ForgeApply
Try it free

ForgeApply · Job listing

Director, Vulnerability Management

Finastra

Atlanta, USonsite

See all 46 open roles at Finastra

Tailor your resume for this Finastra job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Finastra's site. Free trial, no card required.

About this role

Who are we?

At Finastra, we’re a global leader in financial services software, dedicated to expanding access to financial services and shaping what’s next for the industry. Our technology powers mission‑critical solutions across Lending, Payments and Universal Banking, supporting over 7,000 customers, including 80% of the world’s top 50 banks, in more than 110 countries.

Position Overview  

We are   seeking   an experienced and strategic   Director of Vulnerability Management   to lead the organization's efforts to   identify , prioritize, remediate, and govern cybersecurity vulnerabilities across infrastructure, cloud environments, applications, and internally developed products.  

This leader will   be responsible for   advancing a mature, risk-based vulnerability management program while partnering closely with Engineering, Product, Architecture, Infrastructure, DevOps, and Security Operations teams to embed security throughout the software development lifecycle. The successful candidate will combine strong technical   expertise , program leadership, and stakeholder management skills to reduce enterprise risk and enable secure business growth.  

Key Responsibilities  

Enterprise Vulnerability Management  

• Own and mature the enterprise vulnerability management program across infrastructure, endpoints, cloud platforms, applications, containers, and third-party technologies.  

• Establish risk-based prioritization methodologies that consider exploitability, business criticality, threat intelligence, and asset exposure.  

• Define and   maintain   vulnerability management standards, operational procedures,   remediation   SLAs, exception processes, and governance frameworks.  

• Drive accountability for remediation efforts and ensure   timely   resolution of critical and high-risk vulnerabilities.  

• Lead executive reporting and board-level metrics related to vulnerability exposure, remediation performance, and cyber risk reduction.  

• Coordinate enterprise response efforts for critical vulnerabilities, zero-day threats, and actively exploited security issues.  

Program Governance & Risk Management  

• Collaborate with Risk, Compliance, Audit, Privacy, and Legal teams to ensure alignment with regulatory and industry requirements.  

• Manage vulnerability exception processes and risk acceptance frameworks.  

• Support regulatory examinations, customer security assessments, internal audits, and external audits.  

• Develop and   maintain   meaningful KPIs and KRIs that   demonstrate   program effectiveness and risk reduction.  

Leadership & Organizational Development  

• Build, lead, and mentor a high-performing team of vulnerability management   professionals.  

• Foster strong partnerships across Engineering, Infrastructure, Operations, and business leadership teams.  

• Establish a culture of accountability, collaboration, innovation, and continuous improvement.  

• Provide strategic guidance and subject matter   expertise   to executive leadership on emerging threats, vulnerability trends, and secure product development practices.  

Required Qualifications  

Education  

• Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or   a related   discipline.  

• Equivalent   combination of education and relevant experience will be considered.  

Experience  

• Progressive cybersecurity experience, including vulnerability management, application security, product security, or related security disciplines.  

• Leadership experience managing security teams, programs, or enterprise initiatives.  

• Demonstrated success leading vulnerability management programs in large-scale enterprise environments.  

• Experience partnering with software engineering organizations and implementing secure development practices.  

• Strong background in cyber risk management, governance, and executive communications.  

Technical Expertise  

• Deep understanding of vulnerability management frameworks, CVSS, exploitability analysis, threat intelligence integration, and remediation prioritization.  

• Strong knowledge of secure software development practices and application security principles.  

• Experience with vulnerability management and application security platforms such as Tenable, Qualys, Rapid7, Wiz, Prisma Cloud, Microsoft Defender, GitHub Advanced Security,   CodeQL , Veracode,   Checkmarx , or similar solutions.  

• Familiarity with cloud environments, containers, Kubernetes, CI/CD pipelines, APIs, and modern software architectures.  

• Ability to communicate technical risks effectively to both technical and non-technical audiences.  

Certifications (Preferred)  

• CISSP  

• CISM  

• Relevant cloud security certifications  

Preferred Qualifications  

• Experience leading Product Security or   DevSecOps   transformation initiatives.  

• Experience implementing secure-by-design principles within enterprise software development environments.  

• Familiarity with software supply chain security and emerging secure software development regulations.  

• Experience supporting highly regulated industries, including financial services, healthcare, insurance, or critical infrastructure sectors.  

• Experience   leveraging   automation and AI-driven security capabilities to improve vulnerability management and security operations.  

Leadership Competencies  

The ideal candidate will   demonstrate :  

• Strategic thinking and business acumen.  

• Strong executive presence and communication skills.  

• Ability to influence without direct authority.  

• Data-driven decision-making and risk prioritization.  

• Effective stakeholder management across technical and business functions.  

• A commitment to talent development, inclusiveness, and continuous improvement.  

Success Measures  

Success in this role will be measured through:  

• Reduction of enterprise vulnerability exposure and risk.  

• Improvement

Salary insight

This posting doesn't disclose pay. Across 712 Atlanta jobs with disclosed salaries on ForgeApply, the median is $131k.

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Tailor your resume for this Finastra role before you apply.

Tailor my resume for this job

Similar jobs

Free ATS checker · No Salary on the Job Posting? How to Find the Number Before You Interview