Summary
Lead, Vulnerability & Exposure Management - Hybrid in NYC or Fort Worth, TX (FTE/Direct-hire)
Optomi, in partnership with a global PE firm, is hiring a Lead Vulnerability & Exposure Management to help mature and lead a growing enterprise vulnerability management program for a global financial services organization.
Location: New York, NY or Fort Worth, TX
This is a high-impact opportunity for someone who wants to go beyond traditional vulnerability scanning and reporting. The team is looking for a hands-on security leader who can take a vulnerability from identification through validation, risk analysis, attack-path assessment, and remediation follow-through.
The environment is currently earlier in its vulnerability management maturity journey, so this person will have the opportunity to significantly influence how the program evolves.
What you'll be responsible for:
- Own and mature the vulnerability management lifecycle across endpoints, servers, networks, cloud platforms, applications, containers, and other enterprise technologies
- Validate vulnerabilities and determine real-world exploitability rather than relying solely on scanner severity
- Build the “attack story” around findings by connecting vulnerabilities to threat actors, TTPs, attack paths, and business impact
- Partner with infrastructure, network, cloud, application, and technology owners to drive remediation through closure
- Improve asset visibility, scanner coverage, data quality, and vulnerability-management processes
- Help mature exposure-management capabilities, including internal/external attack surface and attack-path analysis
- Evaluate vulnerability and exposure recommendations from platforms such as Microsoft Defender and determine what is truly actionable
- Support risk-based prioritization, risk acceptance, compensating controls, and remediation decisions when vulnerabilities cannot immediately be patched
- Monitor emerging vulnerabilities, active exploitation, threat intelligence, and evolving AI-related security risks
- Provide initial incident/security-event triage and identify when activity requires deeper investigation or escalation
- Communicate vulnerability and exposure risk clearly to both technical teams and senior leadership
What we're looking for:
- Strong background in enterprise Vulnerability Management or Exposure Management
- Experience owning vulnerabilities beyond the “scan and report” stage
- Ability to analyze exploitability, attack paths, threat activity, and business risk
- Working knowledge of Incident Response, security operations, or threat analysis
- Experience with tools such as Qualys, Tenable, Rapid7/Nexpose, Microsoft Defender Vulnerability Management, or similar platforms
- Understanding of asset-management and vulnerability-data reconciliation across enterprise environments
- Familiarity with CVSS, EPSS, CISA KEV, threat intelligence, risk acceptance, and compensating controls
- Strong communication skills and the ability to influence remediation without direct authority
- Ability to operate independently and comfortably communicate with senior leadership
This is an excellent opportunity for someone who wants to take ownership of a vulnerability program, improve its maturity, and connect vulnerability management more directly with threat intelligence, incident response, and real-world exposure.
Job Description
Lead, Vulnerability & Exposure Management - Hybrid in NYC or Fort Worth, TX (FTE/Direct-hire)
Optomi, in partnership with a global PE firm, is hiring a Lead Vulnerability & Exposure Management to help mature and lead a growing enterprise vulnerability management program for a global financial services organization.
Location: New York, NY or Fort Worth, TX
This is a high-impact opportunity for someone who wants to go beyond traditional vulnerability scanning and reporting. The team is looking for a hands-on security leader who can take a vulnerability from identification through validation, risk analysis, attack-path assessment, and remediation follow-through.
The environment is currently earlier in its vulnerability management maturity journey, so this person will have the opportunity to significantly influence how the program evolves.
What you'll be responsible for:
- Own and mature the vulnerability management lifecycle across endpoints, servers, networks, cloud platforms, applications, containers, and other enterprise technologies
- Validate vulnerabilities and determine real-world exploitability rather than relying solely on scanner severity
- Build the “attack story” around findings by connecting vulnerabilities to threat actors, TTPs, attack paths, and business impact
- Partner with infrastructure, network, cloud, application, and technology owners to drive remediation through closure
- Improve asset visibility, scanner coverage, data quality, and vulnerability-management processes
- Help mature exposure-management capabilities, including internal/external attack surface and attack-path analysis
- Evaluate vulnerability and exposure recommendations from platforms such as Microsoft Defender and determine what is truly actionable
- Support risk-based prioritization, risk acceptance, compensating controls, and remediation decisions when vulnerabilities cannot immediately be patched
- Monitor emerging vulnerabilities, active exploitation, threat intelligence, and evolving AI-related security risks
- Provide initial incident/security-event triage and identify when activity requires deeper investigation or escalation
- Communicate vulnerability and exposure risk clearly to both technical teams and senior leadership
What we're looking for:
- Strong background in enterprise Vulnerability Management or Exposure Management
- Experience owning vulnerabilities beyond the “scan and report” stage
- Ability to analyze exploitability, attack paths, threat activity, and business risk
- Working knowledge of Incident Response, security operations, or threat analysis
- Experience with tools such as Qualys, Tenable, Rapid7/Nexpose, Microsoft Defender Vulnerability Management, or similar platforms
- Understanding of asset-management and vulnerability-data reconciliation across enterprise environments
- Familiarity with CVSS, EPSS, CISA KEV, threat intelligence, risk acceptance, and compensating controls
- Strong communication skills and the ability to influence remediation without direct authority
- Ability to operate independently and comfortably communicate with senior leadership
This is an excellent opportunity for someone who wants to take ownership of a vulnerability program, improve its maturity, and connect vulnerability management more directly with threat intelligence, incident response, and real-world exposure.
Government Careers
Government jobs offer stability, competitive benefits, and the chance to make a meaningful impact on your community and country.
Whether you’re starting your career or seeking new opportunities, these roles provide pathways for growth, security, and service.
Explore positions across a wide range of fields and take the first step toward a rewarding future in public service.
MORE JOBS
-
Lead Statistical Assistant (Administrative Specialist 1)
- Trenton, New Jersey
- New Jersey Judiciary
- Sep 30, 2026
-
Residence Program Specialist Mon-Thurs, Sun 3pm-11pm
- New York, New York
- Adapt Community Network
- Oct 08, 2026
-
Program Specialist EPICS in IEEE
- Piscataway, New Jersey
- IEEE
- Oct 08, 2026
-
R&D Co-Op
- Raritan, New Jersey
- Johnson and Johnson
- Oct 08, 2026
-
Teen Program Specialist - Bronx, NY
- Bronx, New York
- Boys Club of NY
- Oct 08, 2026
-
Accelerated Path to Management Program
- New Windsor, New York
- New York Life
- Oct 08, 2026