Manager, Vulnerability Management and Application Security
Job Description
PSEG Long Island is seeking a senior security leader to guide the vulnerability management and application security programs. Based in Bethpage, NY with a hybrid work arrangement, this role collaborates with IT, Security, and business units to safeguard critical systems and applications from evolving cyber threats. The Manager will own the end-to-end lifecycle of cyber assessment and vulnerability management, oversee threat intelligence and red team activities, and drive security assessments to strengthen defenses across the organization.
Responsibilities
- Lead the full lifecycle of the Cyber Assessment & Vulnerability Management program, coordinating risk identification, remediation, and reporting.
- Inform, advise, and partner with IT, Security, and other business units to help better secure their operations.
- Identify gaps in current processes, workflows, and design and recommend changes or enhancements as needed.
- Participate in Change Management Process, from early assessment of proposed changes/enhancements, through vulnerability scanning and recommended remediation before go-live.
- Participate in incident response activities as needed.
- Ensure cross-company processes around threat & vulnerability management are adhered to.
- Track SLAs, discovery, and handling of any finding.
- Maintain situational awareness, identification, tracking, and ensuring action on industry news related to software vulnerabilities, including zero-day vulnerabilities and emergency patching.
- Implement and operationalize advanced Vulnerability Management reporting tools.
- Design, develop and operationalize Vulnerability Management metrics.
- Design and implement advanced Vulnerability dashboards.
- Evaluate performance, perform career development, coaching and counseling and manage compensation for Cyber assessment staff.
- Responsible for conducting security assessments & penetration tests.
- Review Cyber threat intelligence and provide relevant data to parties within the Cyber Assessment & Vulnerability Management teams to action upon.
- Oversee regular red team exercises to proactively emulate attackers TTP and report back findings so security engineering and operations can improve their defenses.
- Create, perform tabletop exercises mimicking adversary practices testing PSEG Long Island’s ability to respond to cyber incidents.
Requirements
- Bachelor's degree and 8 years of relevant cyber security experience; candidates without a degree require 12 years of cyber experience.
- Experience within vulnerability/compliance management, penetration testing, and/or threat hunting.
- Ability to present to all levels of management and executive leadership.
- Excellent teamwork, facilitation, relationship building, and negotiation skills.
- Able to maintain positive working relationships both leading and as part of a team.
- Effective time management skills and able to multi-task effectively.
- Able to communicate effectively with both technical and non-technical individuals.
- Compliance with the Department of Energy's regulation 10 CFR 810 is required.
- Certified Information Systems Security Professional (CISSP), or equivalent.
Benefits
- Medical, dental, and vision coverage.
- Paternal leave and family leave programs.
- Behavioral health programs.
- 401(k) with company match.
- Life insurance and tuition reimbursement.
- Generous paid time off.
Location and compensation
Location: Bethpage, NY with a Hybrid Flexible work arrangement. Salary range: $121,200 – $199,200 per year.