software composition analysis, SIEM platforms, and network devices – firewalls, IDS/IPS, routers, and switches.
  • Strong ability to analyze complex security findings, communicate risk clearly to diverse audiences, and drive remediation across infrastructure, engineering, and business teams or partners.
  • Bachelor’s Degree in a technology‑related field or equivalent experience in Cybersecurity and Risk Management, preferred.
Work Location and Arrangement

This role will be based out of the Car Max Home Office in Richmond, VA and associates will work onsite 4 days per week.

Work Authorization

Applicants must be currently authorized to work in the United States on a full‑time basis. Sponsorship will not be considered for this…

Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary