Vulnerability Management Team Lead

Posted 10 Hours Ago
Be an Early Applicant
Hiring Remotely in United States
Remote or Hybrid
110K-185K Annually
Senior level
Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
The Role
Lead a remote Vulnerability Management team to manage the full vulnerability lifecycle: discovery, triage, risk-based prioritization, remediation oversight, automation, and reporting. Partner with IT, DevOps, Security Engineering, and business units to enforce SLAs, drive threat-informed risk reduction, and deliver KPIs and dashboards for stakeholders.
Summary Generated by Built In

SailPoint is seeking a Vulnerability Management (VM) Team Lead to oversee the daily operations of our VM program. As a critical member of our Cybersecurity organization, you will play a crucial role in protecting our systems and data by leading a team dedicated to the continuous discovery, accurate assessment, risk-based prioritization, and successful remediation of vulnerabilities across all company assets. This is a hands-on leadership role for someone who wants to help drive the cultural and technical shift from reactive vulnerability patching to proactive, threat-informed risk reduction.

You will lead a growing threat and vulnerability management team of both emerging and established talent and partner closely with our Attack Surface Management team lead as well as VM Architect. At SailPoint, we value our "4 I's" (Integrity, Individuals, Impact, and Innovation), and we're looking for someone who embodies these principles. By being your authentic self, you will be a positive and influential contributor to our already fantastic work culture. This is a challenging and high-impact role where you will build strong partnerships with colleagues across IT, DevOps, Security Engineering, and business units.

This role is fully remote and can be based anywhere in the United States.

What You'll Do (Core Responsibilities):

Lead Daily VM Operations:

  • Oversee the day-to-day operational activities of a team of Vulnerability Management Analysts. Provide technical guidance, mentorship, and support to elevate the overall skill set of the group.

  • Manage the end-to-end vulnerability lifecycle, ensuring continuous discovery, triage, and assignment of vulnerabilities across cloud and corporate infrastructure.

Drive Risk-Based Prioritization:

  • Develop and enforce a prioritization framework that utilizes risk context beyond standard CVSS scores, factoring in asset criticality, internal threat intelligence, and active exploitation in the wild.

  • Collaborate with the risk team and business leaders to establish risk acceptance criteria and service level objectives (SLOs), ensuring remediation efforts align with the organizational risk appetite.

Lead the Remediation Lifecycle:

  • Serve as an escalation point and subject matter expert to help VM analysts and asset owners (IT, DevOps, Engineering) understand risks, identify dependencies, and facilitate the remediation process.

  • Track remediation progress across business units and ensure compliance with defined SLAs.

Automate and Improve Processes:

  • Drive continuous improvement in the efficiency of vulnerability operations by identifying opportunities for automation across the tech stack (e.g., automating data ingestion, ticketing system integration via Jira, and integrating VM data into SIEM/SOAR).

Reporting & Metrics:

  • Generate operational Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs), such as Mean Time to Remediate (MTTR), Remediation Compliance Rate, and overall vulnerability density.

  • Provide program performance reporting, scorecards, and dashboards for different business units, translating technical data for non-technical stakeholders and executive leadership.

What You'll Need (Must-Have Experience & Skills):

  • 5-7+ years in Cybersecurity, with 2-3+ years in a leadership, team lead, or senior operational role focused specifically on Vulnerability Management.

  • Expert-level, hands-on experience with enterprise vulnerability assessment tools and platforms (e.g., Qualys, CrowdStrike, Wiz, Orca, etc.).

  • Deep technical understanding of vulnerability classification (CVSS, CVE, EPSS), risk vs. severity, and modern patching processes for Windows, Mac, Linux, and containerized environments.

  • Strong familiarity with securing modern complex cloud environments (AWS, Azure, GCP) and corporate infrastructure.

What Will Set You Apart (Bonus Points):

  • Demonstrable proficiency in a scripting language (Python or PowerShell strongly preferred) used for API integration, data analysis, and automation.

  • Experience with regulatory frameworks and compliance requirements (e.g., NIST, ISO 27001, SOC2, FedRAMP).

  • Background in penetration testing, threat intelligence, or attack surface management. Experience establishing or maturing a vulnerability management program from the ground up.

  • Professional certifications such as CISSP, CISM, AWS

Leadership Qualities for This Role:

  • Pragmatic & Results-Oriented: You make informed, risk-based decisions that balance business priorities with security needs to achieve measurable outcomes.

  • Influence & Collaboration: You have a proven ability to build strong, collaborative relationships across diverse technical teams and drive change without direct authority.

  • An Analytical & Investigative Mindset: You possess an innate curiosity and a structured approach to problem-solving, with a talent for turning ambiguous data into a clear action plan.

  • Clear Communicator: You can distill complex technical concepts into clear, concise language for a variety of audiences, from junior analysts to senior executives.

Note: Candidates are required to obtain the AWS Certified Cloud Practitioner or AWS Certified Security - Specialty certification within the first year of employment if they do not already possess it

The Path to Success (Milestones):

60-Day Milestones (The "Connecting" Phase):

  • Become fully comfortable with core processes and tools, including reporting, ticketing, and internal workflows.

  • Solidify relationships with key members of the vulnerability management team and begin engaging with stakeholders in Engineering, IT, and Compliance.

  • Begin performing routine vulnerability management tasks, such as validating scans and initiating remediation ticketing, with increasing independence with a keen eye for areas of improvement.

90-Day Milestones (The “Performance" Phase):

  • Begin overseeing day-to-day routine vulnerability management tasks accomplished by your team of analysts with minimal oversight. This includes running team stand-ups.

  • Act as the initial escalation point for vulnerability analysts, providing mentorship and helping to resolve challenges with remediation teams.

  • Confidently engage with engineering and IT teams to work through remediation problems and ensure operational flow.

  • Demonstrate a deep understanding of our risk-based approach by prioritizing vulnerabilities.

6-Month Milestones (The “Leading" Phase):

  • Become a strong, effective team leader who actively identifies and suggests areas for process and documentation improvement.

  • Take the lead on an internal team project, such as revamping vulnerability metrics or automating a reporting process.

  • Identify training gaps for your team members and work with leadership to develop training plans to address those gaps.

12-Month Milestones (The "Ownership" Phase):

  • Solidly own all day-to-day operational tasks and responsibilities for the Vulnerability Management team, running with them from start to finish with minimal supervision.

  • Actively contribute to maturing the team by bringing in new ideas, finding process efficiencies, and mentoring analysts on technical and communication skills.

  • Establish and maintain strong, trusted relationships with cross-functional partners in Engineering, Compliance, and other departments, effectively working through complex problems together.


Benefits and Compensation listed vary based on the location of your employment and the nature of your employment with SailPoint.


As a part of the total compensation package, this role may be eligible for the SailPoint Corporate Bonus Plan or a role-specific commission, along with potential eligibility for equity participation. SailPoint maintains broad salary ranges for its roles to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect SailPoint’s differing products, industries, and lines of business. Candidates are typically placed into the range based on the preceding factors as well as internal peer equity. We estimate the base salary, for US-based employees, will be in this range from (min-max, USD):

$109,900 - $185,260.00

Base salaries for employees based in other locations are competitive for the employee’s home location.

Benefits Overview

1. Health and wellness coverage: Medical, dental, and vision insurance

2. Disability coverage: Short-term and long-term disability

3. Life protection: Life insurance and Accidental Death & Dismemberment (AD&D)

4. Additional life coverage options: Supplemental life insurance for employees, spouses, and children

5. Flexible spending accounts for health care, and dependent care; limited purpose flexible spending account

6. Financial security: 401(k) Savings and Investment Plan with company matching

7. Time off benefits: Flexible vacation policy

8. Holidays: 8 paid holidays annually

9. Sick leave

10. Parental support: Paid parental leave

11. Employee Assistance Program (EAP) and Care Counselors

12. Voluntary benefits: Legal Assistance, Critical Illness, Accident, Hospital Indemnity and Pet Insurance options

13. Health Savings Account (HSA) with employer contribution

SailPoint is an equal opportunity employer and we welcome all qualified candidates to apply to join our team.  All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other category protected by applicable law.  

Alternative methods of applying for employment are available to individuals unable to submit an application through this site because of a disability. Contact [email protected] or mail to 11120 Four Points Dr, Suite 100, Austin, TX 78726, to discuss reasonable accommodations.  NOTE: Any unsolicited resumes sent by candidates or agencies to this email will not be considered for current openings at SailPoint.

Skills Required

  • 5-7+ years in Cybersecurity with 2-3+ years in a leadership, team lead, or senior operational role focused on Vulnerability Management.
  • Expert-level, hands-on experience with enterprise vulnerability assessment tools and platforms (e.g., Qualys, CrowdStrike, Wiz, Orca).
  • Deep technical understanding of vulnerability classification and scoring (CVSS, CVE, EPSS), risk vs. severity, and patching processes for Windows, Mac, Linux, and containerized environments.
  • Strong familiarity securing modern cloud environments (AWS, Azure, GCP) and corporate infrastructure.
  • Experience managing end-to-end vulnerability lifecycle, triage, assignment, remediation tracking, and enforcement of remediation SLAs.
  • Experience integrating VM data into SIEM/SOAR, automating data ingestion and ticketing system integration (e.g., via Jira).
  • Ability to generate and present operational KPIs/KRIs and dashboards to technical and non-technical stakeholders.
  • Required to obtain AWS Certified Cloud Practitioner or AWS Certified Security - Specialty within the first year if not already held.
  • Proven leadership, mentorship, strong communication, and ability to influence cross-functional teams without direct authority.
  • Proficiency in scripting for automation and API integration (Python or PowerShell).
  • Experience with regulatory frameworks and compliance (NIST, ISO 27001, SOC2, FedRAMP).
  • Background in penetration testing, threat intelligence, or attack surface management; experience building/maturing VM programs.
  • Professional certifications such as CISSP, CISM, or relevant AWS certifications.

SailPoint Compensation & Benefits Highlights

  • Parental & Family Support Parental leave is characterized as generous, with fully paid time available to either parent and additional family medical leave and on‑site support (such as mother’s rooms). This family‑forward design is regularly highlighted alongside community and inclusion programs.
  • Leave & Time Off Breadth Paid time off is described as flexible or unlimited, complemented by paid sick time, holidays, and volunteer time off. The structure emphasizes ease of taking time away and supports work‑life balance across many roles.
  • Healthcare Strength Health coverage is presented as comprehensive across medical, dental, and vision, with mental‑health resources and plan options that can include low‑ or no‑premium HDHPs in some cases. Disability and life insurance further reinforce the benefits package.

SailPoint Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Austin, TX
2,461 Employees
Year Founded: 2005

What We Do

At SailPoint, we believe enterprise security must start with identity at the foundation. Today’s enterprise runs on a diverse workforce of not just human but also digital identities—and securing them all is critical. Through the lens of identity, SailPoint empowers organizations to seamlessly manage and secure access to applications and data at speed and scale. Our unified, intelligent, and extensible platform delivers identity-first security, helping enterprises defend against dynamic threats while driving productivity and transformation. Trusted by many of the world’s most complex organizations, SailPoint secures the modern enterprise.

Why Work With Us

Together, we’re redefining identity’s place in the security ecosystem. We love taking on new challenges that seem daunting to others. We hold ourselves to the highest standards and deliver upon our promises to our customers. We bring out the best in each other, and we’re having a lot of fun doing it.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

SailPoint Teams

Team
International Culture
Team
Engineering
Team
Professional Services
Team
Sales
About our Teams

SailPoint Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Typical time on-site: Flexible
HQAustin, TX
Amsterdam, NL
Coyoacán, Ciudad de México
London, GB
Pune, Maharashtra
Toronto, Ontario
Learn more

Similar Jobs

SailPoint Logo SailPoint

Staff Software Engineer

Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
United States
2461 Employees
156K-263K Annually

SailPoint Logo SailPoint

Sales Executive

Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
Colorado, USA
2461 Employees
109K-165K Annually

SailPoint Logo SailPoint

Regional Vice President, Strategic Accounts

Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
Texas, USA
2461 Employees
126K-212K Annually

SailPoint Logo SailPoint

Principal Engineer

Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
United States
2461 Employees
185K-313K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account