"Alerted.org

Job Title, Industry, Employer
City & State or Zip Code
20 mi
  • 0 mi
  • 5 mi
  • 10 mi
  • 20 mi
  • 50 mi
  • 100 mi
Advanced Search

Advanced Search

Cancel
Remove
+ Add search criteria
City & State or Zip Code
20 mi
  • 0 mi
  • 5 mi
  • 10 mi
  • 20 mi
  • 50 mi
  • 100 mi
Related to

  • Head of Vulnerability Management

    Truist (Richmond, VA)



    Apply Now

    The position is described below. If you want to apply, click the Apply Now button at the top or bottom of this page. After you click Apply Now and complete your application, you'll be invited to create a profile, which will let you see your application status and any communications. If you already have a profile with us, you can log in to check status.

     

    Need Help? (https://www.brainshark.com/bbandt/careers-site-faq)

     

    _If you have a disability and need assistance with the application, you can request a reasonable accommodation. Send an email to Accessibility ([email protected]?subject=Accommodation%20request)_

     

    _(accommodation requests only; other inquiries won't receive a response)._

    Regular or Temporary:

    Regular

    **Language Fluency:** English (Required)

    Work Shift:

    1st shift (United States of America)

    Please review the following job description:

    We are seeking an IT Vulnerability Management Leader to drive the strategy, processes, tooling, and execution of a comprehensive vulnerability management program within a regulated banking environment. This role will be responsible for ensuring proactive identification, assessment, remediation, and reporting of security vulnerabilities across the bank’s IT infrastructure, applications, and cloud environments.

     

    The ideal candidate will have deep expertise in vulnerability lifecycle management, risk-based prioritization, regulatory compliance (e.g., FFIEC, OCC, SOX, PCI-DSS), and automation to improve security posture while aligning with business objectives.

    ESSENTIAL DUTIES AND RESPONSIBILITIES

    Strategy & Governance

     

    Develop and lead the enterprise-wide vulnerability remediation team, aligning with cybersecurity, risk, and compliance frameworks.

     

    Establish policies, standards, and best practices for vulnerability identification, prioritization, and remediation.

     

    Align vulnerability management processes with FFIEC, OCC, GLBA, NIST, SOX, and PCI-DSS regulatory requirements.

     

    Collaborate with risk management, audit, and compliance teams to ensure regulatory reporting and risk mitigation strategies are met.

     

    Vulnerability Management Process

     

    Define and implement a risk-based vulnerability management lifecycle, including scanning, analysis, remediation, and validation.

     

    Develop and enforce Service Level Agreements (SLAs) for vulnerability remediation based on risk severity.

     

    Work with IT, DevOps, and engineering teams to integrate security patching and vulnerability remediation into operational workflows.

     

    Establish automated patching and compensating controls for high-risk vulnerabilities.

     

    Tooling & Automation

     

    Own the selection, implementation, and optimization of vulnerability management, and remediation tools.

     

    Leverage AI, automation, and security orchestration tools to accelerate vulnerability detection and remediation.

     

    Integrate vulnerability data with SIEM, ITSM, and risk management platforms for real-time visibility and response.

     

    Execution & Remediation Oversight

     

    Lead the end-to-end vulnerability detection, risk assessment, and remediation execution across cloud, on-premises, and third-party environments.

     

    Collaborate with IT infrastructure, application security, and DevSecOps teams to ensure timely patching, configuration hardening, and secure coding practices.

     

    Drive continuous improvement initiatives to enhance vulnerability detection, threat intelligence, and risk reduction.

     

    Risk-Based Prioritization & Reporting

     

    Develop and implement a risk-based vulnerability prioritization model using CVSS scores, threat intelligence, and business impact analysis.

     

    Establish executive-level dashboards and reporting on vulnerability trends, risk posture, and compliance adherence.

     

    Provide regular briefings to senior leadership, cybersecurity committees, and regulatory bodies.

     

    Incident Response & Crisis Management

     

    Act as a key stakeholder in security incident response, coordinating with SOC, threat intelligence, and forensics teams on vulnerability exploitation scenarios.

     

    Lead post-mortem analyses on critical vulnerabilities and breaches to strengthen future resilience.

    Required:

    10+ years of experience in IT security, vulnerability management, or cybersecurity risk management.

     

    Strong expertise in vulnerability management tools (e.g., Tenable, Qualys, Rapid7, ServiceNow VR, Prisma Cloud, AWS Security Hub).

     

    Experience in highly regulated banking environments, ensuring compliance with FFIEC, OCC, GLBA, SOX, PCI-DSS, NIST 800-53, and CIS benchmarks.

     

    Proven ability to develop and implement vulnerability management programs at an enterprise scale.

     

    Strong knowledge of cloud security vulnerabilities (AWS, Azure, GCP) and container security (Kubernetes, Docker).

     

    Experience working with patch management solutions, threat intelligence platforms, and security automation.

     

    Familiarity with risk-based vulnerability prioritization frameworks (e.g., EPSS, MITRE ATT&CK, CVSS v3+).

     

    Strong leadership and stakeholder management skills, with experience engaging CTO, CISO, CIO, and regulatory bodies.

     

    CISSP, CISM, OSCP, CRISC, or GIAC certifications.

     

    Hands-on experience integrating vulnerability data with SIEM, SOAR, and ITSM platforms.

     

    Knowledge of DevSecOps practices and secure CI/CD pipeline integration.

    Compliance and Regulatory Knowledge:

    In-depth understanding of compliance in regulated industries (e.g., financial services, healthcare).

     

    Experience working with audit and risk management processes.

    Stakeholder Engagement & Communication:

    Facilitate collaboration between application, infrastructure, and business teams to drive efficiency and innovation.

     

    Demonstrated ability to partner with line-of-business leaders, security teams, and developers to drive collaborative outcomes.

     

    Excellent communication and influence skills to balance business, technology, and compliance needs.

    QUALIFICATIONS

    Required Qualifications:

    The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

     

    1. Bachelor’s degree and 20 to 30 y ears related experience or equivalent combination.

    2. Managed Technology or Technology Process Teams for more than 15 years or teams of 30 or more technologists.

    3. Excellent knowledge of technical management and data governance.

    4. Knowledge of current trends in IT hardware and systems software field.

    5. Database management skills with the ability to produce reports.

    6. Familiarity with the support and troubleshooting of personal computers and tablet devices.

    7. Training ability and experience is a plus.

    8. The position requires strong problem solving and analytical skills with the ability to work independently and exercise sound judgment

    9. The ability to make commitments and be willing to be held accountable against them, organizing workloads to meet deadlines

    10. Exhibit adaptability to accept or bring about change when needed

    11. Strong written and verbal communication skills

    12. The ability to excel in a team environment and advance overall team objectives

    13. The ability to ensure customer satisfaction by delivering excellence in products and service

    14. Ability to work and communicate with peers, vendors, internal staff, including software program leadership and others

    15. Consistently demonstrate professional, positive, and approachable attitude, demeanor and discretion

    16. Demonstrate sensitivity in handling confidential information

    17. Formulate and clearly communicate ideas to others

    OTHER JOB REQUIREMENTS / WORKING CONDITIONS

    Sitting / Standing / Walking / Bending / Lifting

     

    Able to sit for extended periods of time and periodically move about during the work day.

     

    Visual / Audio / Speaking

     

    Able to access and interpret client information received from the computer and be able to hear and speak with individuals in person and on the phone

     

    Manual Dexterity / Keyboarding

     

    Able to work standard office equipment, including PC keyboard and mouse, copy/fax machines, and printers.

     

    Mental

     

    Able to focus, interpret information logically to solve problems, and answer customers’ questions appropriately.

     

    Availability

     

    Able to work all hours scheduled, including overtime as directed by manager/supervisor and required by business need.

     

    Travel

     

    Up to 50%

     

    Physical Conditions / Environment

     

    Normal office environment where there is little or no discomfort due to temperature, dust, noise, or other disagreeable elements.

     

    **General Description of Available Benefits for Eligible Employees of Truist Financial Corporation:** All regular teammates (not temporary or contingent workers) working 20 hours or more per week are eligible for benefits, though eligibility for specific benefits may be determined by the division of Truist offering the position. Truist offers medical, dental, vision, life insurance, disability, accidental death and dismemberment, tax-preferred savings accounts, and a 401k plan to teammates. Teammates also receive no less than 10 days of vacation (prorated based on date of hire and by full-time or part-time status) during their first year of employment, along with 10 sick days (also prorated), and paid holidays. For more details on Truist’s generous benefit plans, please visit our Benefits site (https://benefits.truist.com/)

    . Depending on the position and division, this job may also be eligible for Truist’s defined benefit pension plan, restricted stock units, and/or a deferred compensation plan. As you advance through the hiring process, you will also learn more about the specific benefits available for any non-temporary position for which you apply, based on full-time or part-time status, position, and division of work.

     

    _Truist is an Equal Opportunity Employer that does not discriminate on the basis of race, gender, color, religion, citizenship or national origin, age, sexual orientation, gender identity, disability, veteran status, or other classification protected by law. Truist is a Drug Free Workplace._

     

    EEO is the Law (https://www.eeoc.gov/sites/default/files/2022-10/EEOC\_KnowYourRights\_screen\_reader\_10\_20.pdf)

     

    Pay Transparency Nondiscrimination Provision (https://www.dol.gov/sites/dolgov/files/OFCCP/pdf/pay-transp\_%20English\_formattedESQA508c.pdf)

     

    E-Verify (https://e-verify.uscis.gov/web/media/resourcesContents/E-Verify\_Participation\_Poster\_ES.pdf)

     


    Apply Now



Recent Searches

  • Staff Engineer (United States)
  • Security Shift Supervisor (Nevada)
  • Partner Revenue Enablement Manager (Colorado)
  • Customer Service Greeter (California)
[X] Clear History

Recent Jobs

  • Head of Vulnerability Management
    Truist (Richmond, VA)
[X] Clear History

Account Login

Cancel
 
Forgot your password?

Not a member? Sign up

Sign Up

Cancel
 

Already have an account? Log in
Forgot your password?

Forgot your password?

Cancel
 
Enter the email associated with your account.

Already have an account? Sign in
Not a member? Sign up

© 2025 Alerted.org