iCapital Logo

Vulnerability Management Specialist - Assistant Vice President

Job Description

iCapital is looking for a AVP Engineer to join the Information Security team. This role will help establish and run Vulnerability and Exposure Management practices, build structured remediation processes, support application security activities, and continuously identify and reduce risk across iCapital technology. The ideal candidate is a hands-on individual contributor who can implement and improve processes, work directly with developers and drive remediation execution at scale.

Responsibilities

  • Build and manage Vulnerability and Exposure Management processes, providing continuous monitoring, prioritisation, and resolution of vulnerabilities across the environment.
  • Implement and drive remediation of vulnerabilities and security weaknesses.
  • Collaborate with engineering teams to improve workflows, adopt best practices, and drive consistent remediation standards.
  • Build automation capabilities to ingest, track and report vulnerabilities and exposures.
  • Evolve and improve exposure management capabilities, including prioritization based on risk, attack paths, and business impact.
  • Build processes and automation capabilities for application security workflows, including SAST, SCA, secrets and API security in collaboration with developers.
  • Review and validate penetration testing findings and ensure effective remediation.
  • Work directly with developers to explain vulnerabilities, agree remediation approaches, and validate fixes.
  • Support threat modelling activities to identify risk earlier in the design phase.
  • Assist the SOC in improving detection and alerting capabilities based on identified vulnerabilities and exposures.
  • Develop workflows for vulnerability intake, triage, remediation tracking, and reporting across tools.
  • Assist Risk and Governance teams with policies, procedures, standards, and audit evidence.
  • Collaborate with cross-functional teams, including Engineering and Security, to deliver security improvements.

Qualifications

  • Experience in Vulnerability Management, Exposure Management, or Application Security.
  • Strong understanding of web and API security risks.
  • Experience reviewing and validating penetration testing findings.
  • Experience working with developers.
  • Experience with scripting and automation, preferably Python.
  • Experience with development workflows, systems engineering and modern CI/CD environments.
  • Strong verbal and written communication skills.
  • Able to influence stakeholders.
  • Able to drive tasks to completion.

Nice to have

  • Security certifications.
  • Experience with GitLab or GitHub security features.
  • Experience with Wiz, CSPM, CrowdStrike or code scanning tools (SAST, SCA, DAST).
  • Experience with secure code reviews and threat modelling.
  • Experience with API security and Burp Suite or similar testing tools.

We believe the best ideas and innovation happen when we are together. Employees in this role will work in the office four days, with the flexibility to work remotely one day (Friday).

Benefits

iCapital offers a comprehensive benefits package that includes a total compensation program consisting of competitive salary, annual performance bonus, and equity for all full-time employees; healthcare with 100% employer-paid health and dental insurance; and generous paid time off (PTO).

For additional information on iCapital Network, please visit https://www.icapitalnetwork.com/about-us  Twitter: @icapitalnetwork | LinkedIn: https://www.linkedin.com/company/icapital-network-inc

Share this job:
Please let iCapital know you found this job on Remote First Jobs 🙏

Remote companies like iCapital

Find your next opportunity with companies that specialize in Hnw Fundraising Platform, Alternative Investments, Private Equity And Hedge Funds, and Private Investor Network. Explore remote-first companies like iCapital that prioritize flexible work and home-office freedom.

CAIS Logo

CAIS

An alternative investment platform, offering streamlined access to private equity, hedge funds, and structured notes for financial advisors.

View company profile →
Goji, Euroclear group Logo

Goji, Euroclear group

Offers a digitised investment platform for private market funds, streamlining services for asset managers, fund administrators, and distributors.

View company profile →
Yieldstreet Logo

Yieldstreet

Private market investment platform

View company profile →
MUFG Investor Services Logo

MUFG Investor Services

Provides solutions for global alternative investment management, including fund administration and asset servicing.

View company profile →
DiligenceVault Logo

DiligenceVault

A digital diligence ecosystem and technology platform for the investment management industry.

View company profile →
Drawbridge Logo

Drawbridge

Cybersecurity software and solutions for the alternative investment and wealth management industry.

View company profile →

Project: Career Search

Rev. 2026.6

[ Remote Jobs ]
Direct Access

We source jobs directly from 21,000+ company career pages. No intermediaries.

01

Discover Hidden Jobs

Unique jobs you won't find on other job boards.

02

Advanced Filters

Filter by category, benefits, seniority, and more.

03

Priority Job Alerts

Get timely alerts for new job openings every day.

04

Manage Your Job Hunt

Save jobs you like and keep a simple list of your applications.

21,000+ SOURCES UPDATED 24/7
Apply