VP, Vulnerability Management & Threat Operations

United States, New York, New Jersey
Permanent
Job ID: 2559

Job Description


[Up to c. $325k Comp Package | Hybrid Working]


Role Overview

A major global financial institution is hiring a senior cyber security leader to take ownership of its enterprise vulnerability management capability while providing broader direction across threat hunting, attack-surface security, intelligence and adversary-led testing. This is not a traditional vulnerability reporting position - it's centred on actively reducing security exposure - taking issues from identification and prioritisation through engineering engagement, remediation and closure. You will work closely with security engineering, infrastructure, application and technology teams to ensure vulnerability and threat intelligence translates into stronger controls and measurable improvements to the organisation's risk position.

The role also carries leadership responsibility for a distributed group of approximately 20 permanent employees and consultants across the US, EMEA and India. Established people-management experience would be valuable, although an accomplished technical leader who has successfully directed sizeable teams and complex security programmes could also be highly relevant...


Key Responsibilities

  • Lead the enterprise vulnerability and exposure management capability across infrastructure, applications and cloud, covering scanning, analysis, prioritisation, patching, remediation tracking and risk visibility
  • Maintain ownership beyond initial identification, working directly with technology teams to ensure material vulnerabilities are addressed within appropriate risk and remediation thresholds
  • Convert vulnerability research and threat intelligence into defensive improvements by partnering with security engineering teams across SIEM, EDR/XDR, detection and preventative controls
  • Direct proactive security activity encompassing threat hunting, attack-surface analysis, purple-team exercises, internal testing, automated penetration testing and external cyber-risk monitoring
  • Bring together infrastructure, application, cyber security and business stakeholders through cross-functional programmes designed to accelerate remediation and remove systemic weaknesses
  • Define meaningful operational and risk metrics covering exposure, remediation performance, recurring weaknesses and the effectiveness of proactive security activity
  • Provide technical and organisational leadership to a geographically distributed team of approximately 19 security professionals and consultants
  • Use automation and modern AI-assisted capabilities where appropriate to improve vulnerability analysis, enrichment, prioritisation and workflow efficiency without compromising governance or human oversight


What You'll Bring...

  • 8+ years working within cyber security, with significant practical depth in vulnerability management alongside experience across areas such as threat hunting, attack-surface security, threat intelligence or offensive testing
  • Demonstrable ownership of enterprise-scale vulnerability programmes, including discovery, scanning, risk-based prioritisation, patching, remediation SLAs, escalation and reporting
  • Strong understanding of adversary-led security disciplines, ideally including threat hunting, purple teaming, attack-surface management, penetration testing or red-team activity
  • Experience providing leadership across technical security teams, programmes or major cross-functional initiatives; formal line-management experience is useful but not essential
  • Ability to work directly with security engineering and operations teams to convert vulnerabilities and emerging threats into improved detection, endpoint and preventative controls
  • Broad, platform-agnostic exposure to vulnerability and security technologies such as Qualys, Tenable, BitSight, SIEM, EDR/XDR and associated offensive or investigative tooling
  • Practical automation or scripting experience using Python, PowerShell or similar, combined with an interest in applying AI/LLM capabilities to security analysis and operational processes
  • Clear, credible communication with both technical and senior business stakeholders, coupled with a proactive approach focused on fixing security weaknesses rather than treating vulnerability management as a compliance exercise


...


Apply for this role

All fields marked with * are required.

I confirm I have a pre-existing right to work in the role’s location *
I require visa sponsorship now or will require it in the future

Back to Job Listings