Practice Lead, Exposure Management - Northeast region
General Description
GuidePoint Security is seeking a Practice Lead, Exposure Management to lead and grow our Exposure Management practice. This role is responsible for delivering expert advisory and technical services that help clients build, mature, and operationalize exposure management programs — spanning vulnerability management, asset visibility, cloud security, attack surface management, and risk-based remediation. The Practice Lead will provide “Wow Them” service to clients while driving the commercial success of the practice.
The Practice Lead, Exposure Management will be required to demonstrate strong technical depth, consultative acumen, and leadership capability. This individual will lead by influence, apply strong business and financial acumen, and drive the adoption of progressive exposure management programs that align delivery with client business objectives and priorities.
About the Exposure Management Practice
Exposure Management Practice is responsible for helping clients identify, understand, and reduce cyber risk across their environments. We deliver advisory, implementation, and managed services that span the full exposure management lifecycle — from vulnerability and asset discovery through risk-based prioritization and remediation.
Our team of security engineers, architects, and consultants focuses on vulnerability management, CAASM, CNAPP, attack surface management, and remediation orchestration. We partner with clients and GuidePoint account teams to improve security posture and drive measurable risk reduction.
Vulnerability management program advisory, platform procurement, proof of concept, implementation, and Vulnerability Management as a Service (VMaaS)
Exposure management platform enablement and optimization across CAASM, CNAPP, attack surface management, and risk-based prioritization technologies
Pre-sales technical advisory and solution development in partnership with GuidePoint account executives and regional leadership
Roles and Responsibilities:
Lead and grow the Exposure Management practice, including developing and refining service offerings across vulnerability management, CAASM, CNAPP, attack surface management, and remediation orchestration
Deliver professional technology solutions and advisory services in an enterprise-level consultative role, supporting clients across the full exposure management lifecycle from assessment and tool selection through implementation, optimization, and managed operations
Proactively mature the practice, including improving existing service offerings, creating new offerings, and mentoring and developing team members
Author comprehensive business and technical collateral to support the practice, proficiently tailored to both technical and executive audiences
Support sales efforts through conference speaking, blog and white paper authoring, podcast participation, and direct engagement with account executives to drive services opportunities
Work with the Security Architecture team to provide pre-sales support and technical leadership to develop and close opportunities for the practice
Manage and scale a team of technical resources, including training plans for professional and personal growth, proper resourcing of engagements, and tracking and communication of team and Key Performance Indicators (KPIs)
Build and manage relationships with key technology vendors and evaluate emerging platforms relevant to the practice and its underlying service areas
Work with key OEM partners to position GuidePoint as a preferred partner for exposure management and vulnerability management opportunities
Coordinate with Regional Technology Solutions teams to ensure consistency of messaging, delivery methodology, and client outcomes across GuidePoint
Collaborate with the Security Consulting and Information Assurance teams to develop joint service offerings across GRC, cloud security, identity, threat intelligence, and incident response disciplines
Embrace emerging technologies, including AI tools, to work smarter, solve problems faster, and drive better outcomes for clients and the practice
Required Experience and Education:
7+ years of experience in cybersecurity, with significant depth in vulnerability management, exposure management, or related security domains
Advanced practical experience with vulnerability management platforms such as Tenable, Rapid7, or Qualys, including deployment, configuration, optimization, and integration in complex enterprise environments
Experience with exposure management and CAASM platforms such as Axonius, Armis, or similar asset intelligence and attack surface management tools
Experience with CNAPP and cloud security platforms such as Wiz, Prisma Cloud, or Orca, including cloud posture management and cloud-native exposure analysis
Deep understanding of risk-based vulnerability prioritization methodologies and tooling, including platforms such as Kenna Security, Brinqa, Vulcan, or Nucleus
Experience operationalizing security tooling in complex enterprise environments, including integration with ITSM platforms such as ServiceNow or Jira for remediation workflow automation
Strong understanding of security program design, including how vulnerability management, exposure management, and asset visibility capabilities align to broader security program maturity
Demonstrated ability to manage time independently while handling multiple client engagements and internal initiatives concurrently
Very strong writing and communication skills, with the ability to clearly articulate complex technical and programmatic topics to both technical and executive audiences
Deep understanding of asset management, vulnerability lifecycle, and remediation strategies across on-premises, cloud, and hybrid environments
Team-first attitude with a genuine interest in helping peers grow, collaborating on complex engagements, and serving as a subject matter expert on technical escalations
Standard industry certifications are preferred (e.g., CISSP, CEH, vendor certifications from Tenable, Qualys, or Rapid7)
Must reside in the Northeast region; this role requires travel primarily within the Northeast region for client meetings, workshops, and conferences
Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes
Preferred Experience and Education
Experience with CNAPP platforms such as Wiz, Prisma Cloud, Orca, or Lacework in customer-facing delivery or advisory engagements
Experience operating or advising on vulnerability management programs within large enterprise or regulated environments
Familiarity with cloud platforms (AWS, Azure, GCP) and cloud-native security posture management
Experience assessing or validating multiple vulnerability management, exposure management, CAASM, or attack surface management platforms across diverse client environments
Prior experience in a pre-sales, solutions architecture, or technical advisory capacity, including developing scopes of work and presenting to executive audiences
Experience using AI-assisted tools such as LLMs, copilots, or automation frameworks to accelerate analysis, reporting, and security operations workflows
Relevant industry certifications such as CISSP, CISM, or platform-specific certifications from Tenable, Qualys, Rapid7, or cloud providers
Travel Requirements:
Up to 25% travel, primarily within the Northeast region
Physical Requirements:
Sedentary work
Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day
Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day