GuidePoint Security

Practice Lead, Exposure Management - Northeast region

Remote · Posted 2d ago

salary not listedDept: Engineering

Job Description

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.

General Description

GuidePoint Security is seeking a Practice Lead, Exposure Management to lead and grow our Exposure Management practice. This role is responsible for delivering expert advisory and technical services that help clients build, mature, and operationalize exposure management programs — spanning vulnerability management, asset visibility, cloud security, attack surface management, and risk-based remediation. The Practice Lead will provide “Wow Them” service to clients while driving the commercial success of the practice.

The Practice Lead, Exposure Management will be required to demonstrate strong technical depth, consultative acumen, and leadership capability. This individual will lead by influence, apply strong business and financial acumen, and drive the adoption of progressive exposure management programs that align delivery with client business objectives and priorities.

About the Exposure Management Practice

Exposure Management Practice is responsible for helping clients identify, understand, and reduce cyber risk across their environments. We deliver advisory, implementation, and managed services that span the full exposure management lifecycle — from vulnerability and asset discovery through risk-based prioritization and remediation.

Our team of security engineers, architects, and consultants focuses on vulnerability management, CAASM, CNAPP, attack surface management, and remediation orchestration. We partner with clients and GuidePoint account teams to improve security posture and drive measurable risk reduction.

  • Vulnerability management program advisory, platform procurement, proof of concept, implementation, and Vulnerability Management as a Service (VMaaS)
  • Exposure management platform enablement and optimization across CAASM, CNAPP, attack surface management, and risk-based prioritization technologies
  • Pre-sales technical advisory and solution development in partnership with GuidePoint account executives and regional leadership

Roles and Responsibilities:   

  • Lead and grow the Exposure Management practice, including developing and refining service offerings across vulnerability management, CAASM, CNAPP, attack surface management, and remediation orchestration
  • Deliver professional technology solutions and advisory services in an enterprise-level consultative role, supporting clients across the full exposure management lifecycle from assessment and tool selection through implementation, optimization, and managed operations
  • Proactively mature the practice, including improving existing service offerings, creating new offerings, and mentoring and developing team members
  • Author comprehensive business and technical collateral to support the practice, proficiently tailored to both technical and executive audiences
  • Support sales efforts through conference speaking, blog and white paper authoring, podcast participation, and direct engagement with account executives to drive services opportunities
  • Work with the Security Architecture team to provide pre-sales support and technical leadership to develop and close opportunities for the practice
  • Manage and scale a team of technical resources, including training plans for professional and personal growth, proper resourcing of engagements, and tracking and communication of team and Key Performance Indicators (KPIs)
  • Build and manage relationships with key technology vendors and evaluate emerging platforms relevant to the practice and its underlying service areas
  • Work with key OEM partners to position GuidePoint as a preferred partner for exposure management and vulnerability management opportunities
  • Coordinate with Regional Technology Solutions teams to ensure consistency of messaging, delivery methodology, and client outcomes across GuidePoint
  • Collaborate with the Security Consulting and Information Assurance teams to develop joint service offerings across GRC, cloud security, identity, threat intelligence, and incident response disciplines
  • Embrace emerging technologies, including AI tools, to work smarter, solve problems faster, and drive better outcomes for clients and the practice

Required Experience and Education: 

  • 7+ years of experience in cybersecurity, with significant depth in vulnerability management, exposure management, or related security domains
  • Advanced practical experience with vulnerability management platforms such as Tenable, Rapid7, or Qualys, including deployment, configuration, optimization, and integration in complex enterprise environments
  • Experience with exposure management and CAASM platforms such as Axonius, Armis, or similar asset intelligence and attack surface management tools
  • Experience with CNAPP and cloud security platforms such as Wiz, Prisma Cloud, or Orca, including cloud posture management and cloud-native exposure analysis
  • Deep understanding of risk-based vulnerability prioritization methodologies and tooling, including platforms such as Kenna Security, Brinqa, Vulcan, or Nucleus
  • Experience operationalizing security tooling in complex enterprise environments, including integration with ITSM platforms such as ServiceNow or Jira for remediation workflow automation
  • Strong understanding of security program design, including how vulnerability management, exposure management, and asset visibility capabilities align to broader security program maturity
  • Demonstrated ability to manage time independently while handling multiple client engagements and internal initiatives concurrently
  • Very strong writing and communication skills, with the ability to clearly articulate complex technical and programmatic topics to both technical and executive audiences
  • Deep understanding of asset management, vulnerability lifecycle, and remediation strategies across on-premises, cloud, and hybrid environments
  • Team-first attitude with a genuine interest in helping peers grow, collaborating on complex engagements, and serving as a subject matter expert on technical escalations
  • Standard industry certifications are preferred (e.g., CISSP, CEH, vendor certifications from Tenable, Qualys, or Rapid7)
  • Must reside in the Northeast region; this role requires travel primarily within the Northeast region for client meetings, workshops, and conferences
  • Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes

Preferred Experience and Education 

  • Experience with CNAPP platforms such as Wiz, Prisma Cloud, Orca, or Lacework in customer-facing delivery or advisory engagements
  • Experience operating or advising on vulnerability management programs within large enterprise or regulated environments
  • Familiarity with cloud platforms (AWS, Azure, GCP) and cloud-native security posture management
  • Experience assessing or validating multiple vulnerability management, exposure management, CAASM, or attack surface management platforms across diverse client environments
  • Prior experience in a pre-sales, solutions architecture, or technical advisory capacity, including developing scopes of work and presenting to executive audiences
  • Experience using AI-assisted tools such as LLMs, copilots, or automation frameworks to accelerate analysis, reporting, and security operations workflows
  • Relevant industry certifications such as CISSP, CISM, or platform-specific certifications from Tenable, Qualys, Rapid7, or cloud providers

Travel Requirements:

  • Up to 25% travel, primarily within the Northeast region

Physical Requirements:

  • Sedentary work
  • Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day
  • Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day

We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application.


Why GuidePoint?

GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1,300 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 6,200 customers.

Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity.  

This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation.

Some added perks….

  • Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
  • Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
  • Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
  • 12 corporate holidays and a Flexible Time Off (FTO) program
  • Healthy mobile phone and home internet allowance
  • Eligibility for retirement plan after 2 months at open enrollment
  • Pet Benefit Option