Role description
Who We Are
At UST, we help the world’s best organizations grow and succeed through transformation. Bringing together the right talent, tools, and ideas, we work with our clients to co-create lasting change. Together, with over 30,000 employees in 30+ countries, we build for boundless impact, touching billions of lives in the process. Visit us at UST.com.
Summary
We are seeking an experienced Scrum Master / POD Lead to lead a dedicated Vulnerability Remediation POD responsible for reducing Critical and High security vulnerabilities across enterprise applications. The successful candidate will drive planning, execution, governance, reporting, and stakeholder coordination while ensuring remediation activities are completed within established SLAs and security compliance requirements.
This role requires strong Agile delivery expertise, experience managing cross-functional technology teams, and a solid understanding of application security, vulnerability management, and software development lifecycles. The ideal candidate will effectively coordinate Developers, QA Engineers, Security Teams, Architects, Product Owners, and Application SMEs to deliver secure and compliant outcomes.
Key Responsibilities
POD Leadership & Delivery Management
- Champion an AI-first approach to delivery and operational efficiency.
- Lead the Vulnerability Remediation POD and drive end-to-end remediation programs.
- Manage intake, prioritization, planning, execution, and tracking of vulnerability remediation activities.
- Ensure Critical and High vulnerabilities are remediated within agreed SLA timelines.
- Facilitate Scrum ceremonies including daily stand-ups, sprint planning, backlog refinement, sprint reviews, and retrospectives.
- Coordinate remediation activities across multiple application portfolios, product teams, and technology platforms.
- Drive accountability and delivery excellence across the POD.
- Manage dependencies, impediments, and resource allocation to ensure successful delivery.
Agile Delivery & Program Governance
- Establish and maintain POD operating models, governance practices, and delivery frameworks.
- Monitor remediation backlog, throughput, velocity, cycle time, SLA adherence, and risk exposure.
- Develop and maintain dashboards, delivery metrics, and executive reporting.
- Provide regular status updates to technology leadership and key stakeholders.
- Escalate risks, blockers, capacity issues, and cross-functional dependencies proactively.
- Drive continuous improvement initiatives focused on delivery effectiveness and operational excellence.
Stakeholder Engagement & Collaboration
- Partner closely with Security Teams, Product Owners, Application Development Teams, QA Leads, Architects, and Platform Teams.
- Facilitate prioritization decisions based on security severity, business impact, and regulatory requirements.
- Coordinate testing, validation, deployment, and post-remediation verification activities.
- Ensure business objectives and remediation priorities remain aligned.
- Manage communications across multiple stakeholder groups and executive leadership.
Risk & Compliance Management
- Monitor remediation activities against vulnerability management policies and SLA commitments.
- Ensure audit readiness through proper documentation, evidence collection, and remediation tracking.
- Identify and mitigate delivery, operational, and security-related risks.
- Support compliance reviews, governance forums, and leadership decision-making processes.
- Ensure remediation activities meet security, regulatory, and organizational standards.
Continuous Improvement & Automation
- Drive Agile best practices and promote high-performing team behaviors.
- Use delivery metrics and KPIs to improve remediation predictability, quality, and velocity.
- Identify opportunities to automate vulnerability intake, reporting, and remediation workflows.
- Promote adoption of AI-enabled tools and automation solutions to improve productivity.
- Foster a culture of continuous learning, innovation, and operational excellence.
Required Skills
- Bachelor's Degree in Computer Science, Information Technology, Engineering, or equivalent experience.
- Minimum 5+ years of experience in Agile delivery, Scrum Master, Project Management, or Program Delivery roles.
- Minimum 2+ years of experience leading cross-functional technology teams.
- Experience managing enterprise application development, modernization, or transformation initiatives.
- Experience supporting security, compliance, or vulnerability remediation programs.
- Strong stakeholder management and communication skills.
- Experience operating within large-scale Agile environments.
Agile Delivery & Project Management Skills
Strong experience in:
- Scrum Framework
- Agile Project Management
- Kanban
- Sprint Planning & Execution
- Backlog Management
- Dependency Management
- Risk & Issue Management
- Release Planning
- Agile Metrics & Reporting
- Cross-Functional Team Leadership
- Continuous Improvement Practices
- Capacity Planning
- Team Facilitation & Coaching
Security & Vulnerability Management Skills
Strong understanding of:
- Application Security Fundamentals
- Vulnerability Management Lifecycle
- Secure Software Development Lifecycle (SSDLC)
- OWASP Top 10 and Security Best Practices
- Risk-Based Vulnerability Prioritization
- Security Governance & Compliance
- Security Remediation Programs
- Vulnerability Triage and Tracking
- Security Testing & Validation
Experience with security tools such as:
- Snyk
- SonarQube
- Veracode
- Checkmarx
- Microsoft Defender
- Security Scanning & Code Quality Platforms
Governance, Reporting & Collaboration Tools
- Jira
- Confluence
- Azure DevOps (Preferred)
- KPI & Dashboard Management
- Executive Reporting
- SLA Tracking & Compliance Reporting
- Risk Registers
- Power BI (Preferred)
- Microsoft Office Suite
Preferred Skills
- Certified Scrum Master (CSM)
- Professional Scrum Master (PSM)
- SAFe Scrum Master Certification
- SAFe Agilist Certification
- Experience within Financial Services, Insurance, Healthcare, or other regulated industries.
- Exposure to Java, .NET, Salesforce, Cloud, and Modern Application Platforms.
- Experience managing distributed and global delivery teams.
- Knowledge of DORA Metrics and Operational Excellence practices.
- Familiarity with DevSecOps principles and CI/CD environments.
- Experience with AI-driven delivery and productivity tools.
Key Competencies
- Strong leadership and team management skills.
- Excellent communication and executive stakeholder management.
- Strong analytical thinking and data-driven decision-making.
- Effective risk identification and mitigation capabilities.
- Ability to manage multiple priorities and competing demands.
- Strong problem-solving and conflict-resolution skills.
- Outcome-oriented and customer-focused mindset.
- Ability to influence without direct authority.
Success Measures
- Critical vulnerabilities remediated within established 48-hour SLA.
- High vulnerabilities remediated within established 7-day SLA.
- Reduction in overall vulnerability backlog across applications.
- Improved remediation throughput, predictability, and delivery efficiency.
- Timely and accurate executive reporting and governance updates.
- High stakeholder satisfaction across Security, Product, and Engineering teams.
- Effective collaboration across Application, Security, QA, and Platform teams.
- Minimal disruption to business delivery while maintaining security objectives.
What We Believe
We’re proud to embrace the same values that have shaped UST since the beginning. Since day one, we’ve been building enduring relationships and a culture of integrity. Today, those same values inspire us to encourage innovation from everyone, champion diversity and inclusion, and place people at the center of everything we do.
Humility
We will listen, learn, be empathetic, and help selflessly in our interactions with everyone.
Humanity
Through business, we will better the lives of those less fortunate than ourselves.
Integrity
We honour our commitments and act with responsibility in all our relationships.
Equal Employment Opportunity Statement
UST is an Equal Opportunity Employer. We believe that no one should be discriminated against because of their differences, such as age, disability, ethnicity, gender, gender identity and expression, religion, or sexual orientation.
All employment decisions shall be made without regard to age, race, creed, colour, religion, sex, national origin, ancestry, disability status, veteran status, citizenship status, sexual orientation, gender identity or expression, genetic information, marital status, or any other basis protected by applicable law.
UST reserves the right to periodically redefine your roles and responsibilities based on organizational requirements and/or performance.
- To support and promote the values of UST.
- Comply with all Company policies and procedures.
Skills
Skills
Scrum, Agile Delivery, Scrum Master, POD Lead, Vulnerability Management, Application Security, OWASP, SSDLC, Kanban, Jira, Confluence, Azure DevOps, Stakeholder Management, Risk Management, KPI Reporting, Executive Reporting, Security Compliance, Program Governance, Remediation Tracking, Project Management
About UST
UST is a global digital transformation solutions provider. For more than 20 years, UST has worked side by side with the world’s best companies to make a real impact through transformation. Powered by technology, inspired by people and led by purpose, UST partners with their clients from design to operation. With deep domain expertise and a future-proof philosophy, UST embeds innovation and agility into their clients’ organizations. With over 30,000 employees in 30 countries, UST builds for boundless impact—touching billions of lives in the process.