Saronic

Saronic

Vulnerability Management Lead

Austin, TX

No sponsorship$171k-$800kDetected 34 days ago
TypeScriptPythonBashPowerShellCloud PlatformsCI/CDLinuxPlatform EngineeringCybersecurityComplianceStakeholder ManagementSupply ChainCadenceEmbedded SystemsLeadershipCommunication

About the role

  • You will be the technical authority for vulnerability discovery, triage, prioritization, remediation, and reporting across our entire environment - cloud, on-prem, embedded systems, and classified infrastructure.
  • You're also someone who can step back, think about the program architecturally, and communicate risk clearly to leadership.
  • The right person for this role has strong opinions about how VM should work, isn't afraid to push for remediation ownership across the org, and sees automation as the path to scale.

Responsibilities

  • Own end-to-end vulnerability lifecycle: discovery, validation, prioritization, remediation tracking, exception management, and verification across cloud, on-prem, container, and embedded Linux environments
  • Operate and optimize enterprise vulnerability scanning platforms for continuous credentialed scanning across servers, endpoints, network devices, containers, and cloud assets
  • Integrate vulnerability scanning into CI/CD pipelines to harden build workflows, enforce least-privilege controls, and surface supply chain risks before they reach production
  • Apply CVSS, CISA KEV, exploit maturity, and asset exposure context - including internet-facing systems, privileged access paths, and classified adjacency - to drive risk-based SLAs and remediation sequencing
  • Partner with software and platform engineering teams to drive timely remediation
  • own escalation paths for aging critical and high findings
  • Lead critical CVE response: rapid triage, impact assessment, containment guidance, and stakeholder communication for zero-days and actively exploited vulnerabilities

Requirements

  • Strong command of CVE/CVSS scoring, CISA KEV, exploit maturity indicators, and the ability to translate technical risk into business impact for non-technical stakeholders
  • Experience with CI/CD security tooling and supply chain risk management, including build pipeline security principles
  • Proven track record driving remediation accountability across engineering teams - you know how to get vulnerabilities closed, not just reported
  • 5+ years in cybersecurity with 3+ years of hands-on vulnerability management ownership in hybrid on-prem/cloud environments
  • Deep operational expertise with enterprise vulnerability scanning platforms - credentialed scanning, policy tuning, coverage management, and integration with downstream workflows
  • Experience aligning VM programs to federal or defense compliance frameworks; CMMC, NIST SP 800-171, or NIST RMF experience strongly preferred

Nice to have

  • Active Secret or TS clearance, or prior clearance history
  • Experience with AI-assisted vulnerability tooling, graph-based asset and exposure analysis, or automated enrichment pipelines
  • Experience with CI/CD pipeline security hardening platforms
  • Experience operating in classified or air-gapped environments
  • Scripting or automation experience (Python, PowerShell, or Bash) for scan orchestration, data normalization, API integrations, and reporting pipelines
  • Experience with container and cloud-native vulnerability management using CSP-native security tooling
  • Familiarity with NIST SP 800-218 (Secure Software Development Framework) and software supply chain security frameworks
  • Relevant certifications: CISSP, CySA+, GCSA, GCPN, Security+, or equivalent

Skills

  • Correlate findings across tools to eliminate noise, reduce false positives, and surface the vulnerabilities that actually matter
  • Coordinate patching windows and change management across Windows, Linux, network devices, and cloud services
  • Align the VM program to CMMC Level 2/3 requirements; produce audit-ready evidence, POA&Ms, and control effectiveness documentation

Compensation

  • Industry-standard salaries with opportunities for performance-based bonuses
  • Competitive Salary: Industry-standard salaries with opportunities for performance-based bonuses

Benefits

  • Free lunch benefit and unlimited free drinks and snacks in the office
  • Medical Insurance: Comprehensive health insurance plans covering a range of services
  • Dental and Vision Insurance: Coverage for routine dental check-ups, orthodontics, and vision care
  • Time Off: Generous PTO and Holidays
  • Parental Leave: Paid maternity and paternity leave to support new parents
  • Retirement Plan: 401(k) plan with company match
  • Stock Options: Equity options to give employees a stake in the company's success
  • Life and Disability Insurance: Basic life insurance and short- and long-term disability coverage

Company info

  • We are also committed to providing reasonable accommodations for qualified individuals with disabilities.

Visa & Work Authorization

  • Security clearance eligibility

This listing is sourced directly from Saronic's careers page and normalized into a canonical job model.