Live opening · Posted 4 days ago

Senior Restricted Secure / High Secure Exposure Management Lead

NXP Semiconductors · Bucharest
Workday
You are 4 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 4 days ago
CompanyNXP Semiconductors
LocationBucharest
SourceWorkday
Listed4 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
0 min from Workday publishing this role to us finding it
14 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
16,632 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

Job Title: Senior Restricted Secure / High Secure Exposure Management Lead
Location: Bucharest Romania
Job Position: Senior Restricted Secure / High Secure Exposure Management Lead
Role Summary
The Senior Restricted Secure / High Secure Exposure Management Lead serves as the senior technical and operational lead for exposure management across Restricted Secure and High Secure (RS/HS) environments. The role is responsible for ensuring vulnerabilities, misconfigurations, exposed services, unsupported technologies, and attack-path risks are continuously identified, validated, prioritized, and driven through remediation in accordance with the heightened protection requirements of RS/HS environments.
This is a hands-on technical leadership role requiring deep expertise in vulnerability and exposure management, scanning platforms, risk-based prioritization, remediation governance, and secure-environment operations. The role coordinates with system owners, infrastructure engineering, application teams, cloud and platform teams, Security Operations, Threat Intelligence, Incident Response, and governance stakeholders to reduce exploitable exposure while maintaining availability, integrity, segmentation, and change-control requirements.
Success in this role requires sound technical judgment, disciplined handling of sensitive exposure data, strong program execution, and the ability to translate complex findings into clear remediation priorities and measurable risk reduction for technical and leadership audiences.
Job ResponsibilityRS/HS Exposure Management Leadership
Lead the day-to-day technical and operational execution of exposure management for Restricted Secure and High Secure environments.
Establish a consistent operating model for identifying, validating, prioritizing, assigning, tracking, and closing security exposures across RS/HS assets.
Maintain an authoritative view of vulnerabilities, misconfigurations, exposed services, unsupported technologies, and attack-path risks affecting RS/HS environments.
Ensure exposure-management activities align with applicable security architecture, segmentation, access-control, data-handling, and change-management requirements.
Define and continuously improve exposure-reduction processes, technical standards, control objectives, and operating procedures.
Vulnerability Detection & Platform Operations
Operate and maintain enterprise vulnerability detection capabilities supporting RS/HS infrastructure, endpoints, applications, network devices, and approved cloud or container platforms.
Maintain scanner configuration, credentialed assessment coverage, agent deployment, scan scheduling, policy alignment, and platform health.
Use platforms including Rapid7 InsightVM, Rapid7 InsightAppSec, and CrowdStrike Falcon Spotlight / Exposure Management where approved for the target environment.
Validate findings, investigate false positives, reconcile duplicate records, and ensure accurate association between findings, assets, owners, and business services.
Identify assessment blind spots and coordinate approved methods to improve coverage without introducing unacceptable operational or confidentiality risk.
Maintain visibility into RS/HS attack surfaces, trust boundaries, privileged pathways, remote access points, security appliances, and externally reachable components.
Identify exposed services, weak configurations, unmanaged assets, unsupported software, certificate issues, and control gaps that increase attack-path risk.
Ensure newly introduced or materially changed RS/HS assets receive appropriate assessment and are incorporated into ongoing exposure monitoring.
Coordinate assessment of approved cloud platforms, containers, Kubernetes environments, and CI/CD components used within the RS/HS scope.
Partner with architecture and engineering teams to reduce systemic weaknesses and embed exposure-management requirements into design and deployment processes.
Archer Governance & Risk Management
Support governance through the Archer IT Security Vulnerabilities Program and applicable RS/HS risk-management processes.
Ensure risk acceptances, remediation exceptions, compensating controls, and mitigation plans are documented, approved, time-bound, and tracked to closure.
Maintain audit-ready evidence for exposure identification, ownership, remediation, verification, exception decisions, and management review.
Support risk reporting on material exposure, overdue remediation, recurring weaknesses, and accepted residual risk.
Threat-Informed Risk Prioritization
Implement risk-based prioritization incorporating technical severity, exploit intelligence, known exploitation, asset criticality, reachability, control effectiveness, and RS/HS impact.
Collaborate with Security Operations, Threat Intelligence, and Incident Response teams to identify vulnerabilities and exposures associated with active or relevant threat activity.
Prioritize remediation of exposures that create credible attack paths to sensitive assets, privileged functions, administrative boundaries, or critical services.
Document prioritization rationale and ensure urgent exposures receive clear ownership, escalation, and verification.
Remediation Engineering & Automation
Coordinate remediation across infrastructure, endpoint, network, application, database, identity, cloud, and platform teams responsible for RS/HS assets.
Establish and enforce remediation service levels aligned with exposure risk, asset criticality, operational constraints, and approved risk tolerance.
Integrate exposure workflows with patch management, configuration management, infrastructure automation, and change-control processes where authorized.
Reduce backlog and mean time to remediate through root-cause analysis, recurring-finding elimination, workflow improvements, and safe automation.
Ensure remediation is verified through rescanning, technical validation, or approved evidence before closure.
Metrics, Reporting & Executive Communication
Develop and maintain exposure-management dashboards using approved data from ServiceNow Vulnerability Response, Rapid7, CrowdStrike, Archer, and Power BI.
Track metrics including coverage, backlog, remediation aging, service-level compliance, mean time to remediate, recurrence, exception status, and exposure reduction.
Provide concise risk-posture updates, material exposure escalations, remediation forecasts, and decision support to security leadership and RS/HS stakeholders.
Protect sensitive asset and vulnerability details by applying need-to-know access, appropriate classification, and approved distribution practices.
Leadership & Stakeholder Collaboration
Provide technical leadership, mentoring, standards, and quality oversight for engineers and analysts supporting RS/HS exposure management.
Build effective partnerships with system owners, IT operations, application teams, cloud and platform teams, architects, governance functions, and engineering leadership.
Lead working sessions for material exposures, overdue remediation, recurring weaknesses, exceptions, and control improvements.
Promote risk-based remediation practices and clear accountability across the organization.
Job QualificationProfessional Experience
8+ years of experience in cybersecurity, vulnerability management, exposure management, security engineering, infrastructure security, or related disciplines.
4+ years of experience operating or leading vulnerability or exposure management capabilities in a complex enterprise environment.
Demonstrated experience coordinating remediation across infrastructure, endpoints, applications, networks, cloud platforms, and security teams.
Experience supporting restricted, regulated, high-assurance, sensitive, or otherwise tightly controlled technology environments.
Proven ability to lead complex exposure investigations, make risk-based decisions, and communicate with technical and leadership stakeholders.
Technical Skills
Hands-on experience with ServiceNow Vulnerability Response, Rapid7 InsightVM, Rapid7 InsightAppSec, CrowdStrike Falcon Spotlight / Exposure Management, or comparable enterprise platforms.
Experience with Archer IT Security Vulnerabilities Program or comparable governance, risk, and compliance workflows.
Strong understanding of vulnerability assessment, credentialed scanning, asset correlation, attack-surface management, risk scoring, patch management, remediation governance, and validation.
Experience assessing Windows, Linux, network infrastructure, applications, databases, identity systems, cloud platforms, containers, Kubernetes, and internet-facing assets.
Knowledge of CVSS, CISA Known Exploited Vulnerabilities, EPSS, exploit intelligence, threat-informed prioritization, compensating controls, and attack-path analysis.
Familiarity with NIST Cybersecurity Framework, ISO/IEC 27001, CIS Critical Security Controls, and applicable regulatory or assurance requirements.
Ability to develop dashboards, data-quality checks, workflow automation, and reporting using ServiceNow, Power BI, APIs, scripting, or related technologies.
Understanding of secure architecture, network segmentation, privileged access, change control, evidence handling, and need-to-know information protection.
Soft Skills
Strong analytical thinking, problem-solving, and technical

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App