Senior Principal, Vulnerability Management

Business AnalystBusiness AnalystFull TimeRemoteLeadTeam 10,001+H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

52 days ago

Salary

$145K - $203K / year

Seniority

Lead

No structured requirement data.

Job Description

Senior Principal, Vulnerability Management

Gainwell Technologies

Be part of a team that unleashes the power of leading-edge technologies to help improve the health and well-being of those most vulnerable in our country and communities. Working at Gainwell carries its rewards. You’ll have an incredible opportunity to grow your career in a company that values work flexibility, learning, and career development. You’ll add to your technical credentials and certifications while enjoying a generous, flexible vacation policy and educational assistance. We also have comprehensive leadership and technical development academies to help build your skills and capabilities. Summary The Senior Principal, Vulnerability Management is the enterprise owner for all vulnerability management strategy, tooling, and execution across Gainwell’s environments and client-facing platforms. This role provides deep technical leadership and program governance to ensure vulnerabilities are identified, prioritized, and remediated in a risk-based, measurable, and repeatable manner. The Senior Principal will design and lead a mature vulnerability management program leveraging Tenable, Tanium, ServiceNow Vulnerability Response, and integrated security tooling to reduce cyber risk at scale. Your role in our mission - Own the end-to-end enterprise Vulnerability Management (VM) program, including strategy, roadmap, operating model, and metrics. - Define and maintain a risk-based vulnerability management framework aligned to NIST CSF, CIS Controls, and industry best practices. - Establish and maintain policies, standards, and procedures for vulnerability identification, assessment, prioritization, remediation, and exception handling. - Develop multi-year maturity plans for VM capabilities across server, endpoint, network, application, cloud, and third-party domains. - Serve as product owner and technical authority for the Tenable platform (Tenable.sc, Tenable.io, Tenable One) across the enterprise. - Design and maintain Tenable architecture. - Lead design and operation of scanning strategies across Tenable.sc, Tenable.io, and Tenable One, including asset tagging, scoping, credential management, and scan frequency. - Oversee the full lifecycle from detection → triage → assignment → remediation → validation, ensuring timely closure of high and critical vulnerabilities. - Operationalize risk-based prioritization using Tenable risk scores (e.g., VPR/CES) combined with business impact, exploitability, and threat intelligence. - Partner with infrastructure, application, and cloud teams to align remediation timelines with SLAs and change management processes. - Ensure vulnerability and configuration coverage across: Network devices (e.g., Palo Alto firewalls, Panorama, F5, Citrix/NetScaler, Riverbed), Endpoints and servers (via Tanium and SCCM), Virtualized and remote access environments (Citrix, NS). - Integrate threat intelligence and MITRE ATT&CK mappings into vulnerability prioritization and reporting. - Correlate vulnerabilities with active exploitation trends, threat actor TTPs, and sector-specific threats (especially healthcare/public sector). - Inform executive and technical stakeholders on emerging vulnerabilities (e.g., zero-days, high-profile CVEs) and coordinate rapid response efforts. - Define and track key VM metrics and KPIs (e.g., mean time to remediate by severity, SLA adherence, exception volumes, exposure trends, coverage levels). - Produce executive-ready dashboards and reports for senior leadership, auditors, and clients. - Support internal and external audits, regulatory assessments, and customer security due diligence as the authoritative owner of VM processes and data. - Chair or participate in governance forums to drive accountability for remediation across infrastructure, application, and product teams. - Provide senior technical and leadership guidance to vulnerability analysts, security engineers, and partner IT teams. - Mentor junior leaders and technical staff on VM best practices, risk-based thinking, and program management. What we're looking for - 17+ years of progressive IT experience, with strong grounding in infrastructure, networking, and enterprise operations. - 3+ years of leadership experience in complex, mission-critical environments (healthcare, public sector, and/or military strongly preferred). - 4–7+ years of hands-on cybersecurity experience, with significant time spent building, leading, or owning vulnerability management programs. - Proven experience designing and operating enterprise VM at scale using: Tenable.sc / Tenable.io / Tenable One (5+ years strongly preferred). - Preferred Completion of SANS MGT516 / SANS 516 – Building and Leading Vulnerability Management Programs or equivalent leadership training in vulnerability management. - Professional security certifications such as CISSP, GIAC (e.g., GCLD, GMON, GVAC), or equivalent are preferred. What you should expect in this role - This opportunity is 100% remote within the Unites States with the opportunity to travel for work up to 15% annually. This posting is intended for pipelining. We will accept applications on an ongoing basis. The pay range for this position is $145,000 - $203,000 per year, however, the base pay offered may vary depending on geographic region, internal equity, job-related knowledge, skills, and experience among other factors. Put your passion to work at Gainwell. You’ll have the opportunity to grow your career in a company that values work flexibility, learning, and career development. All salaried, full-time candidates are eligible for our generous, flexible vacation policy, a 401(k) employer match, comprehensive health benefits, and educational assistance. We also have a variety of leadership and technical development academies to help build your skills and capabilities. We believe nothing is impossible when you bring together people who care deeply about making healthcare work better for everyone. Build your career with Gainwell, an industry leader. You’ll be joining a company where collaboration, innovation, and inclusion fuel our growth. Learn more about Gainwell at our company website and visit our Careers site for all available job role openings. Gainwell Technologies is an Equal Opportunity Employer, where all qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical condition), age, sexual orientation, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. Gainwell Technologies defines “wages” and “wage rates” to include “all forms of pay, including, but not limited to, salary, overtime pay, bonuses, stock, stock options, profit sharing and bonus plans, life insurance, vacation and holiday pay, cleaning or gasoline allowances, hotel accommodations, reimbursement for travel expenses, and benefits.

Related Categories

Related Job Pages

More Business Analyst Jobs

Majesco logo

Senior Lead Business Analyst

Majesco

Majesco is a leading insurance solutions and services provider. Software for core insurance functions include Policy Administration, Underwriting, New Business Processing, Billing, Claims, Product Modeling, Incentive Compensation, and Producer Life cycle Management. Offers consulting and insurance-specific IT services for testing, data conversion, data-warehousing/BI, mobility, enterprise integration, and BPM. Specializes in connecting people and business to insurance in innovative, hyper-relevant, compelling, and personal ways. Helps insurers modernize, innovate and connect to build the future of their business and the industry at speed and at scale.

Business Analyst52 days ago
Full TimeRemoteTeam 1,001-5,000

Majesco isn’t just riding the AI wave – we’re leading it for the P&C and L&AH insurance industry. Born in the cloud and built with an AI-native vision, we’ve reimagined the insurance core as a platform that lets insurers move faster, see farther, and operate smarter. As leaders in intelligent SaaS solutions, we’ve embedded AI and Agentic AI throughout our robust product portfolio of core, underwriting, loss control, distribution, and digital solutions so our customers can reimagine their business with real-time business insights, optimized operations, and enhanced business outcomes. Everything we build is designed to strip away complexity and let our clients focus on what matters: delivering exceptional products, experiences, and outcomes. In a world where change is constant, our native-cloud SaaS platform empowers insurers the agility to adapt to market and risk shifts quickly, reshape their operational cost structure, accelerate innovation readiness, and rethink how insurance can be done with the intelligence to stay ahead. With 1000+ implementations, we are the AI insurance leader that over 350 insurers, reinsurers, MGAs rely on to rethink how insurance can be done in today’s modern era of insurance. Break free from the past and build the future of insurance. Job Overview Majesco is seeking a Senior Business Analyst – Property & Casualty (P&C) Policy to help shape the future of our insurance software solutions. You’ll play a pivotal role in translating complex ISO and NCCI bureau circulars, regulatory updates, and business needs into actionable system requirements that drive compliance and innovation across commercial and personal lines. As part of a global team modernizing insurance technology, you’ll act as the vital connector between business stakeholders, compliance experts, and technical teams—ensuring that every policy and rating update is delivered with precision, efficiency, and regulatory accuracy. This role offers the opportunity to work on industry-leading P&C platforms, directly influencing how insurers streamline operations, manage risk, and deliver better experiences to their customers. All About the Role - Conduct in-depth analysis of ISO/NCCI circulars to evaluate coverage, rating methodologies, regulatory rules, and form requirements across multiple jurisdictions. - Gather and validate business and regulatory requirements, ensuring all implications are fully documented prior to handoff to development. - Partner closely with compliance, actuarial, underwriting, and IT teams to maintain alignment between regulatory changes and system functionality. - Develop and maintain traceability matrices that map circular provisions to business and system features. - Create detailed user stories, functional specifications, and process diagrams to guide design and development. - Support Agile ceremonies including sprint planning, backlog refinement, and retrospectives, ensuring priorities reflect both customer needs and compliance timelines. - Analyze existing policy administration workflows, recommend process improvements, and contribute to testing and validation of policy changes. - Facilitate cross-functional meetings and workshops to communicate circular impacts and ensure shared understanding across departments. - Provide informed recommendations to developers and product teams, helping shape solutions that meet business objectives while advancing Majesco’s commitment to modernization and customer success. - Manage change requests and ensure delivery milestones are met with transparency and accountability. All About You - Bachelor’s degree in Business, Insurance, Information Systems, or a related field. - 3–5 years of experience in Property & Casualty insurance, ideally in a business analyst or policy systems capacity. - Proven ability to interpret ISO and NCCI circulars and apply regulatory frameworks to policy administration systems. - Hands-on experience with policy administration platforms and rating engines within the insurance domain. - Proficient with JIRA, SharePoint, Excel, and SQL for documentation, analysis, and collaboration. - Exceptional analytical and communication skills—able to distill complex information into clear, actionable insights for diverse technical and non-technical teams. - Strong sense of ownership and collaboration, with a track record of driving compliance-focused solutions that enhance operational performance and customer outcomes. As a member of a rapidly growing and dynamic organization, the successful candidate must be flexible and willing to take on new tasks and responsibilities as business needs evolve. The company reserves the right to vary, change, or update job duties and responsibilities based on business requirements. This role may require shifting priorities, learning new technologies, and contributing to projects outside of the initial scope. What Majesco Offers: Majesco is committed to equal pay and transparency. The annual base salary range for this position is $110 to $125,000. Please note that the salary range information provided is a general guideline and combines all of the distinct labor markets within the US. It is uncommon for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on a variety of factors. Majesco considers factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience, candidate's work location, education/training, key skills, internal peer equity, external market data, as well as market and business considerations when making compensation decisions. Majesco is a leading insurance solutions and services provider. Majesco's software for core insurance functions include Policy Administration, Underwriting, New Business Processing, Billing, Claims, Product Modeling, Incentive Compensation and Producer Life cycle Management. Additionally, Majesco offers consulting and insurance specific IT services for testing, data conversion, data-warehousing/BI, mobility, enterprise integration and BPM. Majesco specializes in connecting people and business to insurance in ways that are innovative, hyper-relevant, compelling and personal. Our technology, expertise and leadership helps insurers modernize, innovate and connect to build the future of their business – and the industry – at speed and at scale. Majesco is an inclusive equal opportunity employer and complies with federal, state and local laws regarding equal employment opportunity. Qualified applicants are considered without regard to race, color, national origin, religious beliefs, sex (including pregnancy), age, disability, sexual orientation, gender identity or expression, citizenship status, military status, genetic information, or any other basis protected by federal, state and/or local employment laws. If you require accommodations or assistance to complete the online application process, please contact reasonableaccommodation@majesco.com and identify the type of accommodation or assistance you are requesting and your contact information. Do not include any medical or health information in this email. This email alias is not for the general submission of application materials and any application materials submitted through this alias will not be considered. In addition, Majesco will not provide a response to inquiries made to reasonableaccommodation@majesco.com that are not related to accessibility of the online application system by persons with disabilities.

United States
$110 - $125K / year

Req ID: 362032 NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. We are currently seeking a Project Manager / BA - Endpoint Modernization to join our team in Salem, Oregon (US-OR), United States (US). The Project Manager / BA provides end‑to‑end project management services for an enterprise technology deployment, overseeing planning, execution, governance, and closure. This role is responsible for establishing and maintaining project governance, coordinating cross‑functional technical and business teams, managing rollout planning and change management activities, and ensuring operational readiness and post‑deployment validation. The Project Manager / BA proactively manages risks, issues, and decisions, while ensuring deliverables meet business requirements and established governance standards. The position also ensures the project is completed with documented handoff and formal closure. This position supports plan development, progress reporting, mentoring, and other related services at the direction of the NTT DATA Delivery Director. Job Responsibilities Include: • Establish and maintain project governance cadence, including status reporting, steering committee updates, and decision governance. • Ensure all project deliverables comply with project governance standards. • Drive stakeholder alignment and manage cross‑functional dependencies across IT, security, identity, endpoint, support, and business teams. • Develop current‑state assessments, future‑state design, and gap analyses for endpoints, identity, security, applications, and support processes. • Develop documentation of functional and non‑functional requirements and the agreed solution approach in collaboration with business and technical owners. • Develop, maintain, and socialize a comprehensive Project Management Plan, including sub-plans. • Create and manage the integrated project schedule. • Initiate corrective actions to stay on schedule. • Manage scope, resources, budget, and quality controls. • Coordinate execution across internal teams and external vendors, proactively identifying and managing constraints and risks. • Build and manage deployment rollout wave planning and provide execution oversight throughout project lifecycle. • Coordinate communications, readiness checkpoints, training logistics, and user adoption activities. • Ensure post‑deployment validation activities and operational handoffs are completed, documented, and approved. • Create and maintain project risk, issue, and decision logs, ensuring timely escalation and resolution. • Develop and present weekly and monthly executive status reports. • Ensure work is completed on time and of high quality. Basic Qualifications: • A minimum of eight (8) years’ experience, including endpoint or device deployment initiatives. • A minimum of six (6) years of project management experience with medium-to-large-sized information technology projects. • A minimum of three (3) years of experience in business analysis. • Bachelor’s degree, or equivalent work experience. Preferred Skills: • PMI Project Management Professional (PMP) certification. • A minimum of three (3) years of project management experience working in government. • A minimum of five (5) years of experience working as a consultant in a client-facing role. • Certified Business Analysis Professional (CBAP) credential. Where required by law, NTT DATA provides a reasonable range of compensation for specific roles. The starting pay range for this remote role is $79,920- $145,000. This range reflects the minimum and maximum target compensation for the position across all US locations. Actual compensation will depend on a number of factors, including the candidate’s actual work location, relevant experience, technical skills, and other qualifications. This position may also be eligible for incentive compensation based on individual and/or company performance. This position is eligible for company benefits including medical, dental, and vision insurance with an employer contribution, flexible spending or health savings account, life and AD&D insurance, short and long term disability coverage, paid time off, employee assistance, participation in a 401k program with company match, and additional voluntary or legally-required benefits. About NTT DATA NTT DATA is a $30 billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world's leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services. our consulting and Industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 50 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is a part of NTT Group, which invests over $3 billion each year in R&D. Whenever possible, we hire locally to NTT DATA offices or client sites. This ensures we can provide timely and effective support tailored to each client’s needs. While many positions offer remote or hybrid work options, these arrangements are subject to change based on client requirements. For employees near an NTT DATA office or client site, in-office attendance may be required for meetings or events, depending on business needs. At NTT DATA, we are committed to staying flexible and meeting the evolving needs of both our clients and employees. NTT DATA recruiters will never ask for payment or banking information and will only use @nttdata.com and @talent.nttdataservices.com email addresses. If you are requested to provide payment or disclose banking information, please submit a contact us form, https://us.nttdata.com/en/contact-us. NTT DATA endeavors to make https://us.nttdata.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact us at https://us.nttdata.com/en/contact-us. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications. NTT DATA is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. For our EEO Policy Statement, please click here. If you'd like more information on your EEO rights under the law, please click here. For Pay Transparency information, please click here.

United States
$79.9K - $145K / year
Job Closed
General Dynamics logo

Business Analyst

General Dynamics

General Dynamics is a global aerospace and defense company offering products designed to provide safety and security to people around the world. In the past, Ge

Business Analyst52 days ago

• Provide expertise in business process and system analysis and design • Collaborate with stakeholders and product teams to decompose large epics into features and user stories • Envision, develop, and create requirements to improve tools to streamline processes • Meeting with product design team to determine testing parameters • Work with teams to bring continuous improvement to DevSecOps processes and tools • Engineering and implementing solutions and providing recommendations for continuous improvement • Creating and executing test plans, test cases, and test scripts for accessibility validation • Managing test data architecture definition • Providing validation testing of different system and data sets for cloud migrations • Testing and examining code written by others and analyzing results • Troubleshooting errors and streamlining the test procedures • Use JIRA as agile lifecycle tool, along with SalesForce functional and administrative features. • Automating and improving development, testing, deployment, and release processes • Documenting as-is state of the environment, performing a gap analysis, and producing artifacts that articulate options and recommendations.

United States
$93.7K - $112.7K / year
Job Closed
CVS Health logo

Senior Analyst, Business Compliance

CVS Health

Bringing our heart to every moment of your health.

Business Analyst52 days ago
Full TimeRemoteTeam 10,001+Since 1963H1B No Sponsor

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time. Position Summary - Develops and implements complex monitoring systems and procedures to assess compliance with legal and regulatory requirements. - Conducts routine audits, reviews, and assessments of various business activities and processes. - Analyzes internal controls, policies, and procedures to identify weaknesses and recommend improvements. - Develops and implements, under general supervision, compliance policies and procedures, and ensures they align with relevant laws and regulations. - Configures compliance reports and documentation, highlighting findings, recommendations, and areas of concern. - Examines procedures and reporting to ensure efficiency and appropriate risk mitigation. - Communicates with legal and regulatory teams to ensure accurate and timely reporting to external authorities. - Administers investigations into potential compliance violations or breaches. Gathers evidence, conducts interviews, and prepares reports on the findings. - Liaises with regulatory bodies, auditors, and legal professionals to address compliance-related matters. Required Qualifications - 2+ years of prior relevant work experience. - Working knowledge of problem-solving and decision-making skills. Preferred Qualifications - Experience working with Third Party Administrators and/or self-funded health plans Education - Bachelor's degree preferred/specialized training/relevant professional qualification or High school diploma and 5+ years equivalent experience. Anticipated Weekly Hours 40 Time Type Full time Pay Range The typical pay range for this role is: $46,988.00 - $122,400.00 This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong. Great benefits for great people We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families. This full‑time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well‑being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility. Additional details about available benefits are provided during the application process and on Benefits Moments. We anticipate the application window for this opening will close on: 04/17/2026 Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.

United States + 1 moreAll locations: United States | United Kingdom
$47.0K - $122K / year