Join us to harden our defenses and keep CFA Institute a step ahead of evolving threats. As Manager, Cyber Hygiene, you'll lead enterprise-scale vulnerability and patch management across hybrid environments, design automation that speeds remediation, and embed secure-by-default practices in our engineering and operations. This is a hands-on, impact-focused role where you'll reduce risk at scale and measurably improve our security posture.
Please note: CFA Institute does not provide work authorization or visa sponsorship for this position (including temporary worker or student).
What You'll DoLead vulnerability & patch management across infrastructure, applications, and cloud services--own scanning, prioritization, and closure at scale.
Build automation and tooling (e.g., scripting and orchestration) to streamline patch deployment, configuration management, and remediation workflows.
Be the technical authority on cyber hygiene--guide SRE, engineering, and operations on secure configuration and remediation strategies.
Prioritize by risk--correlate findings with threat intelligence to focus on the highest-impact exposures.
Ensure cloud & infrastructure hygiene and compliance across on-prem and AWS/Azure/GCP environments.
Continuously improve tools, processes, and standards; evaluate new technologies to drive efficiency and maturity.
Measure what matters--create dashboards/reports that track closure rates, posture trends, and conformance to industry standards.
Prevent incidents proactively by reducing attack surface and closing gaps before they can be exploited.
What You'll Bring
Minimum QualificationsBachelor's degree in Computer Science, Information Security, or related field; or equivalent technical experience.
5-7 years in cybersecurity, SRE, or IT operations with significant hands-on vulnerability remediation experience.
Advanced expertise with vulnerability scanning platforms (e.g., Tenable, Qualys, Rapid7).
Deep knowledge of patch management, OS hardening, and CIS-aligned secure configuration.
Strong scripting/programming (Python, PowerShell, Bash) for remediation and reporting automation.
Familiarity with IaC and configuration management (Ansible, Puppet, Chef, Terraform).
Solid grounding in networking, operating systems, and enterprise IT architecture.
Demonstrated collaboration with engineers/developers/operations to embed hygiene practices; strong analytical and communication skills.
Preferred QualificationsExperience with cloud-native security controls (e.g., AWS Inspector, Azure Security Center, GCP Security Command Center).
Technical certifications such as OSCP, GCFA, GPEN, or other GIAC credentials.
Cloud security certifications (e.g., AWS Security Specialty, Azure Security Engineer).
Why Join Us?
At CFA Institute, you'll shape security outcomes that protect a global mission-driven organization. You'll collaborate with talented colleagues across SRE, engineering, and IT, have autonomy to implement automation and best practices, and see your work reflected in meaningful, measurable risk reduction. We offer a supportive culture grounded in accountability, authenticity, courage, agility, strategic thinking, growth mindset, and talent development.At CFA Institute, we are committed to transparency and equity in our hiring process. In compliance with wage transparency laws in many of the jurisdictions in which we recruit, we provide the following information regarding compensation for this position:
MNCJobz.com will not be responsible for any payment made to a third-party. All Terms of Use are applicable.