The key difference to anti-virus systems, IDS/IPS installs and firewall solutions lies in the perspective. The latter focuses on recognizing attack patterns from inside out. Vulnerability management does the opposite: here, you view the IT infrastructure like an attacker would – from the outside looking in.
Penetration testing assumes a similar perspective, with one distinct difference. Its specific goal is to penetrate the corporate network and take over control. As soon as that is accomplished, the penetration test ends. All further flaws go unnoticed.
In contrast, vulnerability management aims at finding every single security gap. Where vulnerability assessment is a one-time security survey of the IT infrastructure, vulnerability management raises the entire level of security through one comprehensive process.