Sr Manager, Vulnerability & Exposure Management

DatavantNew York City, NY
14h$224,000 - $280,000

About The Position

Datavant is a data platform company and the world’s leader in health data exchange. Our vision is that every healthcare decision is powered by the right data, at the right time, in the right format. Our platform is powered by the largest, most diverse health data network in the U.S., enabling data to be secure, accessible and usable to inform better health decisions. Datavant is trusted by the world’s leading life sciences companies, government agencies, and those who deliver and pay for care. By joining Datavant today, you’re stepping onto a high-performing, values-driven team. Together, we’re rising to the challenge of tackling some of healthcare’s most complex problems with technology-forward solutions. Datavanters bring a diversity of professional, educational and life experiences to realize our bold vision for healthcare. What We’re Looking For As the Sr Manager of Vulnerability & Exposure Management, you will lead and grow a highly technical team responsible for the vulnerability and attack surface exposure reduction of Datavant’s applications and infrastructure. You’ll play a pivotal role in defining the strategy and framework for the management of risk in a shared responsibility model, guiding a team of skilled engineers, and partnering with cross-functional leaders to drive down vulnerabilities and weaknesses.

Requirements

  • Proven experience leading a vulnerability management program, with a strong ability to build, mentor, and inspire technical talent.
  • Well-formed opinions on what makes a successful vulnerability and exposure management program
  • Understanding and background in standing up vulnerability aggregation and/or ASPM platforms.
  • Strong experience with vulnerability identification sources including application penetration testing, application code scanning(SCA, SAST), cloud and container analysis(CNAPP).
  • Depth of knowledge working with Wiz.
  • Experience with attack surface management tools.
  • An engineering background with practical knowledge of how to automate and integrate systems through custom software development, building pipelines, and LCNC orchestration.
  • Excellent collaboration and communication skills, capable of influencing stakeholders across technical and non-technical teams.
  • Minimum of 5 years of experience in vulnerability management, including at least 3 years of leadership experience.
  • Experience in highly regulated industries such as healthcare, with knowledge of frameworks like HIPAA, HITRUST, and SOC 2 (preferred).

Nice To Haves

  • A background in software engineering and automation
  • Ability to directly contribute to engineering efforts for the program in a hands on keyboard fashion
  • Experience with AI assisted software development such as Claude Code
  • Recent work in a FedRAMP environmen

Responsibilities

  • Use your deep understanding of vulnerability management to help refine the shared responsibility vulnerability and exposure management framework for Datavant.
  • Consolidate the infrastructure and application security detection functions under a single banner.
  • Simplify and where possible, automate the onboarding and integration to our scanning technologies beyond out of the box vendor connections.
  • Provide direct technical engineering guidance and coaching, including code review to your team.
  • Own creating the reporting and presentation for our exposure posture across all detection sources, with metrics rolled up and broken down across multiple facets to drive risk reduction.
  • Smoothly mesh vulnerability management practices into our secure SDLC.
  • Identify and implement a solution to give Datavant a prioritized, single pane of glass view of all vulnerabilities and misconfigurations.
  • Work directly with security senior leadership to ensure maturity, depth, and coverage of our exposure management program.
  • Speak on vulnerability management to government agencies on behalf of Datavant for our FedRAMP compliance.
  • Have an understanding of risks, but may have some knowledge gaps in depth of risk management. It’s OK, we’ll teach you. The core skill set you bring to the table is an engineering mindset.
  • Own new projects for advancing security in our environment.
  • Be the deep technical expert and collaborate with others on the teams to ensure project success.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service