Leads enterprise vulnerability management and cloud security posture management across on-premises, cloud, and application environments. Administers security platforms, monitors AWS environments for vulnerabilities and misconfigurations, prioritizes remediation, automates workflows, and partners with engineering and DevOps teams. Tracks risk metrics and aligns security practices with FedRAMP, NIST CSF, ISO 27001, and CIS Controls.
About the role
The Vulnerability & Cloud Security Program Manager leads the enterprise vulnerability management and cloud security posture management (CSPM) programs, ensuring timely identification, assessment, prioritization, and remediation of risks across on-premise, cloud, and application environments. This role leverages modern cloud security and vulnerability management platforms to monitor, analyze, and strengthen our security posture. You will collaborate closely with engineering, DevOps, and infrastructure teams to reduce risk exposure, support compliance obligations, and advance the organization’s overall security maturity.
Location - We are flexible on remote working from home, if you are located in the USA and reside in one of the following states - CA, CO, CT, FL, GA, *IL, KS, ME, MA, MD, NJ, NC, NY, OR, TN, TX, VA, and WA. We have physical offices in Austin, TX and Tampa, FL, if you prefer a hybrid option.
What You’ll Be Doing
- Lead and operate the full vulnerability management and CSPM lifecycle, ensuring timely discovery, assessment, prioritization, and remediation.
- Administer and optimize our vulnerability management and CSPM platforms, including policies, integrations, reporting, and automation.
- Monitor cloud and infrastructure environments to identify misconfigurations, excessive permissions, and compliance drift, primarily in AWS.
- Partner with engineering and DevOps teams to drive remediation efforts, facilitate triage discussions, and provide technical guidance on complex issues.
- Align security practices with frameworks such as FedRAMP, NIST CSF, ISO 27001, and CIS Controls.
- Track and report key KPIs and risk metrics to leadership, including SLA compliance and vulnerability trends.
- Automate detection, remediation workflows, and tool integrations to enhance efficiency and expand security capabilities
- Other duties as needed
About You
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience.
- 5+ years of experience in vulnerability management and at least 2+ years in cloud security.
- Hands-on experience with CSPM tools, vulnerability detection platforms, and automation (Wiz, AWS Inspector, Nessus, OpenSCAP preferred).
- Strong understanding of AWS security best practices and cloud-native architectures.
- Familiarity with vulnerability scoring systems like CVSS and risk-based prioritization.
- Excellent communication, collaboration, and stakeholder management skills.
- Security certifications such as CISSP, AWS Security Specialty, or GIAC Cloud Security are a plus.
- Preferred knowledge of regulatory and compliance frameworks such as PCI DSS, HIPAA, SOX, FedRAMP.
About Us
NinjaOne automates the hardest parts of IT to deliver visibility, security, and control over all endpoints for more than 40,000 customers. The NinjaOne automated endpoint management platform is proven to increase productivity, reduce security risk, and lower costs for IT teams and managed service providers. NinjaOne is obsessed with customer success and provides free and unlimited onboarding, training, and support. NinjaOne is #1 on G2 in endpoint management, patch management, remote monitoring and management, and mobile device management.
What You’ll Love
We are a collaborative, kind, and curious community.
We honor your flexibility needs with full-time work that is hybrid remote.
We have you covered with our comprehensive benefits package, which includes medical, dental, and vision insurance.
We help you prepare for your financial future with our 401(k) plan.
We prioritize your work-life balance with our unlimited PTO.
We reward your work with opportunity for growth and advancement.
Additional Information
This position is NOT eligible for Visa sponsorship. Due to federal government security requirements associated with our FedRAMP-authorized environment, candidates must be U.S. citizens or lawful permanent residents.
*Due to operational policies, NinjaOne is unable to hire for this role within the city limits of Chicago. We will consider all qualified candidates who reside outside of the city proper or are willing to self-relocate.
Starting pay for the successful applicant depends on a variety of job-related factors, including but not limited to location, market demands, experience, job-related knowledge, and skills. The benefits available for this position include medical, dental, vision, 401(k) plan, life insurance coverage and PTO. For roles based in California, Colorado, Maryland, New Jersey, or Washington the base salary hiring range for this position is$180,000 to $220,000 per year.
For roles based in New York, the base salary hiring range for this position is $180,000 to $220,000 per year.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, marital status, veteran status, or any other status protected by applicable law. We are committed to providing an inclusive and diverse work environment.
Similar Jobs
Security • Cybersecurity
Lead large-scale Linux sensor platform initiatives for high-performance OT and ICS network monitoring. Design and improve packet ingestion, capture pipelines, queue management, broker integration, observability, and reliability. Own production root cause analysis, postmortems, performance benchmarks, and durable fixes. Translate business goals into technical plans, establish engineering standards, mentor team members, and guide architecture across the sensor codebase.
Top Skills:
Af_XdpEbpfKubernetesLinuxOpentelemetryRustXdp
Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
Provide high-level administrative support to sales executives including calendar, travel, expense reporting, and confidential communication. Prepare reports and sales materials using PowerPoint, Excel, and CRM. Plan and execute internal and external sales events and offsites. Liaise with clients and internal teams, multitask under pressure, and travel a few times a year.
Top Skills:
CoupaCRMExcelGoogle SuiteNavanPowerPointSlack
23 Minutes Ago
Information Technology
Engineer AI-powered threat detections, automated response playbooks, and continuous adversary emulation. Apply machine learning and LLMs to security operations, conduct threat hunting and AI red teaming, map coverage to MITRE ATT&CK, and develop detection-as-code through CI/CD. Build production-grade Python integrations, measurable containment capabilities, and safe autonomous defenses with guardrails. Mentor security professionals and collaborate across threat response, cyber defense engineering, and platform teams.
Top Skills:
AIAtomic Red TeamCalderaCi/CdCloud SecurityCobalt StrikeCrowdstrikeEntra IdInfrastructure-As-CodeLlmsMachine LearningMicrosoft DefenderMicrosoft SentinelMitre Att&CkPolicy-As-CodePythonSIEMSoarSplunkTinesXdr
What you need to know about the Charlotte Tech Scene
Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.
Key Facts About Charlotte Tech
- Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
- Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
- Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
- Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
- Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus



