Corporate Vice President - Head of Enterprise Vulnerability & Remediation

New York Life Insurance CoNew York, NY
$147,500 - $211,000Hybrid

About The Position

Lead the enterprise operating model for vulnerability and patch remediation across infrastructure, cloud, endpoints, and application-dependent services. This role will build and lead a centralized remediation function that converts vulnerability findings into measurable risk reduction through structured intake, prioritization, ownership assignment, accelerated patch execution, application validation, exception governance, and evidence-based closure. The role is accountable for driving remediation performance across multiple teams, including Patch & Vulnerability Ops, Endpoint Patching SRE, Infrastructure Patching SRE, App Remediation / SRE partners, Security, Cloud, DevOps, and CIO application teams. Success requires strong operating discipline, clear executive reporting, automation-first execution, and the authority to escalate blockers when remediation stalls. This leader will also guide the enterprise response to Mythos-related remediation priorities, including Critical VITs, High-priority vulnerabilities, AWS remediation, EOL OS modernization, browser/server hardening, and application regression testing automation.

Requirements

  • 12–15+ years of experience in IT Operations, Infrastructure, Security Engineering, Cloud Operations, SRE, or Enterprise Technology leadership.
  • 5+ years leading vulnerability management, patching, remediation, infrastructure operations, or enterprise reliability functions at scale.
  • Deep understanding of enterprise platforms, including Windows, Linux, endpoints, middleware, databases, AWS/cloud infrastructure, containers, and application-dependent services.
  • Experience with vulnerability and patching tools such as Qualys, Tanium, AWS Systems Manager Patch Manager, endpoint management platforms, CMDB, ITSM, and reporting dashboards.
  • Strong knowledge of patch management, change management, configuration management, exception governance, and evidence-based closure.
  • Experience coordinating application teams for testing, dependency remediation, code/configuration changes, release windows, and production sign-off.
  • Strong understanding of cloud remediation, EOL modernization, hardened images, Terraform, CI/CD, EKS, EC2, and DevOps operating models.
  • Demonstrated ability to influence senior stakeholders, drive accountability across organizational boundaries, and escalate unmanaged risk.
  • Strong executive communication skills with the ability to translate technical remediation risk into clear business impact and action plans.

Nice To Haves

  • Experience in financial services or another highly regulated industry.
  • Familiarity with NIST CSF, CIS Controls, SOX, NYDFS, PCI, or similar regulatory/control frameworks.
  • Experience with New Relic, synthetic monitoring, application regression automation, CI/CD test orchestration, and evidence capture.
  • Certifications such as CISSP, CISM, CRISC, CCSP, AWS, ITIL, or SRE-related credentials.
  • Experience building remediation factories, centralized vulnerability operations, or large-scale EOL modernization programs.

Responsibilities

  • Build and lead the centralized Enterprise Vulnerability & Remediation function across infrastructure, endpoint, cloud, and application-dependent services.
  • Define the end-to-end intake-to-closure workflow for vulnerabilities, patches, Critical VITs, zero-days, EOL remediation, and exception handling.
  • Establish severity-based remediation lanes, including: Same-day / P1 response for zero-days, 24-hour automated response for Critical VITs, 3-day cycle for High-priority patches, 6-day accelerated cycle for priority remediation.
  • Ensure every vulnerability has clear ownership, target dates, remediation plan, validation evidence, and closure disposition.
  • Drive daily operational governance and weekly executive reporting across remediation workstreams.
  • Oversee centralized vulnerability intake, prioritization, SLA tracking, remediation coordination, reporting, and escalation.
  • Ensure findings from Qualys, Tanium, cloud tools, security alerts, vendor advisories, and exception requests are triaged and routed to accountable owners.
  • Maintain enterprise dashboards for open vulnerabilities, aging, SLA adherence, exception status, rollback activity, automation coverage, and closure evidence.
  • Drive remediation discipline across platform, endpoint, cloud, and application teams.
  • Ensure vulnerabilities are not closed until validated through scan results, automated testing, system health checks, or approved risk acceptance.
  • Lead the endpoint patching reliability function responsible for endpoint patch execution, deployment waves, reboot compliance, endpoint health, and rollback coordination.
  • Standardize endpoint patching controls across pilot rings, production waves, user-impact monitoring, failed install tracking, and exception handling.
  • Ensure endpoint patching supports accelerated remediation timelines while maintaining controls for VPN, EDR, authentication, productivity tools, and user-impacting issues.
  • Partner with Endpoint Engineering, Service Desk, Security, and Operations teams to resolve endpoint patch failures and reduce repeat defects.
  • Lead the infrastructure patching reliability function across Windows, Linux, middleware, databases, cloud-hosted servers, and related platform services.
  • Establish lower-environment, canary, and production patching waves with clear go/no-go criteria.
  • Standardize patch baselines, maintenance windows, reboot strategy, rollback readiness, compensating controls, and patch failure handling.
  • Drive cloud patching execution through approved tools such as Qualys Patch Management, Tanium, AWS Systems Manager Patch Manager, and related automation platforms.
  • Ensure post-patch validation includes reboot success, service startup, monitoring agent health, scan validation, and closure evidence.
  • Partner with CIO application teams, DevOps, and SREs to ensure application readiness does not become a blocker to vulnerability remediation.
  • Establish structured application-team engagement for ownership confirmation, business criticality, testing windows, release constraints, reboot approvals, and production sign-off.
  • Drive application regression testing automation to reduce manual validation time and enable accelerated patch cycles.
  • Ensure application teams define smoke tests, API checks, service checks, transaction validation, dependency checks, and pass/fail criteria.
  • Support application-level remediation for libraries, middleware compatibility, certificates, runtimes, code fixes, configuration changes, and dependency upgrades.
  • Escalate application readiness, code/configuration, or sign-off delays that threaten Mythos, CBS, AWS remediation, EOL remediation, or Critical VIT timelines.
  • Lead remediation governance for AWS/cloud patching, including non-production rollout, production rollout, BAU transition, tool enablement, and execution risk management.
  • Oversee remediation blockers such as non-reporting agents, root-volume constraints, reboot dependencies, application/SRE coordination, and access limitations.
  • Coordinate EOL OS modernization strategy with platform, cloud, vendor, and application teams.
  • Ensure EOL remediation is tracked through fresh build, replatforming, hardened AMIs, Terraform automation, CI/CD pipelines, EKS for container-ready workloads, and EC2 for non-container workloads.
  • Drive executive visibility into EOL exposure, impacted applications, SLT ownership, modernization waves, and dependency risks.
  • Define the automation roadmap for patch deployment, health checks, application regression testing, scan validation, dashboards, and closure evidence.
  • Partner with DevOps and CIO teams to evaluate New Relic monitors, synthetic checks, service health dashboards, alert policies, and performance baselines as near-term accelerators for post-patch validation.
  • Ensure tooling supports vulnerability-informed remediation, automated deployment, compliance reporting, evidence capture, and closure workflows.
  • Drive integration across Qualys, Tanium, AWS Systems Manager, CI/CD platforms, CMDB, ITSM, monitoring tools, and reporting dashboards.
  • Define and enforce exception standards, including business justification, compensating controls, expiration dates, remediation commitments, and approval authority.
  • Challenge unsupported or open-ended exceptions.
  • Escalate missed deadlines, unresolved blockers, owner gaps, testing delays, and unmanaged risk through formal governance channels.
  • Ensure remediation issues move to one of the required outcomes: deploy, fix, roll back, compensate, exception, or validated closure.

Benefits

  • leave programs
  • adoption assistance
  • student loan repayment programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service