Director, Security Architecture, Vulnerability Management and Response
Omnissa · Remote
📍 Remote - USAvia workday
Apply on company site ↗
CareerRiver pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Omnissa.
Job Description:
Job Description
We are Omnissa!
Omnissa is the first AI-driven digital work platform, built to support flexible, secure, work-from anywhere experiences. We integrate industry-leading solutions—including Unified Endpoint Management, Virtual Apps and Desktops, Digital Employee Experience, and Security & Compliance—into a seamless, autonomous workspace that adapts to how people work. Our platform boosts employee engagement while optimizing IT operations, security, and cost.
Guided by our Core Values— Act in Alignment, Build Trust, Foster Inclusiveness, Drive Efficiency, and Maximize Customer Value —we’re growing rapidly and committed to delivering meaningful impact. If you're passionate about shaping the future of work, we’d love to hear from you.
Director, Security Architecture, Vulnerability Management and Response
Reports to: Chief Information Security Officer (CISO)
Location: AMER (ATL or MV is preferred - Remote-for the right candidate)
Role Summary
Omnissa is seeking a Director, Security Architecture, Vulnerability Management and Response to set and drive the strategy for three tightly integrated security functions: Security Architecture, Vulnerability Management, and Vulnerability Response (PSIRT). This leader leads the technical security capabilities that protect Omnissa's infrastructure, applications, and services across on-premises and cloud environments, and is accountable for the full lifecycle of risk, from identification through mitigation and verified remediation. This role works in close partnership with Product Security and engineering leadership to align shared standards for secure development and vulnerability response, rather than operating as a separate or overlapping function.
This is a hands-on leadership role for someone who can balance long-range strategy with day-to-day operational excellence, build deep partnerships across the business, and lead a distributed team of senior engineers and architects. As Omnissa expands its use of AI across the enterprise, this role also carries responsibility for shaping the security and governance posture around emerging AI/GenAI technologies.
Key Responsibilities
Strategy & Leadership
Set the multi-year strategy and roadmap aligned to Omnissa's risk appetite and business objectives.
Lead, mentor, and grow a globally distributed team of senior security engineers and architects across AMER and APAC.
Serve as the senior escalation point for design conflicts and remediation prioritization decisions, and for security incidents surfaced through the vulnerability response (PSIRT) process.
Represent the function to executive leadership, translating technical risk into business terms and reporting on posture, progress, and investment needs.
Security Architecture
Partner with all lines of business to establish security standards, perform architecture and design reviews, and embed security into every stage of design and implementation.
Drive security framework development, hardening standards, and policy adherence across the enterprise.
Conduct risk assessments and requirements gathering for new infrastructure, products, and services, ensuring controls are defined before deployment.
Partner closely with Product Security and engineering to define security architecture requirements across the SDLC and CI/CD ecosystem, including threat modeling, architecture standards, SAST, DAST, software composition analysis, secrets detection, and artifact/image signing, ensuring security controls are built into development and deployment workflows from design through release.
Drive secure-by-design practices across the enterprise, reference architectures, secure design patterns, and paved-road templates that make the secure path the default path for engineering teams, reducing reliance on after-the-fact review.
Oversee threat modeling for new architectures, major features, and significant changes, partnering with IT, Product Security, and Engineering, to identify design-stage risk before implementation begins.
Define and maintain Omnissa's enterprise identity security strategy and standards, spanning workforce and non-human identities, including AI agents, and API-level access, authentication (SSO, MFA, phishing-resistant methods), authorization, privileged access, and identity governance, across on-premises and cloud environments, partnering with IT, who own and operate the underlying IAM tooling.
Partner with IT and engineering to drive adoption of modern identity architecture (e.g., Zero Trust access principles, just-in-time/just-enough access, federation standards) that scales to AI-driven and non-human identity growth across enterprise and product-facing systems.
Align security architecture, hardening standards, and control design with applicable frameworks: SOC 2, ISO 27001, NIST CSF/800-53, PCI, HIPAA, and FedRAMP; supporting control evidence and audit readiness in partnership with Compliance/GRC.
Partner with data owners, Legal, and Privacy to define data classification, residency, retention, and disposal standards, including for data used in AI/GenAI training, fine-tuning, and retrieval — and ensure security architecture enforces them across on-prem, cloud, and AI/ML pipelines
Exposure/Vulnerability Management
Own the end-to-end Exposure Management program, the tooling, scanners, processes, and SLAs that identify, prioritize, and remediate risk across all environments.
Continuously monitor, prioritize, and report on vulnerabilities, providing remediation guidance to system and product owners and driving accountability to closure.
Govern the program in alignment with Omnissa's Vulnerability Management Policy and Standards.
Ensure Exposure/Vulnerability Management SLAs and remediation accountability apply uniformly across infrastructure, cloud, and product/application codebases.
Vulnerability Response (PSIRT)
Own the enterprise PSIRT strategy, partnering with the
More Remote jobs
Remote jobs · Browse all locations