Job Description

Kenvue Is Currently Recruiting For a

Manager – Vulnerability Management & Risk Governance

What We Do

At Kenvue, we realize the extraordinary power of everyday care. Built on over a century of heritage and rooted in science, we’re the house of iconic brands - including NEUTROGENA®, AVEENO®, TYLENOL®, LISTERINE®, JOHNSON’S® and BAND-AID® that you already know and love. Science is our passion; care is our talent.

Who We Are

Our global team is ~ 22,000 brilliant people with a workplace culture where every voice matters, and every contribution is appreciated. We are passionate about insights, innovation and committed to delivering the best products to our customers. With expertise and empathy, being a Kenvuer means having the power to impact millions of people every day. We put people first, care fiercely, earn trust with science and solve with courage – and have brilliant opportunities waiting for you! Join us in shaping our future–and yours. For more information, click here.

Role Reports To

GCC Cybersecurity Lead

Location:

Asia Pacific, India, Karnataka, Bangalore

Work Location:

Hybrid

What You Will Do

Kenvue is hiring a Manager – Vulnerability Management & Risk Governance .

As the Manager of Vulnerability Management and Risk Governance, you will lead the strategic and operational execution of Kenvue’s cybersecurity risk and vulnerability programs across cloud and endpoint environments. This role is pivotal in ensuring alignment with enterprise security policies and industry frameworks, while driving measurable improvements in risk posture.

Key Responsibilities

  • Define and lead the vulnerability management (VM) strategy, standards, and operating model. Ensure continuous discovery and coverage across governed assets.
  • Ensure adherence to the Vulnerability Management Policy and relevant NIST cybersecurity controls. Maintain alignment with frameworks such as NIST, MITRE, ISO 27005/31000, etc.
  • Manage and optimize tools such as Wiz and Microsoft Defender to support the full vulnerability lifecycle—discovery, prioritization, remediation, and reporting.
  • Lead the cyber risk governance cadence including steering committees, working groups, RACI matrices, and decision logs. Maintain an up-to-date risk register with clear ownership, prioritization, treatment plans, and timelines.
  • Establish and operationalize risk management policies, govern risk data quality, and oversee exception handling processes.
  • Translate technical risk posture into business-relevant insights. Define and report on key risk indicators (KRIs), quantify residual risk, and deliver periodic briefings to leadership and audit stakeholders.
  • Triage and prioritize vulnerabilities based on business impact and likelihood. Maintain a unified backlog and drive remediation efforts in collaboration with product, infrastructure, and application teams.
  • Develop and refine dashboards to measure program effectiveness. Track KPIs, SLAs, and identify roadblocks to drive continuous improvement.
  • Lead a team of analysts and engineers, ensuring accountability for remediation SLAs. Partner cross-functionally with Enterprise Architecture, Cloud, Platform, AppSec, IT Operations, and Compliance teams to embed risk-informed decisions into strategic roadmaps.

What We Are Looking For

  • Minimum 10-15 years of experience in cybersecurity, with a strong focus on vulnerability management and risk governance.
  • Proven ability to lead cross-functional initiatives and engage stakeholders effectively.
  • Hands-on experience with enterprise-grade tools such as Wiz and Microsoft Defender across cloud and endpoint environments.
  • Deep understanding of cybersecurity frameworks including NIST, MITRE, ISO, and FAIR, and their practical application in policy and metrics.
  • Experience integrating risk workflows with enterprise risk systems and maintaining high-quality risk registers.
  • Strong communication skills—both written and verbal—with the ability to convey technical concepts to non-technical audiences.
  • Relevant certifications such as Azure Security Engineer/Architect, CCSP, CISM, CRISC, or CISSP.

What’s In It For You

  • Competitive Benefit Package
  • Paid Company Holidays, Paid Vacation, Volunteer Time, Summer Fridays & More!
  • Learning & Development Opportunities
  • Employee Resource Groups
  • This list could vary based on location/region

Kenvue is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, or protected veteran status and will not be discriminated against on the basis of disability.

If you are an individual with a disability, please check our Disability Assistance page for information on how to request an accommodation.


Job Details

Role Level: Mid-Level Work Type: Full-Time
Country: India City: Bengaluru ,Karnataka
Company Website: https://www.kenvue.com Job Function: Information Technology (IT)
Company Industry/
Sector:
Personal Care Product Manufacturing

What We Offer


About the Company

Searching, interviewing and hiring are all part of the professional life. The TALENTMATE Portal idea is to fill and help professionals doing one of them by bringing together the requisites under One Roof. Whether you're hunting for your Next Job Opportunity or Looking for Potential Employers, we're here to lend you a Helping Hand.

Report

Similar Jobs

Disclaimer: talentmate.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@talentmate.com.


Talentmate Instagram Talentmate Facebook Talentmate YouTube Talentmate LinkedIn