Job posting has expired
Manager, Vulnerability Management - Enterprise Security
![]() | |
![]() | |
![]() | |
![]() | |
![]() 5985 State Bridge Road (Show on map) | |
![]() | |
Be part of an amazing story. Macy's is more than just a store. We're a story. One that's captured the hearts and minds of America for more than 160 years. A story about innovations and traditions...about inspiring stores and irresistible products...about the excitement of the Macy's 4th of July Fireworks, and the wonder of the Thanksgiving Day Parade. We've been part of memorable moments and milestones for countless customers and colleagues. Those stories are part of what makes this such a special place to work. Job Overview The Manager, Vulnerability Management provides strategic direction and collaborates across enterprise teams to develop, coordinate, elevate, and streamline the vulnerability management program. They draw on extensive experience in vulnerability management and penetration testing to ensure the program's continuous improvement. This role oversees the enhancement of vulnerability platforms, works closely with security and business teams to create innovative risk mitigation strategies, and ensures compliance with established policies. The Manager also communicates key metrics to senior leaders and remediation teams across the enterprise. They possess expertise in a variety of security testing tools, including BurpSuite, HP WebInspect, Core Impact, Tenable, MetaSploit, and Qualys. Additionally, they are well-versed in penetration testing, vulnerability scanning, and red teaming methodologies. The Manager is capable of explaining vulnerabilities and weaknesses in the CISA KEV, OWASP Top 10, and CWE 25 to diverse audiences and discussing effective defensive techniques. What You Will Do
Skills You Will Need Regulatory Compliance: Strong knowledge of regulatory compliance requirements, including PCI-DSS, SOX, and GLBA. Security Infrastructure: Advanced knowledge in security infrastructure design and architecture for both new implementations and existing infrastructure. Enterprise Security: Experience in designing and implementing enterprise-wide security strategies, policies, and standards. Threat Protection: Experience protecting large enterprise environments from internal and external attacks. Vulnerability Management: Strong understanding of network, physical, application, and web security as it relates to vulnerability management. Advanced knowledge of common vulnerabilities, testing approaches, and remediation strategies. Security Technologies: Expert understanding of current and emerging security technologies, defense strategies, and industry standards. Ability to determine and recommend security-related products and activities, influencing decision-making processes. Interpersonal Skills: Advanced leadership, facilitation, and interpersonal skills to work across functional lines and at various levels. Communication: Excellent written and verbal communication skills, with the ability to read, write, and interpret instructional documents. Certifications: One or more certifications such as CISSP, CEH, Secure+, OCSP, GPEN, CISA, CISM, GWAPT, GXPN etc. preferred. Who You Are
What We Can Offer You
About Us This is a great time to join Macy's! Whether you're helping a customer find the perfect gift, streamlining operations in one of our distribution centers, enhancing our online shopping experience, buying in-style and on-trend merchandise to outfit our customers, or designing a balloon for the Thanksgiving Day Parade, we offer unique opportunities to be part of some of the most memorable moments in people's lives. Join us and help write the next chapter in our story - Apply Today! This job description is not all-inclusive. Macy's, Inc. reserves the right to amend this job description at any time. Macy's, Inc. is an Equal Opportunity Employer, committed to a diverse and inclusive work environment. TECH00 LEGALRE00 |