Senior Manager, Vulnerability Assessment

🏢 The Nielsen Company · all 21 jobs
📍 United States
📅 Posted Sep 13, 2026 · via Himalayas
🏷 Application Security, Cloud Security, Security Management, Vulnerability Assessment, Devsecops, Vulnerability Assessment Lead +5 more
Apply on original site ↗

Nielsen is seeking a proactive Senior Manager within the Product Security organization to drive and expand our cloud and application security initiatives. This role requires a balance of operational discipline, high-agency, and technical vision.

You will lead a group of skilled engineers and collaborate with development teams to transition our security framework toward a modern, automated, AI-driven DevSecOps model. You will be accountable for team performance, defining security policies, and ensuring compliance, while adapting departmental plans to address operational challenges. Additionally, you will provide subject matter guidance to employees and colleagues operating within policy guidelines with moderate managerial oversight.
Work Style & Mindset

- You prioritize business enablement over rigid perfectionism. You know how to make calculated risk trade-offs, focus on the 20% of risks that cause 80% of the impact, and keep engineering teams moving forward.

- You treat engineering teams as internal customers. You measure success not by how many vulnerabilities you find, but by how easily developers can fix them with minimal friction.

- You possess the grit and diplomatic skills to drive cultural change. You comfortably navigate organizational inertia and win buy-in for AI automation through small, high-impact victories.

- You stay ahead of emerging tech trends, continuously evaluating how AI, cloud-native patterns, and modern tooling can simplify security operations.

- You maintain a steady, analytical composure during high-severity events or pipeline blockers, focusing on automated prevention and root-cause solutions.

Responsibilities

- Lead and mentor a high-performing Application Security engineering team, fostering professional development and aligning team priorities with organizational goals and operational challenges.

- Drive a forward-thinking Application and Pipeline Security strategy that transitions operations to an autonomous, AI-driven DevSecOps model, pioneering agentic security workflows for automated remediation while establishing robust architectural guardrails and validation standards for secure AI-assisted development.

- Partner collaboratively with Platform Engineering to define cloud security baselines and Policy-as-Code (PaC) guardrails.

- Oversee application penetration testing initiatives ensuring findings are triaged, fed into pipeline guardrails, and remediated within SLA.

- Establish comprehensive observability and regulatory standards across the development lifecycle, including supply chain safeguards (SBOM), automated CI/CD security gates, and risk-approval protocols to drive rapid, friction-free remediation and ensure high-confidence visibility.

- Implement structured prioritization protocols to effectively resolve existing security vulnerabilities across application environments and cloud infrastructures.

- Refine and calibrate scanning telemetry (SAST, DAST, SCA, IaC) to minimize false positives and enhance the delivery of high-confidence, actionable intelligence.

- Design automated response triggers within AWS ecosystems utilizing native orchestration tools for rapid isolation and runtime threat containment.

- Cultivate an environment where security is seamlessly embedded into native development workflows, including IDEs and CI/CD pipelines.

- Architect and report on critical performance indicators, such as Mean Time to Remediate (MTTR) and Auto-Fix Acceptance Rates, to demonstrate program efficacy.

- Minimum of 5-8 years of experience in specialized roles across Application Security or Cloud Engineering, including at least 3 years in a management or leadership capacity.

- Demonstrated proficiency in designing AWS security governance and deploying automated incident mitigation within large-scale cloud ecosystems.

- Comprehensive technical mastery of CI/CD orchestration, containerization safeguards, and the integration of SAST/DAST/SCA solutions within developer-centric

← All remote jobs

Get remote jobs like this by email

One weekly digest. No spam, unsubscribe anytime.

Similar for you