City/State
Norfolk, VAWork Shift
First (Days)Overview:
OverviewThe ASM Manager leads the Cyber Attack Surface Management function, responsible for assisting with strategy, execution, and continuous improvement of capabilities that reduce the organization’s cyber exposure. This role ensures alignment with enterprise risk priorities and coordinates across security, IT, and business units.
- Define and execute the ASM program strategy, roadmap, and priorities.
- Oversee all ASM functions: threat intelligence, third-party incident management, identity hygiene, vulnerability management, and legacy OS risk tracking.
- Establish governance, processes, and performance metrics.
- Act as primary stakeholder liaison across Security Operations, IT, Risk, and Vendor Management.
- Drive risk-based prioritization and decision-making.
- Present risk posture, trends, and recommendations to senior leadership.
- Ensure integration with CTOC and broader cyber security programs.
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field—or equivalent industry training and certifications. (Preferred)
or
- Experience in lieu of Bachelor’s Degree -7 yrs relevant years’ experience without a degree
- Certification or License (Preferred)- CISSP/ CISM/CRISC/ Vendor/platform certifications related to vulnerability management, cloud security, or threat intelligence are a plus
- 7 yrs relevant years’ experience without a degree
- 5+ years of experience with a degree
- Experience leading or supporting Cyber Attack Surface Management (ASM), vulnerability management, threat intelligence, or cyber exposure management programs.
- Strong hands-on experience coordinating vulnerability remediation efforts and driving risk reduction initiatives across cross-functional teams.
- Experience building, operationalizing, and maturing cybersecurity processes, governance frameworks, and remediation workflows.
- Experience partnering with Security Operations, Infrastructure, Cloud, IAM, Risk, Compliance, and Vendor Management teams in a complex enterprise environment.
- Experience with cybersecurity platforms and tools such as Tenable, Qualys, CrowdStrike, ServiceNow, Microsoft Defender, Palo Alto, or similar technologies.
We provide market-competitive compensation packages, inclusive of base pay, incentives, and benefits. The base pay rate for Full Time employment is:$116,729.60-$216,777.60. Additional compensation may be available for this role such as shift differentials, standby/on-call, overtime, premiums, extra shift incentives, or bonus opportunities.
•Legal Resources Plan
•Colleagues have the opportunity to earn an annual discretionary bonus if established system and employee eligibility criteria is met.
Sentara Health is an equal opportunity employer and prides itself on the diversity and inclusiveness of its close to an almost 30,000-member workforce. Diversity, inclusion, and belonging is a guiding principle of the organization to ensure its workforce reflects the communities it serves.
In support of our mission “to improve health every day,” this is a tobacco-free environment.
For positions that are available as remote work, Sentara Health employs associates in the following states:
Alabama, Delaware, Florida, Georgia, Idaho, Indiana, Kansas, Louisiana, Maine, Maryland, Minnesota, Nebraska, Nevada, New Hampshire, North Carolina, North Dakota, Ohio, Oklahoma, Pennsylvania, South Carolina, South Dakota, Tennessee, Texas, Utah, Virginia, Washington, West Virginia, Wisconsin, and Wyoming.
Skills Required
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field or equivalent industry training and certifications
- 7 yrs relevant experience without a degree
- 5+ years of experience with a degree
- Experience leading or supporting Cyber Attack Surface Management programs
- Strong hands-on experience coordinating vulnerability remediation efforts
- Experience building and maturing cybersecurity processes and frameworks
- Experience partnering with Security Operations and other teams in an enterprise environment
- Experience with cybersecurity tools and platforms
Sentara Healthcare Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Sentara Healthcare and has not been reviewed or approved by Sentara Healthcare.
-
Parental & Family Support — Four weeks of paid parental leave at full base pay and two weeks of job‑protected family caregiver leave support major life and care needs. Emergency back‑up care and reimbursements for infertility, adoption, and surrogacy further bolster family support.
-
Retirement Support — A 401(A) plan alongside 403(B)/401(K) employer matching is designed to strengthen long‑term financial security. Company‑paid life insurance with buy‑up options adds additional protection for families.
-
Flexible Benefits — Choice of medical plan designs and dental/vision options enables tailoring coverage to individual needs. An annual election between tuition assistance and student‑loan repayment offers flexibility to align with financial or education priorities.
Sentara Healthcare Insights
What We Do
Sentara Healthcare celebrates a 130-year history of innovation, compassion and community benefit. Based in Norfolk, VA, Sentara is a diverse not-for-profit family of 12 hospitals, an array of integrated services and a team of nearly 30,000 strong on a mission to improve health every day. This mandate is pursued through a disciplined strategy to achieve Top 10% performance in key measures through shared best practices, transformation of primary care through clinical integration and strategic growth that adds value to the communities we serve in Virginia and North Carolina.

.jpeg)




