Urgently hiring Use left and right arrow keys to navigate
Provided by the employer
Verified Pay check_circle $140000 - $180000 per year
Hours Full-time
Location Houston, TX
Houston, Texas open_in_new

About this job

Job Description

Job Description

AXG is partnered with an independent power generation company is seeking a Cybersecurity Vulnerability Management Lead to own its vulnerability and patch management program across corporate IT and power generation OT environments. This is a hands-on role for someone who can turn findings into completed remediation while protecting the safety and availability of operating plants.


Reporting to the Cybersecurity Manager, you will work with infrastructure, network, cloud, application, security, and OT/SCADA teams. The position may be based in either Houston or the New York Metropolitan Area and involves collaboration with generating sites.


Responsibilities:


  • Own the vulnerability lifecycle: assess and validate findings, prioritize them by exploitability and asset criticality, assign accountable owners, track remediation, verify fixes, and manage documented exceptions.
  • Lead risk-based patch planning and execution across Windows, Linux, virtual, cloud, network, and approved industrial systems. Coordinate testing, maintenance windows, change approvals, rollback plans, and post-deployment validation.
  • Partner with plant operations, engineering, OT/SCADA specialists, and vendors to address vulnerabilities in control systems and supporting infrastructure. Develop compensating controls where patching is unsafe, unavailable, or must wait for an outage.
  • Establish remediation targets and escalation paths; maintain accurate asset and ownership data; and report aging, compliance, exceptions, and residual risk to technical and business leaders.
  • Monitor security advisories and active exploitation, coordinate urgent action when needed, and automate discovery, ticketing, validation, and reporting workflows.
  • Support audit evidence and applicable critical infrastructure and NERC CIP requirements.


Requirements:


  • 5-10+ years in vulnerability management, patch management, cybersecurity engineering, systems engineering, infrastructure security, or a related field, with demonstrated ownership of remediation through closure.
  • Hands-on experience with Windows and Linux in a complex enterprise environment and experience coordinating fixes across multiple technical teams.
  • Experience with vulnerability assessment tools such as Qualys, Tenable, Rapid7, Tanium, Microsoft Defender Vulnerability Management, or comparable platforms, plus enterprise patch management tools.
  • Sound judgment about risk, change control, maintenance windows, exceptions, and operational impact; clear communication with technical teams and leadership.
  • A bachelor’s degree in cybersecurity, IT, computer science, engineering, or a related field, or equivalent relevant experience.


Strongly preferred: Experience with OT, ICS, or SCADA in power generation, utilities, energy, manufacturing, or another critical infrastructure setting. Familiarity with industrial security tools, NERC CIP, and scripting or automation with PowerShell, Python, Bash, or APIs is valuable.


If you have led vulnerability remediation across complex environments and can work effectively with both enterprise IT and plant teams, we would welcome a conversation.


Nearby locations

Posting ID: 1300183211 Posted: 2026-10-04 Job Title: Cybersecurity Vulnerability Management Lead