|
Ampcus Inc. is a certified global provider of a broad range of Technology and Business consulting services. We are in search of a highly motivated candidate to join our talented Team. Job Title: Director - Vulnerability Management & Cloud Security Platform 2 Location(s): New York City, NY (Hybrid: On-Site in either New York City, NY; Pittsburgh, PA; or Washington, DC; 4 days a week) Job Summary We are seeking a Director - Vulnerability Management & Cloud Security Platform to join a Cybersecurity Engineering Tools & Platforms team. This is a highly technical individual contributor role responsible for engineering, operating, and continuously improving enterprise vulnerability management and cloud security platforms. The position combines platform ownership, automation, cloud security, infrastructure engineering, and operational excellence to enhance enterprise cyber risk visibility and resilience. Key Responsibilities
- Own engineering and operational responsibility for enterprise vulnerability management and cloud security posture management platforms.
- Administer and maintain enterprise security platforms, including platform health, upgrades, configuration, integrations, onboarding, access management, troubleshooting, and vendor support.
- Improve platform scalability, reliability, automation, data quality, performance, and operational resilience.
- Manage scanner infrastructure, agents, cloud connectors, platform configurations, tenant administration, and service health.
- Support vulnerability scanning across servers, endpoints, databases, network devices, appliances, cloud environments, containers, and internet-facing assets.
- Collaborate with infrastructure and networking teams on scanner deployment, routing, segmentation, firewall configuration, authenticated scanning, and connectivity troubleshooting.
- Drive enterprise asset discovery, inventory reconciliation, CMDB integration, ownership validation, and coverage reporting.
- Build automation using APIs, scripting, configuration management, dashboards, reporting workflows, and data pipeline integrations.
- Integrate security platforms with CMDBs, ticketing systems, cloud platforms, enterprise reporting, and remediation workflows.
- Enable vulnerability prioritization, remediation tracking, SLA management, exception handling, and critical vulnerability response.
- Monitor platform health, create operational dashboards, support incident response, disaster recovery, business continuity, and vendor escalations.
- Manage SSO, RBAC, privileged access, API tokens, service accounts, audit evidence, and regulatory compliance requirements.
- Troubleshoot issues involving scanners, agents, APIs, cloud connectors, identity systems, networking, firewalls, routing, and reporting platforms.
- Develop automation using Python, Go, Java, or similar programming languages.
- Mentor engineers and improve operational documentation, runbooks, and engineering standards.
Required Qualifications
- Bachelor's degree in Computer Science or a related discipline (or equivalent experience); advanced degree preferred.
- 10-12 years of information security or related technology experience.
- Experience supporting enterprise cybersecurity platforms within large organizations; financial services experience is preferred.
- Strong experience operating vulnerability management, asset discovery, scanning, cloud security posture management, or cloud-native security platforms.
- Hands-on experience supporting production environments, incident management, change management, platform monitoring, and lifecycle management.
- Strong engineering background with automation, APIs, configuration management, and operational optimization.
- Deep understanding of vulnerability management processes, remediation tracking, SLA governance, ownership validation, and exception management.
- Strong networking knowledge including TCP/IP, DNS, routing, firewalls, proxies, NAT, segmentation, packet flow analysis, and troubleshooting.
- Experience scanning enterprise infrastructure including servers, endpoints, databases, network devices, appliances, containers, cloud assets, and internet-facing systems.
- Knowledge of scanner architecture, authenticated scanning, credential management, agent health, and scan troubleshooting.
- Experience with AWS, Azure, and GCP cloud environments including IAM, APIs, cloud connectors, and cloud security controls.
- Experience integrating security platforms with CMDBs, ticketing systems, reporting platforms, enterprise dashboards, and cloud services.
- Strong understanding of identity and access management including SSO, MFA, RBAC, privileged access, service accounts, and API security.
- Programming experience with Python, Go, Java, or similar languages.
- Experience troubleshooting distributed enterprise security platforms across networking, cloud, identity, APIs, and data pipelines.
- Experience supporting audits, compliance reporting, production controls, and regulatory requirements.
- Experience with Kubernetes, container security, image scanning, runtime visibility, registry integrations, and cloud-native asset inventory.
Preferred Qualifications
- Experience with Qualys, Wiz, Lumeta, or comparable vulnerability management and cloud security platforms.
- Experience supporting FedRAMP-authorized or FedRAMP-aligned cloud environments.
- Knowledge of FedRAMP controls, continuous monitoring, vulnerability scanning, access governance, compliance reporting, and cloud security operations.
Desired Skills
- Vulnerability Management
- Cloud Security Posture Management (CSPM)
- Cybersecurity Platform Engineering
- Enterprise Security Operations
- Qualys
- Wiz
- Lumeta
- AWS
- Azure
- Google Cloud Platform (GCP)
- Kubernetes
- Container Security
- Asset Discovery
- Network Security
- Infrastructure Security
- TCP/IP
- DNS
- Firewalls
- Routing
- Network Segmentation
- API Integration
- Python
- Go
- Java
- Automation
- Infrastructure as Code
- Configuration Management
- CMDB Integration
- ServiceNow
- Identity and Access Management (IAM)
- SSO
- RBAC
- MFA
- Privileged Access Management
- Incident Response
- Change Management
- Disaster Recovery
- Business Continuity
- Security Compliance
- FedRAMP
- Audit Support
- Vulnerability Scanning
- Cloud Connectors
- Data Pipelines
- Dashboarding
- Reporting
- DevSecOps
Success Profile
- Own and operate enterprise vulnerability management and cloud security platforms.
- Improve platform reliability, scalability, and operational resilience.
- Expand security visibility across enterprise infrastructure and cloud environments.
- Enable effective vulnerability reporting, remediation tracking, and compliance.
- Reduce manual effort through automation and standardized engineering practices.
- Strengthen governance, access controls, platform stability, and production readiness.
Ampcus is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veterans or individuals with disabilities.
|