Vulnerability Management Lead

Posted Yesterday
Be an Early Applicant
Hiring Remotely in 33134, Miami, FL, USA
In-Office or Remote
Senior level
Logistics • Transportation
The Role
Leads enterprise vulnerability management by configuring and operating scanning tools, validating findings, assessing risk, prioritizing remediation, and coordinating corrective actions with technical and business teams. Develops vulnerability strategies, metrics, reports, coverage processes, and remediation schedules. Oversees application, infrastructure, configuration, and penetration-test findings while ensuring compliance with security standards. Researches emerging threats, advises stakeholders on risk, and verifies remediation effectiveness across on-premises and cloud environments.
Summary Generated by Built In

Job Seekers can review the Job Applicant Privacy Policy by clicking here.

Job Description:

Summary
The Vulnerability Management Lead will ensure continuous vulnerability lifecycle management within the Ryder environment including monitoring, collection, reporting, and assessment of impact for vulnerability related data from vendors and internal resources. This individual will be responsible for configuring vulnerability assessment tools, performing scans, analyzing vulnerabilities, identifying relevant threats, recommending corrective actions, and summarizing results for relevant operational teams. This individual will lead by forming strong partnerships with technical teams and provide vision, strategy, and prioritization to control vulnerabilities in the environment in a timely and effective manner.
Essential Functions

  • Leads the Proactive assessment and remediation of security vulnerabilities within applications and infrastructure software and/ or other Information assets.

  • Establishes strategies and frameworks for performing validation of scanning results. Performs asset and network discovery activities, helping ensure full coverage of vulnerability management environment.

  • Recommend Fixes, Security Patches and other measures required in the event of a security breach. Reviews penetration test findings with system owners in line with vulnerability and asset risk ratings.

  • Define key performance indicators (KPIs) and metrics across business units to illustrate effectiveness with vulnerability management.

  • Implement or coordinates remediation required by vulnerability scans, and audits, and documents exceptions as necessary.

  • Produces vulnerability, configuration, and coverage metrics and reporting to demonstrate assessment coverage and remediation effectiveness

  • Generates reports on assessment findings and prioritizes remediation schedules

  • Maintains Health and effectiveness of Application and device scanning applications and systems within the security.

Additional Responsibilities

  • Reviews security scans and leads/manages resolution of issues.

  • Ensures compliance with all applicable configuration standards

  • Oversees enterprise vulnerability assessment and configuration assessment tools

  • Periodically attend and participate in change management policy discussions and meetings.

  • Regularly research and learn new TTPs in public and closed forums, and work with colleagues to assess risk and implement/validate controls as necessary

  • Leverage vulnerability database sources to understand each weakness, its probability and remediation options, including vendor-supplied fixes and workarounds.

  • Communicate vulnerability results in a manner understood by technical and non-technical business units based on risk tolerance and threat to the business, and gain support through influential messaging.

  • Work closely with infrastructure teams to advise and support remediation efforts to close vulnerability exposure to new threats in the wild and verify the organization’s security posture against them.

  • Perform other duties as assigned.

Skills and Abilities

  • Strong decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one

  • An ability to effectively influence others to modify their opinions, plans, or behaviors

  • An understanding of business needs and commitment to delivering high-quality, prompt, and efficient service to the business

  • An understanding of organizational mission, values, and goals and consistent application of this knowledge

  • Excellent time management and organizational skills

  • Excellent written and verbal communication skills, interpersonal and collaborative skills

  • Skilled at recommending, implementing, and delivering security solutions based on analysis and business requirements

  • Ability to obtain and maintain technical team and business support to influence a collaborative effort to reduce attack surface

  • Proven trustworthiness and history of acting with integrity, taking pride in work, seeking to excel, being curious and adaptable, and communicating well

  • Self-starter requiring minimal supervision

  • Technical expertise in system security vulnerabilities and remediation techniques, network and web-related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, etc.) advanced required

  • Technical expertise in security engineering, system and network security, authentication and security protocols, cryptography, and application security advanced required

  • Knowledge of Microsoft Windows and Linux systems intermediate required

  • Broad understanding of various IT risk and threat assessment methodologies intermediate required

  • Knowledge with prioritizing remediation activities with operational teams through risk ratings of vulnerabilities and assets, intermediate required

  • Sound Knowledge of common infrastructure and web application vulnerabilities and common vulnerability categorizations such as CVE,CVSS,CWE intermediate required

  • Experience with vulnerability management across Amazon Web Services (AWS), Microsoft Azure or Google Cloud Platform (GCP)intermediate preferred

  • Knowledge of one or more compliance standards, including Payment Card Industry (PCI), Health Information Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act (GLBA), National Institute of Standards (NIST) or International Standards Organization (ISO)advanced required

  • Proficient with vulnerability management solutions such as Qualys, Nexpose, Nessus, Kenna Security, Tanium and open source, intermediate required

  • Understanding of OWASP, CVSS, the MITRE ATT&CK framework and the software development life cycle, intermediate required

  • Strong Knowledge of technology and security topics including network security, wireless security, application security, infrastructure hardening, security baselines, and web server and database security, advanced required

Qualifications

  • Bachelor's degree required Computer Science, Information Security, or related field or additional 4 years of required work experience

  • Five (5) years or more experience in information security, especially in a vulnerability analysis role on a Computer Incident Response Team (CIRT), Computer Emergency Response Team (CERT), Computer Security Incident Response Center (CSIRC) or a Security Operations Center (SOC) required

  • Five (5) years or more experience in deploying and operating vulnerability scanning infrastructure and services. required

  • Five (5) years or more experience and direct working knowledge of Information Security control frameworks such as ISO/IEC 27001, NIST CSF, CobIT, etc. required

  • Technical expertise in system security vulnerabilities and remediation techniques, network and web-related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, etc.) advanced required

  • Technical expertise in security engineering, system and network security, authentication and security protocols, cryptography, and application security advanced required

  • Knowledge of Microsoft Windows and Linux systems intermediate required

  • Broad understanding of various IT risk and threat assessment methodologies intermediate required

  • Knowledge with prioritizing remediation activities with operational teams through risk ratings of vulnerabilities and assets. intermediate required

  • Sound Knowledge of common infrastructure and web application vulnerabilities and common vulnerability categorizations such as CVE,CVSS,CWE intermediate required

  • Experience with vulnerability management across Amazon Web Services (AWS), Microsoft Azure or Google Cloud Platform (GCP). intermediate preferred

  • Knowledge of one or more compliance standards, including Payment Card Industry (PCI), Health Information Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act (GLBA), National Institute of Standards (NIST) or International Standards Organization (ISO). advanced required

  • Proficient with vulnerability management solutions such as Qualys, Nexpose, Nessus, Kenna Security, Tanium and open source. intermediate required

  • Understanding of OWASP, CVSS, the MITRE ATT&CK framework and the software development lifecycle. intermediate required

  • Strong Knowledge of technology and security topics including network security, wireless security, application security, infrastructure hardening, security baselines, and web server and database security. advanced required

  • Information Risk, Privacy, or Security Certification (CISSP, CCSK, CCSP, PCSM, OSCP, CEH, GPEN)

Travel
1-10%
DOT Regulated
No

Job Category

Information Security

Our Culture & Commitment:

At Ryder, you’re trusted to make an impact—while enjoying room to grow and having a voice that’s heard. Our culture is built on respect, collaboration, and shared pride in doing great work rooted in innovation and safety.


Your Voice. Your Success. The Future We Build Together.



Compensation Information:

The compensation offered to a candidate may be influenced by a variety of factors, including the candidate’s relevant experience; education, including relevant degrees or certifications; work location; market data/ranges; internal equity; internal salary ranges; etc. The position may also be eligible to receive an annual bonus, commission, and/or long-term incentive plan based on the level and/or type. Compensation ranges for the position are below:

Pay Type:

Salaried

Minimum Pay Range:

Maximum Pay Range:

Benefits Information:

For all Full-time positions only: Ryder offers comprehensive health and welfare benefits, to include medical, prescription, dental, vision, life insurance and disability insurance options, as well as paid time off for vacation, illness, bereavement, family and parental leave, and a tax-advantaged 401(k) retirement savings plan.

Ryder is proud to be an Equal Opportunity Employer and Drug Free workplace.

All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, sex, sexual orientation, gender identity, age, status as a protected veteran, among other things, or status as a qualified individual with disability.

Important Note:

Some positions require additional screening that may include employment and education verification; motor vehicle records check and a road test; and/or badging or background requirements of the customer to which you are assigned. 

Security Notice for Applicants:

Ryder will only communicate with an applicant directly from a [@ryder.com] email address and will never conduct an interview online through a chat type forum, messaging app (such as WhatsApp or Telegram), or via an online questionnaire.  During an interview, Ryder will never ask for any form of payment or banking details and will never solicit personal information outside of the formal submitted application through www.ryder.com/careers.

Should you have any questions regarding the application process or to verify the legitimacy of an interview or Ryder representative, please contact Ryder at [email protected] or 800-793-3754.

Current Employees:

If you are a current employee at Ryder, please click here to log in to Workday to apply using the internal application process.

Job Seekers can review the Job Applicant Privacy Policy by clicking here.

Skills Required

  • Bachelor's degree in Computer Science, Information Security, or a related field, or four additional years of relevant work experience
  • Five or more years of information security experience, especially vulnerability analysis in a CIRT, CERT, CSIRC, or SOC
  • Five or more years of experience deploying and operating vulnerability scanning infrastructure and services
  • Five or more years of direct experience with information security control frameworks such as ISO/IEC 27001, NIST CSF, or COBIT
  • Advanced expertise in system security vulnerabilities, remediation techniques, and network and web protocols including TCP/IP, UDP, IPsec, and HTTP
  • Advanced expertise in security engineering, system and network security, authentication and security protocols, cryptography, and application security
  • Intermediate knowledge of Microsoft Windows and Linux systems
  • Intermediate understanding of IT risk and threat assessment methodologies
  • Intermediate knowledge of prioritizing remediation activities using vulnerability and asset risk ratings
  • Intermediate knowledge of infrastructure and web application vulnerabilities and CVE, CVSS, and CWE categorizations
  • Experience managing vulnerabilities across AWS, Microsoft Azure, or Google Cloud Platform
  • Advanced knowledge of compliance standards including PCI, HIPAA, GLBA, NIST, or ISO
  • Intermediate proficiency with vulnerability management solutions including Qualys, Nexpose, Nessus, Kenna Security, Tanium, or open-source tools
  • Intermediate understanding of OWASP, CVSS, MITRE ATT&CK, and the software development lifecycle
  • Advanced knowledge of network, wireless, and application security, infrastructure hardening, security baselines, web server security, and database security
  • Information Risk, Privacy, or Security certification such as CISSP, CCSK, CCSP, PCSM, OSCP, CEH, or GPEN
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Coral Gables, FL
5,180 Employees

What We Do

Ryder is a FORTUNE 500® commercial fleet management, dedicated transportation, and supply chain solutions company. Ryder’s stock (NYSE:R) is a component of the Dow Jones Transportation Average and the Standard & Poor’s 500 Index. Ryder has been named among FORTUNE’s World’s Most Admired Companies, and has been recognized for its industry-leading practices in third-party logistics, environmentally-friendly fleet and supply chain solutions, and world-class safety and security programs. The Company is a proud member of the American Red Cross Disaster Responder Program, supporting national and local disaster preparedness and response efforts. For more information, visit www.ryder.com, and follow us on our Online Newsroom, Facebook, Twitter, Google+, and YouTube.

Similar Jobs

PwC Logo PwC

Procurement-Senior Associate

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Remote or Hybrid
67 Locations
370000 Employees
151K-187K Annually

PwC Logo PwC

Executive Concierge- Dallas

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Remote or Hybrid
48 Locations
370000 Employees
109K-124K Annually

General Motors Logo General Motors

Escalation Team - Advisor, High Voltage

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Remote or Hybrid
United States
165000 Employees

Headway Logo Headway

Product Manager

Consumer Web • Healthtech • Professional Services • Social Impact • Software
Remote
USA
819 Employees
265K-332K Annually

Similar Companies Hiring

Toro TMS Thumbnail
Cloud • Enterprise Web • Sales • Software • Transportation
Chicago, IL
80 Employees
Axle Health Thumbnail
Artificial Intelligence • Healthtech • Information Technology • Logistics
Santa Monica, CA
25 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account