Senior Director, Vulnerability Management and Continuous Control Monitoring
Atlanta, GA 
Share
Posted 12 days ago
Job Description
The Senior Director of Vulnerability Management and Continuous Control Monitoring will lead a team of cybersecurity professionals that provide continuous internal and external vulnerability scanning and reporting, continuous configuration monitoring in both on-premise and multi-cloud environments as well as the design and maintenance of a platform that will continuously monitor and report on the state of Cox Automotive's critical cyber controls. The scope of this role is Cox Automotive wide and includes both enterprise and product technologies as well as both domestic and international business units. This leader will direct the global strategy and operational approach of vulnerability, including misconfigurations, identification and reporting across both on-premise and cloud-based infrastructure spanning both enterprise and product technology teams. Additionally, this leader will direct the strategy and day to day operations of the cybersecurity team's continuous control monitoring platform for measurement of ongoing compliance to Cox Automotive's critical cyber controls.

This role will directly report to the Chief Information Security Officer of Cox Automotive.

Primary Responsibilities:

Vulnerability, Configuration, and Attack Surface Management

  • Lead and mentor a team of cybersecurity professionals that:
  • Deliver continuous scanning, identification, and reporting of the external facing attack surface throughout on-premise and cloud-based environments across both enterprise and product technologies.
  • Provide continuous scanning, identification, and reporting of vulnerabilities throughout on-premise and cloud-based environments across both enterprise and product technologies.
  • Manage the operations and effectiveness of the configuration security posture management and compliance capabilities for multiple hyperscaler cloud environments (AWS, Azure, OCI, etc.).
  • Partner with the Security Architecture team to ensure that critical cybersecurity configurations are monitored through the cloud security posture management (CSPM) and Software as a Service security posture management (SSPM) capabilities.
  • Recommend, socialize, and gain consensus on minimum patching and vulnerability mitigation standards and policies across both enterprise and product technology teams.
  • When imminent threats or relevant zero-day vulnerabilities are identified, lead rapid vulnerability response efforts across the entire Cox Automotive Product and Technology Group.
  • Monitor vulnerability mitigation progress and partner with engineering teams to provide recommendations for efficient risk remediation or mitigation.
  • Provide regular reporting on the current state of vulnerabilities and configurations throughout the entire Cox Automotive environment including both on-premise and cloud environments globally.
  • Partner with M&A teams to ensure rapid deployment of vulnerability scanning and related visibility tools to acquisitions.


Continuous Control Monitoring

  • Define and execute the vision and strategy for our continuous control monitoring platform and data model that supports our overall critical cybersecurity objectives and priorities.
  • Lead and mentor a team of engineers who are responsible for developing, testing, and maintaining the continuous control monitoring platform and related data models that integrate data from various cybersecurity and technology sources to report on the current state of Cox Automotive's critical cyber controls.
  • Partner with cybersecurity and enterprise and product technology teams on the development of appropriate scoring algorithms and measurement criteria, including defining and setting policies where needed.
  • Collaborate with engineering and architecture leaders, other cybersecurity leaders, and broader Cox Automotive Product and Technology Group leaders to socialize security requirements for meta data or technical integrations necessary to provide relevant critical cyber control reporting to all layers of the organization.
  • Design and build consumable and audience appropriate reporting of the state of critical cyber controls for consumption by engineering teams, engineering team managers and directors, cybersecurity leaders, and senior technology and business leaders.


Common Responsibilities Across Both Focus Areas

  • Lead and coordinate large-scale information security projects, including implementation and delivery of infrastructure security scanning, correlating overall cybersecurity analytics and reporting, workflow and orchestration solutions, and log ingestion.
  • Identify, propose, and influence business solutions, negotiate deliverables and requirements across multiple business customers or organizations.
  • Partner with other functional groups to develop, manage, track, and analyze operational support structures, tools, methods and procedures to improve process efficacy, inter-team communications, and the customer experience.
  • Provide leadership and strategic direction for the function, including budgeting capital and operating expenses.
  • Oversee and lead contract negotiations and vendor management for vulnerability management, continuous control monitoring, and other security capabilities as appropriate.
  • Responsible for staying abreast of industry leading vulnerability and software security vendors and informing their product roadmaps.
  • Consult with senior leadership on security threats and incident response practices.
  • Working knowledge/experience of network systems, security principles, and applications. Fundamental understanding of defense-in-depth and intelligence-driven strategies.
  • Detailed knowledge of vulnerability management, configuration management, software security, red team concepts, tools and trends.
  • Develop a training program to ensure ongoing education vulnerability management and continuous control monitoring resources.


Minimum Qualifications:

  • Bachelor's degree in a related discipline and 12 years' experience in a related field. The right candidate could also have a different combination, such as a master's degree and 10 years' experience; a Ph.D. and 7 years' experience in a related field; or 16 years' experience in a related field
  • 10+ years of experience required in the field of information security with a demonstrated path of increasing scope and management responsibilities.
  • 5+ years managing or leading an Information Security vulnerability management function.
  • Ability to drive consensus and collaboration among many diverse teams, individuals and functional groups to achieve desired business results.
  • Excellent interpersonal, leadership, presentation, and collaborative skills to work effectively with teams throughout organization.
  • Demonstrated track record of both project and operational delivery.
  • Demonstrated knowledge and expertise in vulnerability assessment, risk management, and cybersecurity frameworks and standards (e.g., NIST, ISO, CIS, OWASP).
  • Strong knowledge of vulnerability scanning and analysis and attack surface management tools (e.g., Qualys, Nessus, Rapid7, Tenable, Veracode, Shodan, etc.)
  • At least one relevant industry certification - CISSP, SANS GIAC, C|EH, CISM, CRISC, CISA, CPA.


Preferred Qualifications:

  • Advanced degree (MBA / MS).
  • 5+ years of experience in a senior management role.
  • Cybersecurity experience in critical infrastructure industries (i.e. telecommunications, financial services, defense or government)


USD 189,100.00 - 315,100.00

Compensation:

Compensation includes a base salary of $189,100.00 - $315,100.00. The base salary may vary within the anticipated base pay range based on factors such as the ultimate location of the position and the selected candidate's knowledge, skills, and abilities. Position may be eligible for additional compensation that may include an incentive program.

Benefits:

The Company offers eligible employees the flexibility to take as much vacation with pay as they deem consistent with their duties, the company's needs, and its obligations; seven paid holidays throughout the calendar year; and up to 160 hours of paid wellness annually for their own wellness or that of family members. Employees are also eligible for additional paid time off in the form of bereavement leave, time off to vote, jury duty leave, volunteer time off, military leave, parental leave, and COVID-19 vaccination leave.

About Cox Automotive

At Cox Automotive, people of every background are driven by their passion for mobility, innovation and community. We transform the way the world buys, sells, owns and uses cars, accelerating the industry with global powerhouse brands like Autotrader, Kelley Blue Book, Manheim and more. What's more, we do it all with an emphasis on employee growth and happiness. Drive your future forward and join Cox Automotive today!

About Cox

Cox empowers employees to build a better future and has been doing so for over 120 years. With exciting investments and innovations across transportation, communications, cleantech and healthcare, our family of businesses - which includes Cox Automotive and Cox Communications - is forging a better future for us all. Ready to make your mark? Join us today!

Benefits of working at Cox may include health care insurance (medical, dental, vision), retirement planning (401(k)), and paid days off (sick leave, parental leave, flexible vacation/wellness days, and/or PTO). For more details on what benefits you may be offered, visit our benefits page .

Cox is an Equal Employment Opportunity employer - All qualified applicants/employees will receive consideration for employment without regard to that individual's age, race, color, religion or creed, national origin or ancestry, sex (including pregnancy), sexual orientation, gender, gender identity, physical or mental disability, veteran status, genetic information, ethnicity, citizenship, or any other characteristic protected by law. Cox provides reasonable accommodations when requested by a qualified applicant or employee with disability, unless such accommodations would cause an undue hardship.

Statement to ALL Third-Party Agencies and Similar Organizations: Cox accepts resumes only from agencies with which we formally engage their services. Please do not forward resumes to our applicant tracking system, Cox employees, Cox hiring manager, or send to any Cox facility. Cox is not responsible for any fees or charges associated with unsolicited resumes.

 

Job Summary
Company
Cox
Start Date
As soon as possible
Employment Term and Type
Regular, Full Time
Required Education
Bachelor's Degree
Required Experience
12+ years
Security Clearance Note
Engineering / Product Development
Email this Job to Yourself or a Friend
Indicates required fields