RVC
JobsFor Employers
  1. Jobs
  2. /
  3. Senior Restricted Secure / High Secure Exposure Management Lead

Senior Restricted Secure / High Secure Exposure Management Lead

nxp | Semiconductors
1h 54m ago
Remote In-Country
Full Time
Romania

Job Title: Senior Restricted Secure / High Secure Exposure Management Lead

Location: Bucharest Romania

Job Position: Senior Restricted Secure / High Secure Exposure Management Lead

Role Summary

The Senior Restricted Secure / High Secure Exposure Management Lead serves as the senior technical and operational lead for exposure management across Restricted Secure and High Secure (RS/HS) environments. The role is responsible for ensuring vulnerabilities, misconfigurations, exposed services, unsupported technologies, and attack-path risks are continuously identified, validated, prioritized, and driven through remediation in accordance with the heightened protection requirements of RS/HS environments.

This is a hands-on technical leadership role requiring deep expertise in vulnerability and exposure management, scanning platforms, risk-based prioritization, remediation governance, and secure-environment operations. The role coordinates with system owners, infrastructure engineering, application teams, cloud and platform teams, Security Operations, Threat Intelligence, Incident Response, and governance stakeholders to reduce exploitable exposure while maintaining availability, integrity, segmentation, and change-control requirements.

Success in this role requires sound technical judgment, disciplined handling of sensitive exposure data, strong program execution, and the ability to translate complex findings into clear remediation priorities and measurable risk reduction for technical and leadership audiences.

Job Responsibility

RS/HS Exposure Management Leadership

  • Lead the day-to-day technical and operational execution of exposure management for Restricted Secure and High Secure environments.
  • Establish a consistent operating model for identifying, validating, prioritizing, assigning, tracking, and closing security exposures across RS/HS assets.
  • Maintain an authoritative view of vulnerabilities, misconfigurations, exposed services, unsupported technologies, and attack-path risks affecting RS/HS environments.
  • Ensure exposure-management activities align with applicable security architecture, segmentation, access-control, data-handling, and change-management requirements.
  • Define and continuously improve exposure-reduction processes, technical standards, control objectives, and operating procedures.

Vulnerability Detection & Platform Operations

  • Operate and maintain enterprise vulnerability detection capabilities supporting RS/HS infrastructure, endpoints, applications, network devices, and approved cloud or container platforms.
  • Maintain scanner configuration, credentialed assessment coverage, agent deployment, scan scheduling, policy alignment, and platform health.
  • Use platforms including Rapid7 InsightVM, Rapid7 InsightAppSec, and CrowdStrike Falcon Spotlight / Exposure Management where approved for the target environment.
  • Validate findings, investigate false positives, reconcile duplicate records, and ensure accurate association between findings, assets, owners, and business services.
  • Identify assessment blind spots and coordinate approved methods to improve coverage without introducing unacceptable operational or confidentiality risk.
  • Maintain visibility into RS/HS attack surfaces, trust boundaries, privileged pathways, remote access points, security appliances, and externally reachable components.
  • Identify exposed services, weak configurations, unmanaged assets, unsupported software, certificate issues, and control gaps that increase attack-path risk.
  • Ensure newly introduced or materially changed RS/HS assets receive appropriate assessment and are incorporated into ongoing exposure monitoring.
  • Coordinate assessment of approved cloud platforms, containers, Kubernetes environments, and CI/CD components used within the RS/HS scope.
  • Partner with architecture and engineering teams to reduce systemic weaknesses and embed exposure-management requirements into design and deployment processes.

Archer Governance & Risk Management

  • Support governance through the Archer IT Security Vulnerabilities Program and applicable RS/HS risk-management processes.
  • Ensure risk acceptances, remediation exceptions, compensating controls, and mitigation plans are documented, approved, time-bound, and tracked to closure.
  • Maintain audit-ready evidence for exposure identification, ownership, remediation, verification, exception decisions, and management review.
  • Support risk reporting on material exposure, overdue remediation, recurring weaknesses, and accepted residual risk.

Threat-Informed Risk Prioritization

  • Implement risk-based prioritization incorporating technical severity, exploit intelligence, known exploitation, asset criticality, reachability, control effectiveness, and RS/HS impact.
  • Collaborate with Security Operations, Threat Intelligence, and Incident Response teams to identify vulnerabilities and exposures associated with active or relevant threat activity.
  • Prioritize remediation of exposures that create credible attack paths to sensitive assets, privileged functions, administrative boundaries, or critical services.
  • Document prioritization rationale and ensure urgent exposures receive clear ownership, escalation, and verification.

Remediation Engineering & Automation

  • Coordinate remediation across infrastructure, endpoint, network, application, database, identity, cloud, and platform teams responsible for RS/HS assets.
  • Establish and enforce remediation service levels aligned with exposure risk, asset criticality, operational constraints, and approved risk tolerance.
  • Integrate exposure workflows with patch management, configuration management, infrastructure automation, and change-control processes where authorized.
  • Reduce backlog and mean time to remediate through root-cause analysis, recurring-finding elimination, workflow improvements, and safe automation.
  • Ensure remediation is verified through rescanning, technical validation, or approved evidence before closure.

Metrics, Reporting & Executive Communication

  • Develop and maintain exposure-management dashboards using approved data from ServiceNow Vulnerability Response, Rapid7, CrowdStrike, Archer, and Power BI.
  • Track metrics including coverage, backlog, remediation aging, service-level compliance, mean time to remediate, recurrence, exception status, and exposure reduction.
  • Provide concise risk-posture updates, material exposure escalations, remediation forecasts, and decision support to security leadership and RS/HS stakeholders.
  • Protect sensitive asset and vulnerability details by applying need-to-know access, appropriate classification, and approved distribution practices.

Leadership & Stakeholder Collaboration

  • Provide technical leadership, mentoring, standards, and quality oversight for engineers and analysts supporting RS/HS exposure management.
  • Build effective partnerships with system owners, IT operations, application teams, cloud and platform teams, architects, governance functions, and engineering leadership.
  • Lead working sessions for material exposures, overdue remediation, recurring weaknesses, exceptions, and control improvements.
  • Promote risk-based remediation practices and clear accountability across the organization.

Job Qualification

Professional Experience

  • 8+ years of experience in cybersecurity, vulnerability management, exposure management, security engineering, infrastructure security, or related disciplines.
  • 4+ years of experience operating or leading vulnerability or exposure management capabilities in a complex enterprise environment.
  • Demonstrated experience coordinating remediation across infrastructure, endpoints, applications, networks, cloud platforms, and security teams.
  • Experience supporting restricted, regulated, high-assurance, sensitive, or otherwise tightly controlled technology environments.
  • Proven ability to lead complex exposure investigations, make risk-based decisions, and communicate with technical and leadership stakeholders.

Technical Skills

  • Hands-on experience with ServiceNow Vulnerability Response, Rapid7 InsightVM, Rapid7 InsightAppSec, CrowdStrike Falcon Spotlight / Exposure Management, or comparable enterprise platforms.
  • Experience with Archer IT Security Vulnerabilities Program or comparable governance, risk, and compliance workflows.
  • Strong understanding of vulnerability assessment, credentialed scanning, asset correlation, attack-surface management, risk scoring, patch management, remediation governance, and validation.
  • Experience assessing Windows, Linux, network infrastructure, applications, databases, identity systems, cloud platforms, containers, Kubernetes, and internet-facing assets.
  • Knowledge of CVSS, CISA Known Exploited Vulnerabilities, EPSS, exploit intelligence, threat-informed prioritization, compensating controls, and attack-path analysis.
  • Familiarity with NIST Cybersecurity Framework, ISO/IEC 27001, CIS Critical Security Controls, and applicable regulatory or assurance requirements.
  • Ability to develop dashboards, data-quality checks, workflow automation, and reporting using ServiceNow, Power BI, APIs, scripting, or related technologies.
  • Understanding of secure architecture, network segmentation, privileged access, change control, evidence handling, and need-to-know information protection.

Soft Skills

  • Strong analytical thinking, problem-solving, and technical judgment.
  • Excellent written and verbal communication for engineering, risk, audit, and leadership audiences.
  • Ability to lead through influence, resolve ownership gaps, and drive remediation across distributed teams.
  • Disciplined handling of sensitive information and ability to operate in high-assurance environments.
  • Ability to manage multiple priorities, urgent exposures, and long-term capability improvements.

Certifications (Preferred)

  • Security certifications such as CISSP, CISM, CCSP, OSCP, GIAC, or equivalent cybersecurity certifications.
  • Platform certifications or demonstrated advanced experience with ServiceNow Vulnerability Response, Rapid7, CrowdStrike, Archer, cloud security, or attack-surface management technologies.

Creating Secure Connections and Infrastructure for a Smarter World

NXP Semiconductors N.V. (NASDAQ: NXPI) makes products and environments safer, more sustainable, and more secure with innovative connectivity and edge processing solutions for a smarter world.

We are in the business of better. Not just better technologies, but better innovations to improve society. As the world leader in secure connectivity and processing solutions for embedded applications, NXP is solving the world’s most complex technology challenges to accelerate business innovation, enhance how we work, and advance how we live.

Ready to create a smarter world? Visit our career website and follow us on social: LinkedIn, Facebook and Twitter.

What can you expect

Contract: This is a fulltime position with a permanent contract

Compensation: Besides a good salary, you will be eligible for our bonus plan and receive lunch vouchers, 25  vacation days and the possibility to buy company shares with a 15% discount. We also have flexible work hours and a work from home policy.

Development opportunities: We believe that a key component to growing our business is to develop our people. To enable you to grow your career at NXP, we offer online and offline learning opportunities to help you develop some of your core and professional skills.

Our office: We are based in one of the high tech hubs in Bucharest with easy access to public transport and restaurants and parks close by. We have many relaxation areas on-site, including a little library where you can borrow books, sofas to relax in a quiet place and a cafeteria and restaurant in our common area.

Hiring process: Applying only takes a minute! Fill in the online application and share your CV with us. After a positive screening based on your CV you will have an initial phone or video conversation with our Talent Acquisition Consultant followed by several business interviews. Here are some useful tips to help you prepare.

And more: Life at NXP is more than work alone. We like to start our day with a free coffee and chat with a colleague and on Thursdays we have fresh fruits for all employees. Join us at one of the many social activities that are organized by and for employees such as our Christmas parties, our employee children’s party and food fairs. Or help us give back to society by donating blood or collecting clothes and food for children in need.

What’s next

Candidates are invited to apply on our career page with the resume and motivation letter in English for one or several open jobs at the same time.

At the application stage, all candidates should have a valid visa and work permit to work in Romania.

If you’re excited about this opportunity, we kindly invite you to apply!

Please note: The successful candidate may/will be responsible for security related tasks. The assignment may/will be in scope of security certifications, therefore a conscious and reliable way of working is necessary.

More information about NXP in Romania...

#LI-9ccb

Required Skills

apisci/cdcloud_servicescontainersdatabaseskuberneteslinuxpower_biscriptingwindows

Required Languages

🇬🇧 English

Related searches

  • Remote In-Country Jobs
  • Senior Jobs
1 jobs
Sort by
1h 54m ago

Senior Restricted Secure / High Secure Exposure Management Lead

nxp·Semiconductors
apisci/cdcloud_servicescontainers+6
📡Remote In-Country
|Romania
General InfoSec
No similar jobs match these filters. Try changing or clearing a filter.
Remote roles
PythonJavaReactTypeScriptGoDevOpsNode.jsC# / .NET
Countries
United StatesUnited KingdomCanadaUS & EMEAGermanyPolandSpainNetherlandsPortugal
Experience
SeniorMid-levelJunior
R© 2026 RVC Globalbuild ef82d542
AboutPricingContactPrivacyCookiesRefundsTerms & ConditionsFor Employers