BeyondTrust

BeyondTrust

BeyondTrust is a global cyber security company specializing in identity and access security solutions, trusted by over 4,000 customers worldwide.

Professional Services
1K-5K
Founded 1985
$49M raised

Description

  • Design and operate the vulnerability management lifecycle, including intake, triage, risk assessment, assignment, SLA tracking, exceptions, and closure verification.
  • Own FedRAMP 20x vulnerability management, including continuous monitoring, machine-readable evidence, Key Security Indicator reporting, and POA&M management.
  • Establish vulnerability management processes for new products and services, including scan coverage, onboarding, SLAs, and reporting.
  • Assess and prioritize risk using exploitability, exposure, asset criticality, and compensating controls.
  • Drive remediation across product engineering teams, escalate overdue findings, and document time-bound risk acceptances.
  • Automate triage, deduplication, enrichment, summarization, workflow, reporting, and evidence collection using scripting, workflow tools, and AI.
  • Define and validate Security Engineering integration requirements for scanners, ticketing, asset inventory, and dashboards.
  • Own and report program metrics, including SLA attainment, remediation time, vulnerability aging, backlog, coverage, and exception volume.
  • Maintain an authoritative view of critical product exposure and communicate current risk, remediation status, and closure timelines.
  • Lead response to actively exploited and zero-day vulnerabilities, including exposure assessment, mitigation tracking, and stakeholder communication.

Requirements

  • 5+ years of experience in vulnerability management, product security, or security operations with direct process ownership.
  • Experience designing and operating vulnerability management in a regulated or audited environment through assessment cycles.
  • Working knowledge of FedRAMP and NIST SP 800-53, including vulnerability scanning, flaw remediation, continuous monitoring, configuration management, and POA&M management.
  • Hands-on experience with vulnerability and exposure management platforms, cloud security posture tools, container scanning, and software composition analysis.
  • Practical automation skills with Python or equivalent, workflow and reporting tools, and AI assistants.
  • Ability to write technical requirements and partner with Security Engineering through design, delivery, and acceptance.
  • Strong knowledge of CVSS, CISA KEV, EPSS, and risk-based prioritization.
  • Working knowledge of AWS or other cloud services, containers, Kubernetes, CI/CD, web applications, and APIs.
  • Ability to drive remediation across engineering teams without direct authority.
  • Clear communication skills with engineers, executives, auditors, and customers.
  • Experience supporting FedRAMP Moderate, High, or FedRAMP 20x is preferred.
  • Experience with executive and audit reporting, SaaS, identity security, privileged access management, or AI-assisted security workflows is preferred.
  • Cloud security certifications, GIAC, CISSP, or equivalent are preferred.

Benefits

  • Fully remote work for candidates based in North America.
  • Flexible, trust-based culture emphasizing continual learning and professional growth.
  • Inclusive workplace focused on diversity, belonging, and employee development.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Security Operations Analyst - Weekend 4x10 Shift

Huntress 251-1K Professional Services

Huntress is seeking a remote US Security Operations Center Analyst to investigate, respond to, and remediate cyber intrusions while supporting customers and improving SOC detection capabilities.

Active Directory AWS Azure Bash Cybersecurity JavaScript Linux macOS PHP PowerShell Python Ruby TCP/IP
4 hours, 17 minutes ago

Security Intern

Crest Industries 51-250 Electrical Equipment

Crest Operations is seeking a Security Intern to support its Enterprise Security & Risk team with cybersecurity operations across manufacturing, cloud, business, and enterprise technology environments.

Active Directory Azure Cybersecurity Power BI SIEM
5 hours, 17 minutes ago

Information Security Analyst

EnableComp 251-1K Insurance

The Security Analyst at EnableComp supports the healthcare revenue cycle company’s security program by maintaining compliance controls, coordinating assessments, and helping protect systems, networks, and information.

Azure Cybersecurity HIPAA
5 hours, 32 minutes ago

Security Scientist

Figma 1K-5K Internet Software & Services

Figma is hiring a Security Scientist to use security expertise and data analysis to reduce risks, improve detection and response, and strengthen the safety of its products, platform, and IT systems.

Apache Spark Presto Python R Snowflake SQL
4 days, 4 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers