Threat and Vulnerability Manager - San Mateo, Ca

San Mateo, CA

Guidewire Software logo
Guidewire Software
Apply now Apply later

Posted 1 month ago

The Vulnerability Management Manager will be responsible technically leading the Vulnerability Management (OS specific) function within the Security Operations Team at Guidewire. She/he would be responsible for managing the scanning infrastructure (both on prem and predominantly AWS) and in the near future, help build a Cyber Threat Intelligence/Data Risk Protection (CTI/DRP) program within this team. The role will report to the Senior Director of Security Operations and is part of the Guidewire’s global Information Security group. The selected candidate needs to demonstrate subject matter expertise in one or more of the following areas:


  • Deploy, configure and manage infrastructure vulnerability management products, tools and solutions to help augment security threat monitoring, detection, prevention and compliance as part of Guidewire’s cloud security architecture (Rapid 7, Qualys, Nessus, Risk Based Scanning Tools)
  •  Work with Cloud Operations, IT and product teams to perform POCs and track deployments for initiatives and/or changes in the Guidewire’s public cloud environment
  •  Responsible for the vulnerability management program that includes periodic scanning, reporting, and tracking remediation of the security vulnerabilities discovered in AWS and data center assets
  •  Develop and enforce cloud security standards in AWS including IAM policies, security groups, S3 bucket policies, encryption, network security, cloud workload and container security, logging, monitoring etc.
  •  Any experience (technology or non-technology) related to managing a team or people would be desirable since this role will be helping build a program and team
  •  Willingness to be on call and serve as the point of contact for information security alerts and incidents 


  •  5+ years of previous experience working in security operations, administration, threat and vulnerability management – experience with automation and familiarity with “Infrastructure as Code” in the public cloud
  •  Minimum 5 years of experience deploying, testing and configuring multiple security technologies including Vulnerability Scanners, AWS Cloud Security platform tools. He/she should be able to share some of the success and failure stories they have had to go through in the past around build an effective vulnerability management program
  •  Thorough knowledge of the TCP / IP protocol suite, securing and hardening Operating Systems, Networks, Databases and Web Applications Information
  •  Hands on experience in running vulnerability scans, analyzing and tracking vulnerabilities with asset owners for timely remediation
  •  Basic hands-on experience with a public Cloud platform (AWS, Azure, GCP) with understanding/working knowledge of IaaS platforms and services (i.e., VPC, EC2, S3, RDS, Lambda, AWS WAF, CloudFront, ECS, Flow Logs etc.) is required
  •  Experience developing and maintaining hardening and configuration standards and procedures
  •  Security certifications like CISSP, GSEC, CEH, AWS certification etc. are highly desired
  •  Familiarity with industry common information technology control frameworks, particularly SOC1/2, Cloud Security Alliance, and ISO 27001/2.
  •  Excellent verbal and written communication skills and ability to document and explain technical details, standards and reports clearly and concisely
  •  B.S. degree in Computer Science or related field or equivalent combination of professional development training and experience
About GuidewireGuidewire is the platform P&C insurers trust to engage, innovate, and grow efficiently.
Guidewire combines core, data, digital, analytics, and AI to deliver our platform as a cloud service. 380 insurers, including the largest and most complex in the world, run on Guidewire.
As a partner to our customers, we continually evolve to enable their success. We are proud of our unparalleled implementation track record with 700+ successful projects, supported by the largest R&D team and partner ecosystem in the industry. Our marketplace provides hundreds of add-ons that accelerate integration, localization, and innovation.
Guidewire Software, Inc. is proud to be an equal opportunity and affirmative action employer. We are committed to an inclusive workplace, and believe that a diversity of perspectives, abilities, and cultures is a key to our success. Qualified applicants will receive consideration without regard to race, color, ancestry, religion, sex, national origin, citizenship, marital status, age, sexual orientation, gender identity, gender expression, veteran status, or disability. All offers are contingent upon passing a criminal history and other background checks where it's applicable to the position.
Disability Accommodations and Guidewire’s Appeals Process. Guidewire provides accommodations to the hiring process to create a fair opportunity for candidates with disabilities to contend for open positions. Accommodation requests should be directed to (650) 356-4940 or If things do not go as hoped, we invite you to use our appeals process. Guidewire promises to independently review any denied accommodation and any decision not to offer you the position. The appeals process is the same in either case. Within five business days of receiving a notice of denial of an accommodation, or receiving a notice of your non-selection for a vacancy, call (650) 356-4940 or e-mail to make an appeal. Guidewire will assign a new decision-maker to review the request and/or hiring decision, who will then notify you in writing of a decision within 10 business days.
Job tags: AI Analytics Architecture Automation AWS Azure C CEH CISSP CloudFront Encryption Go IaaS ISO 27001 Lambda Network security POCs Qualys S3 Threat intelligence Vulnerabilities Vulnerability management Vulnerability scans
Job region(s): North America
Share this job: