Lead the enterprise CTEM and Vulnerability Management program, including its strategy, roadmap, and operating model.
Oversee vulnerability scanning and assessment across infrastructure, cloud, endpoint, application, identity, network, and OT environments.
Manage the product security vulnerability lifecycle with Product Security, including intake, triage, risk assessment, remediation tracking, software bill of materials (SBOM) analysis, and coordinated vulnerability disclosure support.
Prioritize vulnerabilities and exposures using CVSS, EPSS, CISA Known Exploited Vulnerabilities (KEV), threat intelligence, asset criticality, and business context.
Lead attack surface management, exposure validation, and breach and attack simulation activities to confirm exploitability and control effectiveness.
Evaluate emerging vulnerabilities, exploits, and threat intelligence affecting enterprise systems, marketed products, and embedded systems.
Drive automation for vulnerability discovery, data enrichment, ticketing, remediation workflows, and reporting through SOAR platforms, APIs, Python, or PowerShell.
Support cyber incident investigations with vulnerability context, exposure analysis, and remediation expertise.
Leadership & People Management Responsibilities:
Partner with Infrastructure, Cloud, Application, Product Security, and Engineering teams to establish risk-based service-level agreements, drive remediation, and track plans of action and milestones.
Establish governance standards, quality assurance procedures, and documentation for vulnerability and exposure management operations.
Measure and report exposure reduction, remediation performance, validation results, and operational metrics to executive stakeholders.
Lead vulnerability management, exposure management, or product security vulnerability teams.
Knowledge and Capabilities:
Analyze complex vulnerability data and large volumes of exposure telemetry to identify risk and guide response.
Translate technical findings, remediation status, and risk trends into clear written, verbal, and presentation-ready updates for technical and executive audiences.
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related discipline.
Minimum 10 years of experience in cybersecurity.
Minimum 3 years of experience leading vulnerability management, exposure management, or product security vulnerability teams.
Experience managing product vulnerabilities, including triage, coordinated vulnerability disclosure, SBOM analysis, and remediation with product engineering teams.
Experience with Tenable, Qualys, Rapid7, Wiz, ServiceNow Vulnerability Response, or equivalent vulnerability and exposure management technologies.
Experience implementing automation through SOAR platforms, APIs, Python, or PowerShell.
Preferred Qualifications
Master's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related discipline.
CISSP, CISM, GEVA, GPEN, GIAC, Tenable, Qualys, or equivalent professional certification.
Posted Date: 09/14/2026 This role will be posted for a minimum of 3 days.
United States of America Pay Ranges:
USN: $155,900 - $259,700 USD Annual
US5: $163,700 - $272,700 USD Annual
US10: $171,500 - $285,700 USD Annual
US15: $179,300 - $298,700 USD Annual
US20: $187,100 - $311,600 USD Annual
US30: $202,700 - $337,600 USD Annual
About Stryker
Healthcare10,001+Founded 1941
Stryker is a global medical technology company offering innovative products and services in surgical equipment, neurotechnology, orthopaedics, and spine care.