Vulnerability Program Manager

🏢 NetCov · all NetCov jobs
📍 United States
💰 USD 75,000 - 100,000 / annual
📅 Posted 2026-08-22 · via Himalayas
🏷 Vulnerability-Management,Patch-Management,Cybersecurity-Program-Management,Security-Operations,IT-Security,Vulnerability-Management-Coordinator,Vulnerability-Management-Specialist,Vulnerability-Management-Engineer,Vulnerability-Management-Analyst,Vulnerability-Management-Expert,Security-Program-Manager,Vulnerability-Manager,DevSecOps-Program-Manager,Cybersecurity-Program-Manager,Vulnerability-Analyst,Program-Manager
Apply on original site ↗

Company Overview

At NetCov , we specialize in delivering cutting-edge IT and cybersecurity solutions designed to protect and optimize the digital infrastructure for the industries we serve. We differentiate ourselves from our competition through our deep and intimate knowledge of our customers’ business.

NetCov was built through the integration of seven specialized companies, each with deep expertise and proud client relationships. Our mandate is to preserve the boutique, client-intimate culture that made each of those companies successful while delivering the depth, scale, and consistency that no one of them could achieve alone.

About the Role

The Vulnerability Program Manager owns how NetCov delivers vulnerability management and patching to our clients. Today that work is delivered differently from account to account, shaped by the practices each of our legacy companies brought with them. This role exists to turn that into one program: a defined service with a documented process, a predictable cadence, consistent reporting, and clear ownership of every step from discovery through verified remediation.

Reporting to the Director of Security Services, the Vulnerability Program Manager is the single point of accountability for the program. This is a hands-on role. The Program Manager is expected to run client vulnerability reviews personally, work directly in the tooling, and write the standards the rest of the team will follow, rather than managing the work from a distance.

The role sits at the center of a delivery chain the Program Manager does not fully control. Scanning data comes from multiple platforms, remediation is often executed by NetCov service desk and engineering teams or by the client themselves, and clients hold approval over their own change windows. Success therefore depends as much on building working rhythm and agreement with those groups as it does on the technical work.

Accountabilities

Program Definition and Standards

- Own the end-to-end vulnerability management and patching program, covering asset discovery, scanning, prioritization, remediation tracking, verification, and reporting.

- Define and document the standard service: scan frequency, patch cadence, severity-based remediation targets, exception and risk-acceptance handling, and the criteria for emergency out-of-band work.

- Establish and maintain the RACI for the program so it is clear which work belongs to the Vulnerability Analysts, security engineering, the service desk, and the client.

- Define ticket types, templates, and workflows in HaloPSA so that patch work, remediation work, and scan evidence are captured consistently and can be reported on.

- Set the standard for what constitutes acceptable evidence of remediation, including where a report rather than a ticket is the appropriate audit artifact.

Delivery Execution

- Run the recurring vulnerability management cadence for assigned clients, including monthly or quarterly review meetings, and hold the follow-through between meetings.

- Maintain a prioritized remediation backlog per client and drive it down, escalating stalled items rather than allowing them to age quietly.

- Coordinate remediation execution across NetCov delivery teams and client staff, including scheduling around change windows and maintenance periods.

- Manage exclusions, suppressions, and risk acceptances deliberately, ensuring that anything removed from a report is documented with a reason, an owner, and a review date.

- Serve as the escalation point for emergency vulnerability response, including zero-day and actively exploited issues that require out-of-cycle patching.

Client Engagement and Reporting

- Own the client-facing report catalog, including the recurring vulnerability review deck, aging and trend analysis, and executive summaries suitable for non-technical audiences.

- Present program status to client stakeholders and translate scan output into a clear picture of risk, progress,

← All remote jobs