Vulnerability Management Lead
TheDriveGroupListed 1 Oct 2026
Vulnerability Management Lead Sydney | Hybrid | Permanent
- Own and mature an enterprise Vulnerability Management capability
- Qualys, Microsoft Defender, Horizon3.ai & watchTowr
- Highly regulated environment with significant security investment
About the role We’re looking for a Vulnerability Management Lead to take ownership of vulnerability identification, prioritisation and remediation across a complex enterprise environment.
This is a hands-on technical leadership role for someone who understands vulnerability management beyond simply running scans and producing reports.
You’ll work across infrastructure, cloud, applications and external attack surfaces, using platforms including Qualys, Microsoft Defender, Horizon3.ai and watchTowr to identify genuine exposure and help technical teams understand what needs fixing first and why.
Operating within a highly regulated environment, you’ll work closely with Cyber Security, Infrastructure, Cloud and Application teams to mature vulnerability management and reduce risk across the organisation.
What you’ll do
- Lead the organisation’s Vulnerability Management capability across infrastructure, cloud and applications.
- Own and optimise vulnerability tooling including Qualys, Microsoft Defender, Horizon3.ai and watchTowr.
- Manage vulnerability scanning, validation, prioritisation and remediation.
- Move beyond CVSS scores to prioritise vulnerabilities based on exploitability, exposure, asset criticality and business risk.
- Use attack surface and exposure management capabilities to identify vulnerabilities that present genuine attack paths.
- Work closely with Infrastructure, Cloud, Network, Application and Security teams to drive remediation.
- Track vulnerabilities through to closure and challenge remediation teams where required.
- Identify systemic issues and help engineering teams address root causes rather than repeatedly fixing individual vulnerabilities.
- Improve dashboards, reporting, metrics and executive visibility of vulnerability risk.
- Support vulnerability management requirements across audits, security frameworks and regulatory obligations.
- Continually improve vulnerability management processes, tooling and automation.
What you’ll bring
- Strong experience across Vulnerability Management, Exposure Management or Attack Surface Management.
- Hands-on experience with Qualys.
- Strong experience with Microsoft Defender and the wider Microsoft security ecosystem.
- Exposure to Horizon3.ai for autonomous penetration testing / attack path validation.
- Exposure to watchTowr or similar external attack surface management technology.
- Strong understanding of vulnerability scanning, validation, prioritisation and remediation.
- Ability to interpret technical findings and determine real-world risk and exploitability.
- Experience driving remediation across Infrastructure, Cloud, Network and Application teams.
- Strong stakeholder management skills with the confidence to challenge technical teams and influence priorities.
- Experience working within a highly regulated enterprise environment.
Experience within Financial Services, Banking, Insurance, Superannuation, or another highly regulated industry would be particularly relevant.
Why join?
This is an opportunity to take genuine ownership of Vulnerability Management rather than simply administer a scanning platform.
You’ll have access to a modern security stack spanning Qualys, Defender, Horizon3.ai and watchTowr, giving you the ability to combine traditional vulnerability management with continuous exposure management, attack surface visibility and real-world validation.
You’ll have the remit to improve how vulnerabilities are identified, prioritised and remediated across a large enterprise while influencing teams across Cyber, Infrastructure, Cloud and Applications.
If you have any questions about this role or others we have available, you can email Hayley directly via ***************************.
For the latest jobs, tech news or to introduce a friend for a $1,000 referral fee, follow us on LinkedIn:
TheDriveGroup on LinkedIn
TheDriveGroup is 100% committed to improving meaningful diversity in the technology industry.
We partner with clients who embrace diversity and seek candidates across all backgrounds, abilities, genders, sexualities, cultures and faiths.
Reference number: ******
Profession:Cyber SecurityCyber Security
Company: TheDriveGroup
Date posted: 2nd Oct, 2026