Cloudflare Logo

Cloudflare

Director, Vulnerability Management

Posted 10 Hours Ago
Be an Early Applicant
Hybrid
3 Locations
Expert/Leader
Hybrid
3 Locations
Expert/Leader
Lead the vulnerability management program, oversee strategies and teams, enhance application security, and ensure compliance with regulations.
The summary above was generated by AI
Available Locations: London, England | Lisbon, Portugal | Austin, Texas
About the role
We are seeking an experienced Director of Vulnerability Management to lead and mature our security program in this critical area. This role is responsible for defining, implementing, and overseeing the comprehensive strategy for identifying, assessing, prioritizing, and remediating vulnerabilities across our entire technology stack, including applications throughout the software development lifecycle.
What You'll Do
  • Develop and lead teams of skilled professionals in the areas of vulnerability management and application security.
  • Enhance and execute comprehensive strategies for vulnerability management and application security that align with the company's risk appetite and business objectives.
  • Define and track key performance indicators (KPIs) and metrics to measure the effectiveness of security programs and report on progress to executive leadership.
  • Stay abreast of emerging threats, vulnerabilities, and security technologies to continuously evolve and improve security posture.
  • Advocate for and secure resources (budget, personnel, tools) necessary to achieve program objectives.
  • Recruit, mentor, and develop a high-performing team of security engineers and analysts.
  • Foster a culture of continuous learning, collaboration, and accountability within the security team.
  • Provide strong technical leadership and guidance to direct reports and cross-functional teams.
  • Contribute to the development and enforcement of security policies, standards, and procedures.
  • Support internal and external audits by providing evidence of security controls and processes.
  • Ensure compliance with internal policies, relevant industry regulations and frameworks.
  • Partner closely with engineering, product, IT, and legal teams to embed security best practices throughout the organization.
  • Communicate complex security concepts and risks effectively to both technical and non-technical stakeholders.
  • Mature the existing vulnerability management program covering infrastructure, networks, containers, cloud environments, and endpoints.
  • Oversee the selection, implementation, and optimization of vulnerability scanning tools (e.g. DAST, SAST, SCA, secrets detections, and web application and infrastructure vulnerability scanners) and platforms, and integration into CI/CD pipelines and infrastructure.
  • Ensure security technology strategies are aligned with companies' business goals.
  • Enforce policies and procedures for vulnerability identification, assessment, prioritization, remediation, and tracking.
  • Collaborate with IT operations, engineering, and development teams to ensure timely and effective remediation of identified vulnerabilities.
  • Develop security policies, procedures, and guidelines and recommend necessary changes to a given project team to ensure the company's systems are fully compliant with all applicable regulatory requirements and privacy laws.
  • Utilize open communication and managerial courage to ensure the standards, expectations and goals of the organization are respected and upheld.
  • Manage the bug bounty program and external application penetration testing engagements.
  • Ensure the application security program is integrated into every phase of the software development lifecycle.
  • Define and implement secure coding standards, guidelines, and best practices.
  • Collaborate closely with development teams to provide security guidance, perform threat modeling, and conduct security reviews of application architecture and codebases.
  • Manage and prioritize vulnerability and security findings from various sources (scans, penetration tests, bug bounties, etc.).
  • Leverage wide-ranging experiences, professional concepts, and company objectives to resolve complex issues in creative and effective ways.
  • Exercise judgment in selecting methods, techniques and evaluation criteria for obtaining results.

Examples of desirable skills, knowledge and experience.
  • Extensive experience in information security, with multiple years in a leadership role focused on vulnerability management and/or application security.
  • Proven experience building, scaling, and leading successful vulnerability management and application security programs from the ground up or significantly maturing existing ones.
  • Deep expertise in modern application security principles, secure SDLC, DevSecOps, and secure coding practices.
  • Strong understanding of common web application vulnerabilities (OWASP Top 10) and remediation techniques.
  • Hands-on experience with various security tools, including:
  • Vulnerability scanners
  • SAST (static application security testing)
  • DAST (dynamic application security testing)
  • SCA (software composition analysis)
  • Secrets detection tools
  • Web application security testing
  • Static and runtime container scanning
  • Experience with cloud security (AWS, Azure, GCP) and securing cloud-native applications.
  • Familiarity with container security and orchestration technologies (e.g., Docker, Kubernetes).
  • Excellent leadership, communication (written and verbal), and interpersonal skills.
  • Ability to influence and drive change at all levels of the organization.
  • Relevant industry certifications (e.g., CISSP, CISM, CSSLP, CEH) are highly desirable.
  • Experience with threat modeling methodologies (e.g., STRIDE, DREAD).
  • Experience producing and reviewing Technical Documentation.

Top Skills

AWS
Azure
Dast
Docker
GCP
Kubernetes
Sast
Sca
Secrets Detection Tools
Static And Runtime Container Scanning
Vulnerability Scanners
Web Application Security Testing

Similar Jobs at Cloudflare

10 Hours Ago
Hybrid
Austin, TX, USA
Internship
Internship
Cloud • Information Technology • Security • Software • Cybersecurity
The Data Analytics Intern will analyze learning data, build dashboards, and help improve enablement strategies to impact sales productivity.
Top Skills: ExcelLmsSalesforceSQLTableau
10 Hours Ago
Hybrid
4 Locations
Senior level
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
The Senior Sales Compensation Analyst ensures timely delivery of compensation plans and serves as a partner to the sales team, driving alignment and managing analytics. They support strategic decision-making through data analysis and project management.
Top Skills: ExcelGoogle SheetsVaricent Icm
10 Hours Ago
Hybrid
Austin, TX, USA
Senior level
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
Manage and execute Cloudflare's global equity compensation programs while ensuring compliance and accuracy. Lead projects for system improvements and collaborate with various departments.
Top Skills: E*Trade Equity Edge Online

What you need to know about the Edinburgh Tech Scene

From traditional pubs and centuries-old universities to sleek shopping malls and glass-paneled office buildings, Edinburgh's architecture reflects its unique blend of history and modernity. But the fusion of past and future isn't just visible in its buildings; it's also shaping the city's economy. Named the United Kingdom's leading technology ecosystem outside of London, Edinburgh plays host to major global companies like Apple and Adobe, as well as a growing number of innovative startups in fields like cybersecurity, finance and healthcare.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account