Senior Principal, Vulnerability Management
Any city, TX, US, 99999
Be part of a team that unleashes the power of leading-edge technologies to help improve the health and well-being of those most vulnerable in our country and communities. Working at Gainwell carries its rewards. You’ll have an incredible opportunity to grow your career in a company that values work flexibility, learning, and career development. You’ll add to your technical credentials and certifications while enjoying a generous, flexible vacation policy and educational assistance. We also have comprehensive leadership and technical development academies to help build your skills and capabilities.
Summary
The Senior Principal, Vulnerability Management is the enterprise owner for all vulnerability management strategy, tooling, and execution across Gainwell’s environments and client-facing platforms. This role provides deep technical leadership and program governance to ensure vulnerabilities are identified, prioritized, and remediated in a risk-based, measurable, and repeatable manner.
The Senior Principal will design and lead a mature vulnerability management program leveraging Tenable, Tanium, ServiceNow Vulnerability Response, and integrated security tooling to reduce cyber risk at scale.
Your role in our mission
- Own the end-to-end enterprise Vulnerability Management (VM) program, including strategy, roadmap, operating model, and metrics.
- Define and maintain a risk-based vulnerability management framework aligned to NIST CSF, CIS Controls, and industry best practices.
- Establish and maintain policies, standards, and procedures for vulnerability identification, assessment, prioritization, remediation, and exception handling.
- Develop multi-year maturity plans for VM capabilities across server, endpoint, network, application, cloud, and third-party domains.
- Serve as product owner and technical authority for the Tenable platform (Tenable.sc, Tenable.io, Tenable One) across the enterprise.
- Design and maintain Tenable architecture.
- Lead design and operation of scanning strategies across Tenable.sc, Tenable.io, and Tenable One, including asset tagging, scoping, credential management, and scan frequency.
- Oversee the full lifecycle from detection → triage → assignment → remediation → validation, ensuring timely closure of high and critical vulnerabilities.
- Operationalize risk-based prioritization using Tenable risk scores (e.g., VPR/CES) combined with business impact, exploitability, and threat intelligence.
- Partner with infrastructure, application, and cloud teams to align remediation timelines with SLAs and change management processes.
- Ensure vulnerability and configuration coverage across: Network devices (e.g., Palo Alto firewalls, Panorama, F5, Citrix/NetScaler, Riverbed), Endpoints and servers (via Tanium and SCCM), Virtualized and remote access environments (Citrix, NS).
- Integrate threat intelligence and MITRE ATT&CK mappings into vulnerability prioritization and reporting.
- Correlate vulnerabilities with active exploitation trends, threat actor TTPs, and sector-specific threats (especially healthcare/public sector).
- Inform executive and technical stakeholders on emerging vulnerabilities (e.g., zero-days, high-profile CVEs) and coordinate rapid response efforts.
- Define and track key VM metrics and KPIs (e.g., mean time to remediate by severity, SLA adherence, exception volumes, exposure trends, coverage levels).
- Produce executive-ready dashboards and reports for senior leadership, auditors, and clients.
- Support internal and external audits, regulatory assessments, and customer security due diligence as the authoritative owner of VM processes and data.
- Chair or participate in governance forums to drive accountability for remediation across infrastructure, application, and product teams.
- Provide senior technical and leadership guidance to vulnerability analysts, security engineers, and partner IT teams.
- Mentor junior leaders and technical staff on VM best practices, risk-based thinking, and program management.
What we're looking for
- 17+ years of progressive IT experience, with strong grounding in infrastructure, networking, and enterprise operations.
- 3+ years of leadership experience in complex, mission-critical environments (healthcare, public sector, and/or military strongly preferred).
- 4–7+ years of hands-on cybersecurity experience, with significant time spent building, leading, or owning vulnerability management programs.
- Proven experience designing and operating enterprise VM at scale using: Tenable.sc / Tenable.io / Tenable One (5+ years strongly preferred).
- Preferred Completion of SANS MGT516 / SANS 516 – Building and Leading Vulnerability Management Programs or equivalent leadership training in vulnerability management.
- Professional security certifications such as CISSP, GIAC (e.g., GCLD, GMON, GVAC), or equivalent are preferred.
What you should expect in this role
- This opportunity is 100% remote within the Unites States with the opportunity to travel for work up to 15% annually.
This posting is intended for pipelining. We will accept applications on an ongoing basis.
The pay range for this position is $145,000 - $203,000 per year, however, the base pay offered may vary depending on geographic region, internal equity, job-related knowledge, skills, and experience among other factors. Put your passion to work at Gainwell. You’ll have the opportunity to grow your career in a company that values work flexibility, learning, and career development. All salaried, full-time candidates are eligible for our generous, flexible vacation policy, a 401(k) employer match, comprehensive health benefits, and educational assistance. We also have a variety of leadership and technical development academies to help build your skills and capabilities.
We believe nothing is impossible when you bring together people who care deeply about making healthcare work better for everyone. Build your career with Gainwell, an industry leader. You’ll be joining a company where collaboration, innovation, and inclusion fuel our growth. Learn more about Gainwell at our company website and visit our Careers site for all available job role openings.
Gainwell Technologies is an Equal Opportunity Employer, where all qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical condition), age, sexual orientation, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. Gainwell Technologies defines “wages” and “wage rates” to include “all forms of pay, including, but not limited to, salary, overtime pay, bonuses, stock, stock options, profit sharing and bonus plans, life insurance, vacation and holiday pay, cleaning or gasoline allowances, hotel accommodations, reimbursement for travel expenses, and benefits.