Mediabistro logo
job logo

Director - Vulnerability Management & Cloud Security Platform 2

Ampcus, Inc · New York, NY, USA ·

Pay:
180.000 - 230.000
Job type:
Full Time

Ampcus Inc. is a certified global provider of a broad range of Technology and Business consulting services. We are in search of a highly motivated candidate to join our talented Team.

Job Title:
Director - Vulnerability Management & Cloud Security Platform 2

Location(s):
New York City, NY (Hybrid: On-Site in either New York City, NY; Pittsburgh, PA; or Washington, DC; 4 days a week)

Job Summary
We are seeking a Director - Vulnerability Management & Cloud Security Platform to join a Cybersecurity Engineering Tools & Platforms team. This is a highly technical individual contributor role responsible for engineering, operating, and continuously improving enterprise vulnerability management and cloud security platforms. The position combines platform ownership, automation, cloud security, infrastructure engineering, and operational excellence to enhance enterprise cyber risk visibility and resilience.

Key Responsibilities

Own engineering and operational responsibility for enterprise vulnerability management and cloud security posture management platforms.

Administer and maintain enterprise security platforms, including platform health, upgrades, configuration, integrations, onboarding, access management, troubleshooting, and vendor support.

Improve platform scalability, reliability, automation, data quality, performance, and operational resilience.

Manage scanner infrastructure, agents, cloud connectors, platform configurations, tenant administration, and service health.

Support vulnerability scanning across servers, endpoints, databases, network devices, appliances, cloud environments, containers, and internet-facing assets.

Collaborate with infrastructure and networking teams on scanner deployment, routing, segmentation, firewall configuration, authenticated scanning, and connectivity troubleshooting.

Drive enterprise asset discovery, inventory reconciliation, CMDB integration, ownership validation, and coverage reporting.

Build automation using APIs, scripting, configuration management, dashboards, reporting workflows, and data pipeline integrations.

Integrate security platforms with CMDBs, ticketing systems, cloud platforms, enterprise reporting, and remediation workflows.

Enable vulnerability prioritization, remediation tracking, SLA management, exception handling, and critical vulnerability response.

Monitor platform health, create operational dashboards, support incident response, disaster recovery, business continuity, and vendor escalations.

Manage SSO, RBAC, privileged access, API tokens, service accounts, audit evidence, and regulatory compliance requirements.

Troubleshoot issues involving scanners, agents, APIs, cloud connectors, identity systems, networking, firewalls, routing, and reporting platforms.

Develop automation using Python, Go, Java, or similar programming languages.

Mentor engineers and improve operational documentation, runbooks, and engineering standards.

Required Qualifications

Bachelor's degree in Computer Science or a related discipline (or equivalent experience); advanced degree preferred.

10-12 years of information security or related technology experience.

Experience supporting enterprise cybersecurity platforms within large organizations; financial services experience is preferred.

Strong experience operating vulnerability management, asset discovery, scanning, cloud security posture management, or cloud-native security platforms.

Hands-on experience supporting production environments, incident management, change management, platform monitoring, and lifecycle management.

Strong engineering background with automation, APIs, configuration management, and operational optimization.

Deep understanding of vulnerability management processes, remediation tracking, SLA governance, ownership validation, and exception management.

Strong networking knowledge including TCP/IP, DNS, routing, firewalls, proxies, NAT, segmentation, packet flow analysis, and troubleshooting.

Experience scanning enterprise infrastructure including servers, endpoints, databases, network devices, appliances, containers, cloud assets, and internet-facing systems.

Knowledge of scanner architecture, authenticated scanning, credential management, agent health, and scan troubleshooting.

Experience with AWS, Azure, and GCP cloud environments including IAM, APIs, cloud connectors, and cloud security controls.

Experience integrating security platforms with CMDBs, ticketing systems, reporting platforms, enterprise dashboards, and cloud services.

Strong understanding of identity and access management including SSO, MFA, RBAC, privileged access, service accounts, and API security.

Programming experience with Python, Go, Java, or similar languages.

Experience troubleshooting distributed enterprise security platforms across networking, cloud, identity, APIs, and data pipelines.

Experience supporting audits, compliance reporting, production controls, and regulatory requirements.

Experience with Kubernetes, container security, image scanning, runtime visibility, registry integrations, and cloud-native asset inventory.

Preferred Qualifications

Experience with Qualys, Wiz, Lumeta, or comparable vulnerability management and cloud security platforms.

Experience supporting FedRAMP-authorized or FedRAMP-aligned cloud environments.

Knowledge of FedRAMP controls, continuous monitoring, vulnerability scanning, access governance, compliance reporting, and cloud security operations.

Desired Skills

Vulnerability Management

Cloud Security Posture Management (CSPM)

Cybersecurity Platform Engineering

Enterprise Security Operations

Qualys

Wiz

Lumeta

AWS

Azure

Google Cloud Platform (GCP)

Kubernetes

Container Security

Asset Discovery

Network Security

Infrastructure Security

TCP/IP

DNS

Firewalls

Routing

Network Segmentation

API Integration

Python

Go

Java

Automation

Infrastructure as Code

Configuration Management

CMDB Integration

ServiceNow

Identity and Access Management (IAM)

SSO

RBAC

MFA

Privileged Access Management

Incident Response

Change Management

Disaster Recovery

Business Continuity

Security Compliance

FedRAMP

Audit Support

Vulnerability Scanning

Cloud Connectors

Data Pipelines

DashboardingReporting

DevSecOps

Success Profile

Own and operate enterprise vulnerability management and cloud security platforms.

Improve platform reliability, scalability, and operational resilience.

Expand security visibility across enterprise infrastructure and cloud environments.

Enable effective vulnerability reporting, remediation tracking, and compliance.

Reduce manual effort through automation and standardized engineering practices.

Strengthen governance, access controls, platform stability, and production readiness.

Ampcus is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veterans or individuals with disabilities.

#J-18808-Ljbffr