Job Overview:
We are looking for a strategic and technically capable Cyber Defense Vulnerability Manager to lead vulnerability management initiatives within our Cyber Defense Operations (CDO) function. Responsible for the vulnerability remediation strategy, aligning with Arm's global security standards and running the operational execution of the vulnerability management lifecycle.
Responsibilities:
- Develop and lead strategic vulnerability management and Attack surface management initiatives across teams and geographies.
- Drive remediation accountability and ensure alignment with business risk profiles.
- Coordinate integration of threat intelligence and vulnerability scanning and Penetration Testing tools (e.g., Tenable, Qualys) with ServiceNow workflows.
- Define Key Performance Indicators and metrics to govern remediation efficiency and SLA compliance.
- Collaborate with global teams, including Product Security, Red Team, Threat Intelligence, and Engineering.
- Provide leadership and mentoring to vulnerability analysts.
- Champion process automation and tooling enhancements.
- Drive operational transformation to mature existing processes, procedures and tooling.
- Lead the response efforts for major vulnerabilities in conjunction with security partners across the business. Act as a senior technical authority, as well as an escalation point for advanced response coordination.
- Scope and perform security reviews of platforms, web applications, mobile applications, and private and public cloud environments.
- Identify architectural deficiencies and implement vulnerability mitigation strategies to address.
Required Skills and Experience:
- Demonstrable experience leading a vulnerability and Attack Surface management function in a global or enterprise-scale environment.
- Expertise in platforms like ServiceNow Vulnerability Management, Tenable, and third-party integrations.
- Sufficient understanding of web technologies to handle Web vulnerabilities.
- Solid understanding of security governance, frameworks (ISO 27001, NIST), and risk assessment practices.
- Demonstrated leadership in running multi-functional teams and stakeholder alignment.
- Ability to articulate security risk and remediation impact to executive audiences.
- Exposure to Networking, automation, scripting, and API integrations.
- Specialist technical knowledge spanning security and IT domains to enable a comprehensive response to vulnerabilities of the highest complexity, as well as cross organisational incident management.
- Detailed cyber security threat landscape knowledge and experience in bringing it to bear in response to a vulnerability.
“Nice To Have” Skills and Experience:
- Bachelor’s or Master’s in Cybersecurity, IT, or related field!
- Certifications such as CISSP, CISM, GIAC (GCCC, GCPM), or PMP.
- Understanding of Agile or DevSecOps practices!
#LI-PC1
Accommodations at Arm
At Arm, we want to build extraordinary teams. If you need an adjustment or an accommodation during the recruitment process, please email accommodations@arm.com. To note, by sending us the requested information, you consent to its use by Arm to arrange for appropriate accommodations. All accommodation or adjustment requests will be treated with confidentiality, and information concerning these requests will only be disclosed as necessary to provide the accommodation. Although this is not an exhaustive list, examples of support include breaks between interviews, having documents read aloud, or office accessibility. Please email us about anything we can do to accommodate you during the recruitment process.
Hybrid Working at Arm
Arm’s approach to hybrid working is designed to create a working environment that supports both high performance and personal wellbeing. We believe in bringing people together face to face to enable us to work at pace, whilst recognizing the value of flexibility. Within that framework, we empower groups/teams to determine their own hybrid working patterns, depending on the work and the team’s needs. Details of what this means for each role will be shared upon application. In some cases, the flexibility we can offer is limited by local legal, regulatory, tax, or other considerations, and where this is the case, we will collaborate with you to find the best solution. Please talk to us to find out more about what this could look like for you.
Equal Opportunities at Arm
Arm is an equal opportunity employer, committed to providing an environment of mutual respect where equal opportunities are available to all applicants and colleagues. We are a diverse organization of dedicated and innovative individuals, and don’t discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.