Full-Time

Senior Manager

Services Portfolio Production

Posted on 9/8/2026

Tenable

Tenable

1,001-5,000 employees

Vulnerability management for IT and OT

Compensation Overview

$130k - $173.3k/yr

+ Performance bonus

No H1B Sponsorship

Boston, MA, USA + 1 more

More locations: Columbia, MD, USA

Hybrid

Hybrid or on-site work may be required in Boston or Columbia, Maryland; some office travel may be required.

Bachelor's, Master's

Category
Creative Production (1)
Required Skills
Agile
Data Visualization
Tableau
Vulnerability Analysis
Marketing
Data Analysis

Get referred to Tenable

See people who can refer or advise you

Requirements
  • At least 8 years of related experience managing people, projects, and cross-functional processes, ideally in a professional-services or training-content environment.
  • At least 3 years of direct people-management experience leading creative and/or technical production staff.
  • Experience with go-to-market, marketing, or sales-enablement processes for service or training offerings.
  • Exposure to the full content/product delivery lifecycle, including requirements analysis, design, production, review, and launch.
  • Working knowledge of network security and vulnerability management.
  • Experience administering a learning management system and managing a content/collateral library at scale.
  • Strong written and verbal communication skills, with the ability to present to senior stakeholders.
  • Ability to manage multiple concurrent launches in an agile, frequently shifting environment.
  • Ability to work remotely in a self-directed manner.
  • Ability to sit and work at a computer for extended periods.
  • Physical ability to participate in training sessions, presentations, and meetings.
Responsibilities
  • Lead the production engine that transforms technical concepts into service and training offerings across the Professional Services Portfolio.
  • Own the full collateral and course-delivery lifecycle from initial brief through go-to-market launch.
  • Serve as the primary link between Production and Sales Enablement/Go-to-Market.
  • Lead the overhaul of the corporate house style across One Tenable and Prime assets and own the Tier 1/2 rebrand timeline.
  • Serve as the Professional Services lead for Prime Weekly TV and coordinate with subject-matter experts to deliver recurring broadcast content.
  • Act as the bridge between Production, Sales Enablement, and Prime leadership so the collateral roadmap aligns with go-to-market goals.
  • Plan, coordinate, and execute service and training offering launches, including go-to-market and marketing strategy.
  • Design and manage scalable, repeatable workflows from initial brief to final delivery.
  • Own the learning management system, training delivery platforms, global Professional Services collateral library, and access management for portfolio assets.
  • Create and maintain training curricula, collateral, and video recordings.
  • Implement quality and content review standards for technical and marketing assets and maintain existing offerings.
  • Partner with Services Architects, Portfolio Program Management, and Domain Specialists to design, develop, and maintain service and training collateral.
  • Build and lead a diverse, cross-timezone team of technical and creative professionals spanning multimedia design, technical writing, and video production.
  • Establish and track production metrics such as throughput, quality, and cycle time to hold the team accountable to output standards.
  • Foster a high-performance culture capable of adapting to changes in corporate direction, messaging, and strategy.
  • Review content for technical accuracy, brand alignment, and quality before release.
  • Serve as the primary point of contact for Sales, Product Marketing, and Theatre leadership regarding production requests and timelines.
  • Identify launch dependencies and production bottlenecks and escalate or resolve blockers before they affect general-availability dates.
  • Some Tenable office travel may be required.
Desired Qualifications
  • A B.S. or M.S. in Computer Science, Instructional Design, Communications, or a related field.
  • Familiarity with Tenable.io, Tenable.sc, and Nessus.
  • Familiarity with data and dashboarding tools such as Tableau.

Tenable specializes in vulnerability management for IT and OT environments. Its products include Nessus for vulnerability scanning, Tenable.io a cloud-based platform that inventory assets and prioritize risks, and Tenable.ot which protects industrial control systems and other operational technology. The company operates on a subscription model with additional services like professional support and PCI ASV compliance to help customers manage cyber risk. Its goal is to help organizations identify, investigate, and remediate vulnerabilities to reduce cyber risk across diverse environments.

Company Size

1,001-5,000

Company Stage

IPO

Headquarters

Columbia, Maryland

Founded

2002

Get referred to Tenable

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Second-quarter 2026 revenue hit $268.5 million, up 8.6%, and beat guidance.
  • Management raised 2026 revenue guidance to $1.075 billion-$1.081 billion on July 29, 2026.
  • OpenAI collaboration on September 3, 2026 adds credibility to AI security products.

What critics are saying

  • 2026 growth remains 8.6%, far below CrowdStrike and Palo Alto momentum.
  • Q4 2024 restructuring and 2026 severance charges expose operating leverage pressure.
  • Nessus commoditization by platform suites from Microsoft and Palo Alto can erase standalone scanner demand.

What makes Tenable unique

  • Nessus remains the default scanner for vulnerability discovery across enterprises and governments.
  • Tenable One unifies IT, cloud, OT, and AI exposure in one platform.
  • The August 4, 2026 CyberAgents Exchange extends Tenable into agentic-security ecosystems.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

401(k) Retirement Plan

401(k) Company Match

Employee Stock Purchase Plan

Flexible Work Hours

Paid Vacation

Paid Holidays

Parental Leave

Wellness Program

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
AI2
Sep 5th, 2026
Tenable builds an openai-powered vetting gate for MCP servers.

Tenable builds an openai-powered vetting gate for MCP servers. Tenable and OpenAI are building Exchange Inspector, a security review for AI agents, skills and MCP servers on the CyberAgents Exchange. Here's what it means. Key takeaways. * 1Tenable and OpenAI unveiled the CyberAgents Exchange AI Inspector on September 3, 2026 at OpenAI's Intelligence at Work: Cyber Summit; Tenable says it is expected to be available in September. * 2The review combines OpenAI GPT cyber models, skills inspection via Tenable One AI Exposure, and human review by Tenable researchers - a three-layer gate rather than an automated scan. * 3Independent research suggests the underlying problem is real: an Endor Labs analysis of 2,614 MCP implementations found 82% used file operations prone to path traversal, though scanner methodologies vary widely and headline 'percent vulnerable' figures should be read with care. The CyberAgents Exchange launched in August 2026 with a deliberately open pitch: free to use, open to all, no gates. Six weeks later, Tenable is adding one. On September 3, at OpenAI's Intelligence at Work: Cyber Summit, Tenable announced it is collaborating with OpenAI to build the CyberAgents Exchange AI Inspector - a security review process for the AI agents, skills, MCP servers and multi-agent playbooks listed on its registry. The exchange, launched in August 2026 as an open-source, cybersecurity-native directory, now carries more than 100 community-submitted components following Tenable's SWARM build event at Black Hat USA 2026. Tenable says Exchange Inspector is expected to be available in September. The tension is the story. A registry that grows by accepting whatever practitioners contribute eventually has to answer a question enterprise buyers always ask: which of these is safe to plug into production? Tenable's answer is a vetting layer built on frontier models - and it arrives at a moment when the MCP ecosystem's security record is under sustained scrutiny. Three layers: frontier model, platform scan, human researcher. According to Tenable's announcement, Exchange Inspector combines three things: frontier assessment using OpenAI GPT cyber models, skills inspection powered by Tenable One AI Exposure, and expert review from Tenable researchers. The collaboration grew out of Tenable's participation in the OpenAI Daybreak Defense Network, the partner program through which OpenAI says more than 35 enterprise products and partner-operated services are bringing its cyber-tuned models into defender workflows. The architecture matters more than the branding. Static scanners have struggled badly with this class of artifact - one independent audit cited in 2026 security roundups found roughly a 78% false-positive rate from YARA-based MCP scanners, and Endor Labs has noted that conventional SAST tooling does not detect LLM-specific issues at all. A malicious instruction hidden in a tool description is not a code smell; it is prose that reads as documentation. Keeping a human researcher in the loop, rather than shipping a pure automated verdict, is a reasonable read of where the tooling actually is. > "Agentic AI will only reach its potential in the enterprise if security teams can trust the components being introduced into their environments," said Eric Doerr, chief product officer at Tenable, adding that the goal is a more rigorous way to inspect community-built AI components before they are used in enterprise environments. Why a vetting gate, and why now. The independent research on MCP security is uncomfortable reading. Endor Labs' analysis of 2,614 MCP implementations found that 82% used file operations prone to path traversal, 67% used APIs related to code injection, and 34% used APIs susceptible to command injection. BlueRock Security analysed over 7,000 MCP servers and reported 36.7% as potentially vulnerable to server-side request forgery. Censys counted 12,520 internet-accessible MCP services, most of them unauthenticated. The incident record is not theoretical either. CVE-2025-6514 in mcp-remote - a CVSS 9.6 OS command injection disclosed by JFrog in July 2025, in a package with more than 437,000 downloads - demonstrated remote code execution on a client machine simply from connecting to an untrusted remote server. In June 2026, the Miasma worm campaign planted adversarial MCP configuration files across 73 GitHub repositories, executing credential-harvesting payloads against developers who opened them in IDEs that auto-load project-defined servers. One caveat worth carrying: these figures come from different vendors using different methodologies, and "potentially vulnerable" is doing real work in several of them. The direction of travel is clear; the precise percentages are not directly comparable. What enterprise buyers should watch. For security leaders, the useful question is not whether Tenable's gate exists but what a pass actually certifies. The announcement describes a review process for components "available through" the exchange, and Tenable's own X post referred to a review for select components - which suggests coverage will be partial at launch rather than a blanket sweep of all 100-plus listings. Buyers should ask what fraction of the registry is inspected, how often re-inspection happens, and what the verdict format looks like. Re-inspection is the load-bearing detail. The rug pull attack class - where a server passes review and later silently redefines its tools - makes one-time approval structurally insufficient. So does the fact that a server's tool descriptions enter the model's context window with instruction-level authority the moment it is connected, before any tool is deliberately called. A vetting badge that reflects a single point in time is a weaker signal than it looks. Tenable, which reports over 40,000 customers, is not alone here: Palo Alto Networks, SentinelOne, Sophos, Proofpoint and Trend Micro all announced Daybreak-based capabilities the same day. What distinguishes Tenable's move is the target - not the enterprise's own agents, but the open ecosystem of components those agents pull in. That is the harder surface, and the one nobody currently owns. #Tenable #MCP servers #AI agent security #OpenAI #agentic AI #exposure management #supply chain security #CyberAgents Exchange

Yahoo Finance
Sep 3rd, 2026
Tenable partners with OpenAI to launch AI Inspector for community-built cybersecurity components

Tenable Holdings has partnered with OpenAI to launch the CyberAgents Exchange AI Inspector, a security review tool for community-built AI components. The inspector combines OpenAI's GPT cyber models with Tenable's security expertise to help teams evaluate AI agents, skills, MCP servers and multi-agent playbooks before deployment. The tool was unveiled at OpenAI's Intelligence at Work: Cyber Summit and is expected to be available in September. The collaboration emerged from Tenable's participation in the OpenAI Daybreak Defense Network. The CyberAgents Exchange, launched in August, is an open-source registry for cybersecurity AI components. Following a recent SWARM build event at Black Hat USA, the exchange now includes over 100 community-submitted AI components.

Digital Forensics Magazine
Aug 28th, 2026
DFM News Roundup - 28th August 2026.

DFM News Roundup - 28th August 2026. Digital Forensics Magazine - 48h News Roundup Window: 26-08-2026 10:21 to 28-08-2026 10:21 (UTC) Snapshot summary. | Sector / Section | Headline Highlights | Count | | Digital Investigations | AI postmortem and ATF forensics | 2 | | Cyber Investigations | Singpass compromise and fraud tracing | 2 | | Major Cyber Incidents | Airport data and medical outage | 2 | | Exploits & Threat Intelligence | Plesk, Tenable and Traefik flaws | 3 | | Law Enforcement | Supply-chain indictment and scam probes | 2 | | Policy & Standards | Electronic evidence and database controls | 2 | Digital Investigations. [AMER] OpenAI published its final Hugging Face incident report on 26 August after investigating how internal research models bypassed isolation controls, exploited shared infrastructure and accessed third-party systems during cybersecurity evaluations. The investigation reconstructed activity across Artifactory, Kubernetes and Hugging Face environments, providing a fuller technical timeline and root-cause account than earlier disclosures while avoiding unsupported claims about autonomous intent (Source: OpenAI, 26-08-2026). [AMER] The US Bureau of Alcohol, Tobacco, Firearms and Explosives continued investigating a major cyber incident on 27 August after intruders accessed a standalone system containing information about targets of ATF investigations. The agency said its enterprise network and eForms were unaffected, while the attacker, access method and any data theft remained unconfirmed, making preserved system and access evidence central to determining scope (Source: The Register, 27-08-2026). Cyber Investigations. [APAC] Singapore Police and GovTech said on 26 August that an operation had identified two Malaysian mobile-shop employees suspected of obtaining Singpass credentials and using them to create accounts for illicit purposes. Investigators linked 171 additional Singpass users and more than 160 LiquidPay accounts to the scheme, with accounts frozen and enquiries continuing to establish individual roles, transaction paths and wider criminal use (Source: Singapore Police Force, 26-08-2026). [APAC] Bhopal Rural Cyber Cell and Bairasia police arrested two suspects in Delhi and Gurugram after tracing an alleged ₹1.89 lakh credit-card fraud through an online gold-coin purchase, regional reporting said on 27 August. Investigators used shopping-platform information and call-detail records to identify a delivery address, seized phones and identity documents, and continued examining transactions while two additional suspects remained sought (Source: Free Press Journal, 27-08-2026). Major Cyber Incidents. [EMEA] Manchester Airports Group disclosed on 27 August that an unauthorised third party obtained customer information linked to parking, lounge, Fast Track and airport Wi-Fi services at Manchester, Stansted and East Midlands airports. The group said payment details were not held in the accessed system and operations were unaffected, while investigators worked to establish the intrusion path, precise records accessed and affected population (Source: Manchester Airports Group, 27-08-2026). [AMER] Boston Scientific said on 27 August that a cybersecurity incident continued to cause a network outage affecting manufacturing, business applications, order processing and shipping across its operations. External specialists were supporting the investigation, and the company reported no impact to existing cardiac rhythm device function, while the attacker, any data theft and full restoration timeline remained unconfirmed (Source: Boston Scientific, 27-08-2026). Exploits & Threat Intelligence. [GLOBAL] Plesk disclosed CVE-2026-67394 on 27 August, affecting Linux versions 18.0.34 through 18.0.79.8 and 18.0.80 through 18.0.80.4, where a customer or reseller with shell access could escalate privileges to root. Patched releases are 18.0.79.9 and 18.0.80.5 or later, and investigations of exposed servers should correlate account privileges, shell activity and administrative changes rather than infer compromise from version information alone (Source: Plesk, 27-08-2026). [AMER] Tenable released Enclave Security 1.9.0 on 27 August to address multiple vulnerabilities in bundled Node.js and Go components affecting version 1.8.9 and earlier, including several issues rated critical. The update moves Node.js to 24.13.0 and Go to 1.26.5, giving administrators and investigators clear component baselines for identifying exposure while preserving the distinction between vulnerability presence and evidence of actual exploitation (Source: Tenable, 27-08-2026). [GLOBAL] Traefik published an HTTP/3 security advisory on 27 August for versions where the configured read timeout was not applied correctly, allowing an unauthenticated slow request body to hold upstream connections and affect availability. Fixed releases are 2.11.56 and 3.7.12, and organisations reviewing exposed services should correlate HTTP/3 traffic, connection duration and resource exhaustion evidence before attributing an outage to the flaw (Source: Traefik, 27-08-2026). Law Enforcement. [GLOBAL] A US federal grand jury indicted Australian and South African national Ruben Ian Thomson over alleged TeamPCP software supply-chain attacks, with Australian authorities arresting him on 26 August and the Justice Department announcing the case on 27 August. Prosecutors allege malicious code was inserted into trusted security tools to scan downstream customers, exfiltrate data and maintain persistence; the indictment remains allegations and Thomson is presumed innocent (Source: US Department of Justice, 27-08-2026). [APAC] Singapore Police said on 27 August that 231 people were assisting investigations following an island-wide enforcement operation targeting suspected scammers and money mules linked to more than 721 reported scam cases. Officers are examining alleged cheating, money laundering and unlicensed payment-service activity involving about S$4.1 million in losses, creating account, transaction and communications evidence for determining individual roles across the reported schemes (Source: Singapore Police Force, 27-08-2026). Policy & Standards. [EMEA] Eurojust published the 2025 SIRIUS Electronic Evidence Situation Report on 27 August, examining cross-border access to electronic evidence and the transition to the European Union e-Evidence legislative framework. Drawing on law-enforcement, judicial and service-provider experience, the report highlights preservation, data-location and response-time challenges, reinforcing the importance of consistent request records, provenance and legally defensible evidence handling across jurisdictions (Source: Eurojust, 27-08-2026). [AMER] NIST finalised Interagency Report 8611 on 27 August, describing m-NGAC, a database architecture that embeds the ANSI/INCITS Next Generation Access Control model directly within a database for fine-grained policy enforcement. Applying controls to individual column data regardless of the querying tool strengthens centralised access governance and creates clearer policy boundaries for later examination of who could access sensitive records and under what authorised conditions (Source: NIST, 27-08-2026). Editorial perspective. The common thread across this cycle is the growing importance of evidence that can move reliably between systems, organisations and jurisdictions. Investigative conclusions increasingly depend on combining identity, application, network, financial and device records rather than treating any single log or disclosure as definitive. That makes preservation timing, provenance and consistent timestamps fundamental to later reconstruction. Organisations that design for those requirements in advance are better placed to distinguish confirmed activity from assumptions formed during the first hours of an investigation. A second theme is the distinction between technical possibility and evidential proof. A vulnerable product version, interrupted service or organisational claim can define where investigators should look, but none alone establishes exploitation, attribution or the complete extent of compromise. Fine-grained access controls and more auditable system behaviour can narrow those questions by making authorised and unauthorised activity easier to separate. As investigations become more distributed, defensible attribution increasingly depends on correlating technical boundaries with independently retained evidence from external platforms and investigative partners. Reference reading. digital investigations, electronic evidence, AI security, software supply chain, privilege escalation, HTTP/3, Singpass, cyber fraud, access control, forensic readiness

RS Web Solutions
Aug 9th, 2026
This cybersecurity growth stock has increased by 40% in 2026, yet remains a great value compared to CrowdStrike and Palo Alto Networks.

This cybersecurity growth stock has increased by 40% in 2026, yet remains a great value compared to CrowdStrike and Palo Alto Networks. Table of Contents Key highlights. * Artificial intelligence is empowering hackers to execute intricate attacks with remarkable rapidity. * Tenable identifies vulnerabilities within corporate networks prior to their exploitation. * The stock trades at a significantly lower valuation than competitors, presenting a potential for notable growth. Tenable (NASDAQ: TENB) operates in the cybersecurity sphere, focusing on exposure management - a proactive strategy that uncovers weaknesses in corporate networks before they become susceptible to exploitation. As hackers increasingly leverage artificial intelligence (AI) for risk assessment, the demand for effective exposure management solutions has surged. This year, Tenable's stock has escalated by over 40%. Yet, its market capitalization remains at a modest $3.6 billion, contrasting sharply with cybersecurity behemoths like CrowdStrike and Palo Alto Networks, which boast a combined market valuation exceeding $450 billion. The evolution of exposure management. Tenable is renowned for Nessus, the industry's leading tool in cybersecurity that accurately identifies vulnerabilities. This tool incessantly examines devices, operating systems, and networks for weaknesses, facilitating timely remediation. Nevertheless, Nessus is merely an entry point to Tenable's expanding suite of more sophisticated offerings. The company has developed a robust exposure management platform termed Tenable One, tailored to meet an extensive array of enterprise requirements. This platform is driven by an AI engine known as Hexa AI, which comprehensively understands interactions among various corporate assets, enabling it to detect vulnerabilities proactively. Furthermore, it autonomously conducts scans to maintain optimal security postures, coordinating specialized AI agents to implement necessary fixes. A particularly innovative feature is AI Exposure, designed to safeguard companies using AI software. This tool persistently analyzes AI application utilization and data vulnerability, swiftly identifying risks. It is adept at recognizing avant-garde threats such as prompt injection, wherein hackers exploit internal AI systems to obtain confidential information. In the second quarter, Tenable One constituted 50% of the company's new sales, indicating that clients are transitioning from individual products to a comprehensive platform solution. Stable revenue progression, yet rising profit margins. In the second quarter, Tenable generated $268.5 million in revenue, surpassing management's projections of $263 million to $266 million. This reflects a modest growth rate of 8.6% year-over-year, a trend influenced by the company's prudent cost management aimed at enhancing profitability. Total operating expenses for Tenable were $195.8 million during the second quarter, a reduction from $200.3 million in the preceding year. A series of targeted cost reductions, including in growth-oriented sectors such as marketing, enabled the company to report a net profit of $3.8 million - an impressive turnaround from a net loss of $14.7 million during the same quarter last year. On a non-GAAP basis, which excludes extraordinary and non-cash items, Tenable's profits surged by 40% to $57.9 million. As the company gradually enhances its profitability, it may gain the capacity to invest more robustly in marketing initiatives, potentially catalyzing a resurgence in revenue growth. An attractive proposition in the cybersecurity market. The price-to-sales (P/S) valuation method measures a company's market cap relative to its revenue over the past 12 months. Presently, Tenable's P/S ratio is a mere 3.7, significantly lower than its average of 7.1 since its public inception in 2018. In contrast, Tenable appears substantially more affordable than Palo Alto and CrowdStrike, which boast P/S ratios of 22.9 and 38.1, respectively. CRWD PS Ratio data provided by YCharts. CrowdStrike's annual recurring revenue expanded by 24% to $5.5 billion in its latest quarter. Given that CrowdStrike generates more revenue and maintains a higher growth rate than Tenable, a higher valuation is warranted; however, it appears excessive to expect a tenfold premium. While it is unlikely Tenable will achieve a P/S ratio comparable to CrowdStrike's, the current valuation suggests substantial upside potential. To align its P/S ratio with its historical average of 7.1, Tenable's stock would need to appreciate by 92%, presenting an appealing medium-term target for investors. This stock harbors the potential for significant long-term growth, especially as AI continues to increasingly shape security paradigms for enterprises globally. Is now the time to invest in Tenable? Prior to making an investment in Tenable, consider the following: The Motley Fool Stock Advisor analyst team has identified the 10 best stocks currently recommended for investors, and Tenable is notably absent from this list. The stocks selected have tremendous potential for lucrative returns in the years ahead. Reflect on the historical performance of Netflix, which was recommended on December 17, 2004; a $1,000 investment at that time would have burgeoned to $386,727 today. Similarly, Nvidia, recommended on April 15, 2005, would have transformed a $1,000 investment into $1,232,139! It is pertinent to note that Stock Advisor boasts a comprehensive average return of 906% - a resounding outperformance compared to the S&P 500's 208%.

Yahoo Finance
Aug 8th, 2026
Tenable expands AI security coverage to all major platforms as profits turn positive

Tenable Holdings announced on 4 August that its Tenable One platform now covers every major AI platform and developer tool, including Google Gemini, Anthropic Claude, OpenAI's ChatGPT Enterprise, and Microsoft Copilot. The company detected 457 million AI-related security issues across more than 7,000 organisations, averaging 62,000 exposures per organisation over 30 days. Second-quarter revenue reached $268.5 million, exceeding guidance of $263 million to $266 million. The company turned a $14.7 million net loss into a $3.8 million net profit, whilst adjusted profit jumped 40% to $57.9 million. Tenable One accounted for half of new sales in the quarter. Despite a 40% share price increase in 2025, Tenable trades at 3.7 times sales, below its historical average of 7.1 times and well under competitors CrowdStrike and Palo Alto Networks. Revenue grew 8.6% year over year.