Post Job Free
Sign in

Enterprise Vulnerability Management & Risk Leadership

Location:
San Pedro, CA
Salary:
135k-+155k
Posted:
August 14, 2026

Contact this candidate

Resume:

TRACY L. SANDERS

ENTERPRISE VULNERABILITY MANAGEMENT & CYBER RISK LEADER

San Pedro, CA • 949-***-**** • ***************@******.** • linkedin.com/in/tracy-sanders-a630208

PROFESSIONAL SUMMARY

Vulnerability management leader with five years owning an enterprise vulnerability management program end to end — identification, risk-based prioritization, remediation, and executive reporting — backed by a career spanning MCI, EDS, and Verizon and fifteen years of people-leadership. Runs remediation across Infrastructure, Cloud, Application Development, DevOps, and IT Operations, pairing scanning-platform ownership with the governance discipline and threat-intelligence-driven prioritization that reduce real risk in large, distributed environments.

Track record of measurable enterprise risk reduction — cutting vulnerability exposure 57% (87,000 to 37,000 findings) and raising application security scanning compliance from 37% to 83% — through risk-based prioritization driven by asset criticality, exploitability, CVSS, and active-exploitation intelligence including the CISA KEV catalog.

Known for translating complex technical findings into business-focused risk decisions, building the metrics and reporting frameworks executives act on, and reporting honestly on posture rather than favorably.

CORE COMPETENCIES

Enterprise Vulnerability Management Program • Vulnerability Management Lifecycle • Risk-Based Prioritization & Remediation • Vulnerability Scanning Platforms (Tenable) • Threat Intelligence & CISA KEV Monitoring • CVSS & Exploitability Assessment • Remediation SLOs & Metrics • Exception & Risk-Acceptance Workflows • Executive Dashboards & KPI / KRI Reporting • Application Security (SAST / DAST / SCA) • Security Governance & Compliance • Incident Response Coordination • Cross-Functional Remediation Leadership • Team Leadership & Development

SELECTED ACHIEVEMENTS

•Reduced enterprise vulnerability exposure 57%, from approximately 87,000 findings to 37,000, through risk-based prioritization, remediation governance, and automated patch management strategy.

•Raised enterprise application security scanning compliance from 37% to 83% across the application portfolio, with the remaining gap formally documented through vendor source code and legacy application security exceptions.

•Quadrupled enterprise security KPI attainment within a single year, moving the organization from 2 goals met to 8, through metric governance, executive reporting, and sustained cross-functional engagement.

•Led enterprise response to a critical zero-day, running parallel exposure scoping and threat hunting workstreams to reduce more than 100 vulnerable libraries across 50 servers to 3.

•Directed a 24x7 technology organization supporting 33,000+ enterprise servers and 86 mainframe LPARs across geographically dispersed teams.

PROFESSIONAL EXPERIENCE

VERIZON

Continuous service bridged from MCI (1997) through EDS outsourcing and Verizon acquisition.

Principal Cybersecurity Engineer Verizon 2021 – 2026

Owned the enterprise vulnerability management program end to end — scanning operations, risk-based prioritization, remediation governance, and executive reporting — across servers, endpoints, network, applications, and databases, coordinating remediation with Infrastructure, Engineering, IT Operations, and Development.

•Reduced enterprise vulnerability exposure 57% — approximately 87,000 findings to 37,000 — through risk-based prioritization, remediation governance, stakeholder engagement, and automated patch management strategy.

•Owned SAST, DAST, and software composition analysis governance across the application portfolio using Fortify SSC, driving scanning compliance from 37% to 83% and formalizing the residual gap through documented vendor source code and legacy application security exceptions.

•Architected and implemented a vulnerability tracking and remediation database that gave application and infrastructure teams a single view of critical and aging findings, materially improving remediation visibility, ownership, and accountability.

•Established remediation SLOs and led recurring vulnerability review and remediation governance forums, managing exception and risk-acceptance workflows and escalating critical and overdue findings to leadership.

•Led enterprise response to the Log4Shell zero-day, directing two simultaneous workstreams — scanner-based exposure scoping across the server estate and Splunk-based threat hunting for JNDI exploit indicators — reducing more than 100 vulnerable libraries across 50 servers to 3.

•Root-caused post-remediation reintroduction of vulnerable libraries to CI/CD pipelines pulling cached dependencies, and drove pipeline-level correction to prevent recurrence.

•Designed executive cybersecurity scorecards, KPI frameworks, and risk intelligence reporting that gave leadership visibility into security posture, remediation effectiveness, and compliance performance.

•Accountable for enterprise security goal attainment across an assigned tower, quadrupling results within a single year — from 2 goals met in January to 8 by year end — through recurring accountability reviews, remediation tracking, and cross-functional collaboration with application and infrastructure teams.

•Conducted executive briefings and governance reviews, translating vulnerabilities, compliance gaps, and security findings into actionable business risk discussions and remediation strategy.

•Prioritized remediation by correlating Tenable scan data with CrowdStrike Falcon and Spotlight telemetry, CVSS, and active-exploitation intelligence — including the CISA KEV catalog — to drive effort by real-world risk rather than raw severity count.

•Performed metric validation and reporting quality assessments to surface data discrepancies and improve the accuracy of executive security reporting.

Manager, Server Engineering Support Verizon 2018 – 2021

•Directed a geographically dispersed 24x7 Level 2 systems administration organization supporting more than 33,000 enterprise servers.

•Championed enterprise adoption of automated patch management standards using BigFix, reducing manual patching effort and accelerating vulnerability remediation across the server estate.

•Led operational transformation initiatives that streamlined support processes, reduced incident recurrence, and improved escalation effectiveness.

•Served on enterprise Incident Review Committees, driving root cause analysis and corrective action that improved operational resiliency.

•Built and developed high-performing technical teams through leadership development, succession planning, and cross-functional training.

Manager, Mainframe Batch Operations Verizon 2015 – 2018

•Led the team accountable for enterprise batch processing operations supporting approximately 180 million annual application job executions across mission-critical business systems.

•Directed modernization initiatives spanning workload automation platforms, support model transformation, and process optimization.

•Monitored offshore mainframe access activity, identifying and resolving compliance exceptions related to privileged command usage and strengthening adherence to enterprise security and regulatory standards.

•Led organizational integration efforts that standardized operational process and improved enterprise service consistency.

EARLIER CAREER

Floor Manager, Application Batch Management — Verizon

Team Lead, Application Batch Management — EDS (Verizon acquisition)

Application Batch Management — MCI

CERTIFICATIONS & PROFESSIONAL DEVELOPMENT

•Certified Information Security Manager (CISM) — ISACA, in progress

•AI Governance Professional (AIGP) — IAPP, planned 2026

•ISO/IEC 42001 AI Management System Governance — in progress

•Cyber Advocate Program Graduate • 95+ hours advanced cybersecurity training

EDUCATION

Bachelor of Science, Cyber Security Management — graduated summa cum laude

TECHNOLOGIES, PLATFORMS & FRAMEWORKS

Vulnerability & Application Security: Tenable • Fortify (SAST / SSC) • OWASP ZAP • Sonatype • Black Duck • MAST

Monitoring & Endpoint: Splunk (SIEM) • CrowdStrike Falcon / Spotlight • BigFix

Governance, Risk & Compliance: NIST CSF • ISO/IEC 27001 • CIS Controls • SOX • SOC 2 • NIST AI RMF • ISO/IEC 42001

Reporting & Analytics: Grafana • Excel • ServiceNow Dashboards

ITSM & Infrastructure: ServiceNow • Windows • Linux • UNIX • Mainframe



Contact this candidate