Saronic Logo

Saronic

Vulnerability Management Lead

Posted 6 Hours Ago
Be an Early Applicant
In-Office
Austin, TX, USA
Senior level
In-Office
Austin, TX, USA
Senior level
Lead and run the end-to-end vulnerability management program across cloud, on‑prem, container, embedded, and classified systems. Own scanning, triage, prioritization, remediation tracking, exception governance, CI/CD integration, reporting, automation, and compliance (CMMC/NIST). Drive remediation accountability, lead critical CVE response, and communicate risk to leadership.
The summary above was generated by AI

Saronic Technologies is a leader in revolutionizing autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations through autonomous and intelligent platforms.

Job Overview

We're looking for a hands-on Vulnerability Management Lead to own Saronic's VM program end-to-end. You will be the technical authority for vulnerability discovery, triage, prioritization, remediation, and reporting across our entire environment — cloud, on-prem, embedded systems, and classified infrastructure. This is an individual contributor role with significant operational and strategic ownership: you'll build and run the program, drive accountability across engineering teams, and shape the long-term VM posture as Saronic scales.

You're a doer first. You're also someone who can step back, think about the program architecturally, and communicate risk clearly to leadership. The right person for this role has strong opinions about how VM should work, isn't afraid to push for remediation ownership across the org, and sees automation as the path to scale.

Responsibilities

Vulnerability Operations

  • Own end-to-end vulnerability lifecycle: discovery, validation, prioritization, remediation tracking, exception management, and verification across cloud, on-prem, container, and embedded Linux environments

  • Operate and optimize enterprise vulnerability scanning platforms for continuous credentialed scanning across servers, endpoints, network devices, containers, and cloud assets; maintain coverage, schedules, and configuration audit policies

  • Integrate vulnerability scanning into CI/CD pipelines to harden build workflows, enforce least-privilege controls, and surface supply chain risks before they reach production

  • Leverage AI-assisted scanning and graph-based enrichment pipelines to accelerate triage, map lateral exposure paths, and prioritize findings by exploitability and mission impact

  • Correlate findings across tools to eliminate noise, reduce false positives, and surface the vulnerabilities that actually matter

Prioritization & Remediation Leadership

  • Apply CVSS, CISA KEV, exploit maturity, and asset exposure context — including internet-facing systems, privileged access paths, and classified adjacency — to drive risk-based SLAs and remediation sequencing

  • Partner with software and platform engineering teams to drive timely remediation; own escalation paths for aging critical and high findings

  • Lead critical CVE response: rapid triage, impact assessment, containment guidance, and stakeholder communication for zero-days and actively exploited vulnerabilities

  • Govern exception management: risk acceptance with compensating controls, time-bound approvals, and periodic review cycles

  • Coordinate patching windows and change management across Windows, Linux, network devices, and cloud services

Compliance & Reporting

  • Align the VM program to CMMC Level 2/3 requirements; produce audit-ready evidence, POA&Ms, and control effectiveness documentation

  • Deliver executive and operational reporting: exposure trends, SLA performance, mean time to remediate, patch coverage, and remediation velocity

  • Support CMMC assessments and audits with clean, well-documented vulnerability data and remediation history

  • Maintain asset inventory hygiene and scan coverage metrics; ensure classified and sensitive system boundaries are respected in tooling and data handling

Program Maturity & Automation

  • Build and mature automation for scan scheduling, finding enrichment, ticket creation, SLA tracking, and reporting — reducing manual overhead as the program scales

  • Define and refine VM policies, procedures, and playbooks including critical CVE response runbooks and patch cadence standards

  • Evaluate and recommend tooling improvements; drive integration across the vulnerability management and broader security stack

  • Mentor and support analysts as the team grows; run tabletop exercises for vulnerability and patching scenarios

Qualifications
  • 5+ years in cybersecurity with 3+ years of hands-on vulnerability management ownership in hybrid on-prem/cloud environments

  • Deep operational expertise with enterprise vulnerability scanning platforms — credentialed scanning, policy tuning, coverage management, and integration with downstream workflows

  • Strong command of CVE/CVSS scoring, CISA KEV, exploit maturity indicators, and the ability to translate technical risk into business impact for non-technical stakeholders

  • Experience with CI/CD security tooling and supply chain risk management, including build pipeline security principles

  • Proven track record driving remediation accountability across engineering teams — you know how to get vulnerabilities closed, not just reported

  • Experience aligning VM programs to federal or defense compliance frameworks; CMMC, NIST SP 800-171, or NIST RMF experience strongly preferred

  • Metrics-driven: comfortable owning exposure reduction KPIs, SLA adherence, MTTR, and patch coverage dashboards

  • Clear, direct communicator — equally effective in a technical deep-dive and an executive briefing

  • Security clearance eligibility

Preferred Qualifications

  • Active Secret or TS clearance, or prior clearance history

  • Experience with AI-assisted vulnerability tooling, graph-based asset and exposure analysis, or automated enrichment pipelines

  • Experience with CI/CD pipeline security hardening platforms

  • Experience operating in classified or air-gapped environments

  • Scripting or automation experience (Python, PowerShell, or Bash) for scan orchestration, data normalization, API integrations, and reporting pipelines

  • Experience with container and cloud-native vulnerability management using CSP-native security tooling

  • Familiarity with NIST SP 800-218 (Secure Software Development Framework) and software supply chain security frameworks

  • Relevant certifications: CISSP, CySA+, GCSA, GCPN, Security+, or equivalent

Physical Demands
  • Prolonged periods of sitting at a desk and working on a computer

  • Occasional standing and walking within the office

  • Manual dexterity to operate a computer keyboard, mouse, and other office equipment

  • Visual acuity to read screens, documents, and reports

  • Occasional reaching, bending, or stooping to access file drawers, cabinets, or office supplies

  • Lifting and carrying items up to 20 pounds occasionally (e.g., office supplies, packages)

Benefits

Medical Insurance: Comprehensive health insurance plans covering a range of services

Saronic pays 100% of the premium for employees and 80% for dependents

Dental and Vision Insurance: Coverage for routine dental check-ups, orthodontics, and vision care

Saronic pays 100% of the premium under the basic plan for employees and 80% for dependents

Time Off: Generous PTO and Holidays

Parental Leave: Paid maternity and paternity leave to support new parents

Competitive Salary: Industry-standard salaries with opportunities for performance-based bonuses

Retirement Plan: 401(k) plan with company match

Stock Options: Equity options to give employees a stake in the company’s success

Life and Disability Insurance: Basic life insurance and short- and long-term disability coverage

Pet Insurance: Discounted pet insurance options including 24/7 Telehealth helpline

Additional Perks: Free lunch benefit and unlimited free drinks and snacks in the office

Saronic CCPA Notice for Candidates and California Employees

If this role is based in the United States, it requires access to export-controlled information or items that require “U.S. Person” status. As defined by U.S. law, individuals who are any one of the following are considered to be a “U.S. Person”: (1) U.S. citizens, (2) legal permanent residents (a.k.a. green card holders), and (3) certain protected classes of asylees and refugees, as defined in 8 U.S.C. 1324b(a)(3).
Saronic does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity or any other reason prohibited by law in provision of employment opportunities and benefits. We are also committed to providing reasonable accommodations for qualified individuals with disabilities.

HQ

Saronic Austin, Texas, USA Office

Austin, TX, United States

Similar Jobs

35 Minutes Ago
Easy Apply
Remote or Hybrid
USA
Easy Apply
196K-245K Annually
Senior level
196K-245K Annually
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
Lead the enterprise data platform strategy and architecture, driving Snowflake/dbt-based platform evolution, self-service Data Mesh and medallion models. Build AI-ready pipelines, RAG systems, and observability/cost frameworks while managing a central data team, supporting federated BI, and executing hands-on technical work.
Top Skills: AiopsAutomated TestingCi/CdCortexData MeshDbtGitGraph RagMatillion Data Productivity Cloud (Matillion Dpc)Medallion ArchitecturePythonRetrieval-Augmented Generation (Rag)SnowflakeSnowparkSQLStreamlit
38 Minutes Ago
Hybrid
Austin, TX, USA
133K-226K Annually
Senior level
133K-226K Annually
Senior level
Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Lead and manage a team of 4–10 software engineers as a player/coach, providing mentoring, hiring, and performance management while contributing significant technical design and implementation across the software lifecycle for electronic warfare systems. Support program execution (cost, schedule, metrics) and collaborate with cross-functional leads to meet customer requirements.
Top Skills: C++
39 Minutes Ago
Hybrid
Austin, TX, USA
Senior level
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
Lead and drive threat detection, response, and emulation programs: align stakeholders, define roadmaps, build AI/automation for program administration, coordinate incident response and postmortems, manage dependencies, timelines, scope, OKRs, and executive reporting while operating across cross-functional teams and time zones.
Top Skills: ConfluenceGemini GemsJIRAOpencode

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account