
Director, Cyber Exposure – Vulnerability Management
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in Ohio.
• Oversee the enterprise vulnerability remediation program, which includes governance, reporting, escalation, and coordination with stakeholders.
• Collaborate with application, infrastructure, cloud, and security teams to facilitate timely risk mitigation.
• Set remediation priorities, performance metrics, and service-level expectations.
• Assist with audits, regulatory assessments, and enterprise risk governance activities.
• Lead the Exposure Analysis & Coordination function.
• Manage the enterprise response to zero-day vulnerabilities, emerging and pre-CVE threats, vendor advisories, third-party technology exposures, and cloud security risks.
• Foster cross-functional assessment, prioritization, mitigation tracking, and communication with executives.
• Ensure that significant exposure events are governed, documented, escalated, and resolved effectively.
• Conduct post-event reviews and implement operational enhancements.
• Convert vulnerability, threat, and exposure data into actionable risk decisions.
• Provide guidance to senior leaders on remediation priorities, business impact, and risk trade-offs.
• Develop strategies, roadmaps, metrics, and maturity objectives for remediation and exposure management.
• Create scalable operating processes, playbooks, and governance frameworks.
• Promote continuous improvement through Agile and Lean methodologies.
• Lead and nurture security engineers and analysts.
• Mentor emerging leaders and enhance organizational capabilities.
• A minimum of 10 years of experience in cybersecurity, technology risk, security operations, vulnerability management, or related fields.
• Experience in leading enterprise-scale remediation, risk reduction, security operations, or response coordination initiatives.
• In-depth knowledge of vulnerability management practices, risk prioritization methods, and cyber risk governance.
• Proven capability to lead large-scale cross-functional projects within complex organizations.
• Experience in presenting to senior leadership and executive audiences.
• Exceptional executive communication and stakeholder management abilities.
• Demonstrated skill in influencing outcomes without direct authority.
• Experience in managing teams, budgets, priorities, and strategic initiatives.
• Preferred: experience in a large regulated financial services organization and familiarity with FFIEC and PCI requirements.
• Preferred: background in supporting regulatory examinations, audits, and enterprise risk governance activities.
• Knowledge of vulnerability management, security analytics, asset management, GRC, and workflow management platforms.
• Experience with security in cloud, infrastructure, application, and third-party technologies.
• Experience working in Agile or SAFe environments.
• Relevant professional certifications such as CISSP, CISM, CRISC, GIAC, or equivalent are preferred.
• Incentive compensation plan based on company, line of business, and/or individual performance.
• Comprehensive benefits package.
• Competitive compensation offerings.
• Benefits that support physical, financial, emotional, and social well-being.
Pfizer
Workleap
GTIA - Global Technology Industry Association
AfterMath
Get handpicked remote jobs straight to your inbox weekly.