SonicJobs Logo
Left arrow iconBack to search

Vulnerability Manager (Contract)

Tokio Marine HCC
Posted 2 months ago, valid for 23 days
Location

Houston, TX 77203, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The Vulnerability Manager position is located in Houston, TX, and operates on a hybrid schedule of four days in the office and one day remote.
  • This contract-to-hire role reports to the Director of Security Governance and requires a minimum of 5 years of experience in vulnerability management or related cybersecurity roles.
  • The successful candidate will lead the organization's vulnerability management program, focusing on identifying, assessing, and remediating security vulnerabilities across various environments.
  • A bachelor's degree in Cybersecurity, Information Technology, or a related field is required, along with relevant certifications such as CISSP or CEH preferred.
  • The salary for this position is competitive and commensurate with experience.

Job Title: Vulnerability Manager
Location: Houston, TX (Hybrid 4:1)
Reports To: Director of Security Governance
Employment Type: Contract - Temp to Hire
 

About Us

Help us insure it. Tokio Marine HCC is a leading global specialty insurance group, backed by the strength and stability of the Tokio Marine Group. With more than 50 years of sustained growth and profitability, and offices across the United States, the United Kingdom, Europe, and other international locations, we offer more than 100 classes of specialty insurance—covering everything from the crops that feed us and the concerts that entertain us to rescuing travelers abroad.

Guided by our Mind Over Risk philosophy, we empower clients to pursue opportunities with confidence while fostering a culture rooted in innovation, collaboration, and trust. Always Advancing, we embrace an entrepreneurial spirit; as Experts in Tomorrow, we anticipate what’s next; and by Reaching Out, we build genuine connections that enable our people and our business to thrive.

Role Overview

Lead the organization's vulnerability management program by identifying, assessing, prioritizing, and coordinating the remediation of security vulnerabilities across IT infrastructure, applications, and cloud environments. Improve the organization's security posture through continuous risk reduction.

Key Responsibilities

  • Develop and manage the enterprise vulnerability management lifecycle, including scanning, assessment, reporting, and remediation tracking.
  • Conduct regular vulnerability scans using Qualys or similar platforms.
  • Analyze scan results, validate findings, and work with IT and development teams to prioritize and remediate vulnerabilities.
  • Maintain an accurate inventory of assets and ensure proper coverage of vulnerability scanning tools.
  • Collaborate with threat intelligence and incident response teams to assess exploitability and risk context.
  • Track remediation efforts and provide regular status updates to leadership and stakeholders.
  • Develop and maintain metrics and dashboards to measure program effectiveness and risk reduction.
  • Stay current with emerging threats, vulnerabilities, and security advisories.
  • Support compliance and audit activities related to vulnerability management.
  • Provide guidance and training on secure configuration and patch management best practices.

What You Bring

Education

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field.
  • Relevant certifications preferred: CISSP, OSCP, CEH, CompTIA Security+, or similar.

Experience

  • 5+ years of experience in vulnerability management, security operations, or related cybersecurity roles.
  • Experience with vulnerability management tools (e.g., Qualys, Akamai).
  • Experience with ticketing systems (e.g., ServiceNow, Jira) and GRC platforms is a plus.
  • Scripting or automation experience (e.g., Python, PowerShell).
  • Experience with container and DevSecOps vulnerability management (e.g., Docker, Kubernetes, SCA tools).

Key Competencies

  • Strong knowledge of vulnerability scanning tools and techniques.
  • Familiarity with Windows, Linux, networking, AWS, Azure, and web application security.
  • Understanding of CVSS scoring, risk assessment methodologies, and remediation workflows.
  • Strong communication and collaboration skills.
  • Ability to manage multiple priorities in a fast-paced environment.

Equal Opportunity Employer

TMHCC is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity, genetic information, marital status, medical condition, national origin, physical or mental disability, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations, and ordinances.

#LI-SD1




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.