Skip to content

Open nowPosted 16 days ago

Vulnerability Management Manager

ConEd61 open roles

Where
New York, NY, United States
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowVulnerability Management ManagerConEd · New York, NY, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on ConEd's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. ConEd postings stay open a median of 3 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.5%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 33.9%30 days
This job: posted 16 days ago

ConEd median: 3 days open

The posting

Job Description

The Systems Manager, Vulnerability Management leads the Vulnerability Management team and drives measurable risk reduction across systems, Cloud, applications and operational technology (OT) and reports to the Director, Cybersecurity Operations while partnering closely with engineering, platform, operations, application security, cloud teams, and OT stakeholders to strengthen cloud security work tied to resource misconfigurations, advance application security through shift left and runtime security and build OT security vulnerability management capability from scratch by defining scope, intake, prioritization, remediation paths and verification, while ensuring rapid and well-coordinated response to emerging critical vulnerabilities and risks such as secrets leakage.

This role will modernize the vulnerability management program towards Continuous Threat Exposure Management (CTEM), by connecting vulnerabilities to real exposure and threat context and tracking outcomes that reflect risk reduction over time. Stakeholder management is a core responsibility, including socializing new programs, desired outcomes and operating models with engineering, platform, operations and security leadership and aligning ownership and expectations so remediation becomes predictable and measurable. You will also train and develop a team of about 9 by building repeatable operating routines, improving escalation and incident coordination, and creating skills roadmap across cloud security, application security, vulnerability workflows, runtime protection, and OT fundamentals, and you will help futureproof the capability by recruiting, onboarding, and developing additional vulnerability management talent as the program grows. In addition, the Systems Manager will participate in industry working groups and forums to collaborate with peers on CTEM and vulnerability management programs and processes.

Responsibilities

Core Responsibilities

  • Manage a team of about 9, coach performance and continuously build capabilities through hiring, skills plans and targeted training.
  • Provide clear updates to leadership and partner teams, including project status, emerging issues and remediation progress for high severity items.
  • Evolve beyond vulnerability patching by connecting vulnerabilities to exposure and threat context.
  • Lead end to end intake, triage, prioritization and remediation coordination for system wide vulnerabilities.
  • Identify and drive automation opportunities across scan orchestration, remediation ticketing, SLA tracking, and CI/CD pipeline integration to reduce manual effort and improve response time.
  • Lead end-to-end tracking, risk assessment, and escalation for emerging critical vulnerabilities, including managing risk exceptions, proposing and documenting compensating controls and maintaining clear status updates.
  • Partner with Cloud, platform and engineering stakeholders to reduce cloud risk misconfigurations. Triage findings by business impact, exploitability and exposure.
  • Work with Application and Engineering Teams to prevent vulnerable code and insecure configurations earlier in the lifecycle. Ensure findings are triaged correctly, assigned owners, and tracked to SLA for remediation, with escalation when remediation is at risk.
  • Drive effective Web Application Firewall operations, including rule tuning, validation and quality improvements.
  • Coordinate response to runtime risks and findings discovered during execution.
  • Stand up OT intake, scope, asset coverage, remediation paths and verification.
  • Train internal partners on how OT findings are prioritized and handled.

Qualifications

Required Education/Experience

  • Bachelor's Degree and 8 years of relevant work experience. or
  • Master's Degree and 6 years of relevant work experience.

Preferred Education/Experience

  • Master's Degree Majors preferred in IT, computer science, business administration, engineering or related. and 6 years of relevant work experience.

Relevant Work Experience

  • 6+ years in vulnerability management, security operations, application security, system security, or a related field, with proven ownership of triage and remediation workflows, required.
  • Proven people leadership experience, including coaching, performance management, hiring and skills development for technical teams, required.
  • Strong cloud security fundamentals, especially reducing critical and high-risk resource misconfigurations with stakeholder partners, required.
  • Strong application security fundamentals, including shift left and runtime risk management, required.
  • Experience leading response for critical vulnerabilities and urgent events, including zero-day response, secrets leakage triage, escalation, containment and validation, required.
  • Experience tracking vulnerability and remediation metrics and building dashboards to measure SLA performance, aging, risk reduction and trends over time, required.
  • Ability to turn security strategy into measurable operations, including metrics and leadership reporting, required.
  • Experience standing up new programs from scratch with clear scope, intake and success criteria, required.
  • Experience with CTEM or equivalent exposure management models beyond patching metrics, preferred.
  • Practical WAF experience, including rule tuning, validation and improving detection quality, preferred.
  • OT environment experience, or strong ability to quickly build OT vulnerability management capability, preferred.
  • Experience applying vulnerability management and remediation controls to regulatory and compliance requirements, such as NERC CIP for OT and critical infrastructure, preferred.
  • Certifications such as CISSP, CISM, GIAC or equivalent, required.

Licenses and Certifications

  • Driver's License Required
  • Project Management Professional (PMP) Training and/or certification in Project Management is a plus. Preferred

Physical Demands

  • Sit or stand to answer a phone for the duration of the workday
  • Sit or stand to use a keyboard, mouse, and computer for the duration of the workday
  • Ability to read small print and symbols

Additional Physical Demands

  • The selected candidate will be assigned a System Emergency Assignment (i.e., an emergency response role) and will be expected to work non-business hours during emergencies, which may include nights, weekends, and holidays.
  • Must be able and willing to travel within Company service territory, as needed.

About Us

Mission Statement:

Consolidated Edison Company of New York, Inc. (Con Edison), Orange & Rockland Utilities (O&R), and Consolidated Edison Transmission (CET) employees are required to follow health, safety, and environmental policies, EEO, Standards of Business Conduct, and all other applicable company policy and procedures. We all share a responsibility to advance the company’s mission by excelling at our three corporate priorities – safety of our people and the public, operational excellence in all that we do, and ensuring the best possible customer experience.

Benefits:

We are dedicated to supporting the physical, mental, and financial health of our employees and their families. This commitment extends beyond the workplace to foster personal growth and holistic wellbeing. Our life-changing rewards package includes:

  • Rich medical & pharmacy benefits, including vision benefits
  • Dental benefits
  • Health Savings Accounts
  • Health Care and Dependent Care Flexible Spending Accounts
  • 401(k) with robust matching
  • Employer paid Pension Plan
  • Employee Stock Purchase Plan with a generous matching contribution
  • State of the art Employee Assistance Program
  • Paid Parental Leave
  • Generous paid time off plus paid holidays
  • Family support: emergency backup child, & elder care assistance
  • Social responsibility and volunteer opportunities
  • Employee discount program
  • Commuter Benefits
  • Culture of growth and learning: career development; tuition reimbursement; recognition program
  • Life and Long-Term Disability Benefits

*Please be aware that some benefits may not apply to provisional or part-time job titles.

EEO Statement:

Consolidated Edison Company of New York, Inc. (Con Edison), Orange & Rockland Utilities (O&R), and Consolidated Edison Transmission (CET) are equal opportunity employers. All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of the individual’s actual or perceived disability, protected veteran status, race, color, creed, religion, sex, age, national origin, gender, gender identity, gender expression, genetic information, marital status, sexual orientation, citizenship, domestic violence victim status, or any other actual or perceived status protected by law.

Technical Difficulty Statement:

For technical issues, please contact us at [email protected]

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against ConEd's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on ConEd's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    ConEd's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.