Head of Vulnerability Management

Truist BankLakeway, TX
Onsite

About The Position

We are seeking an IT Vulnerability Management Leader to drive the strategy, processes, tooling, and execution of a comprehensive vulnerability management program within a regulated banking environment. This role will be responsible for ensuring proactive identification, assessment, remediation, and reporting of security vulnerabilities across the bank’s IT infrastructure, applications, and cloud environments. The ideal candidate will have deep expertise in vulnerability lifecycle management, risk-based prioritization, regulatory compliance (e.g., FFIEC, OCC, SOX, PCI-DSS), and automation to improve security posture while aligning with business objectives.

Requirements

  • Bachelor’s degree in Computer Science, Engineering, Information Systems, or related field.
  • Minimum of 10 years of professional experience in infrastructure engineering with progressive management responsibilities.
  • Proven experience managing a large team within a technology environment.
  • Strong knowledge of enterprise infrastructure technologies including cloud, network, database, storage, platform, computing, and middleware.

Nice To Haves

  • 10+ years of experience in IT security, vulnerability management, or cybersecurity risk management.
  • Strong expertise in vulnerability management tools (e.g., Tenable, Qualys, Rapid7, ServiceNow VR, Prisma Cloud, AWS Security Hub).
  • Experience in highly regulated banking environments, ensuring compliance with FFIEC, OCC, GLBA, SOX, PCI-DSS, NIST 800-53, and CIS benchmarks.
  • Proven ability to develop and implement vulnerability management programs at an enterprise scale.
  • Strong knowledge of cloud security vulnerabilities (AWS, Azure, GCP) and container security (Kubernetes, Docker).
  • Experience working with patch management solutions, threat intelligence platforms, and security automation.
  • Familiarity with risk-based vulnerability prioritization frameworks (e.g., EPSS, MITRE ATT&CK, CVSS v3+).
  • Strong leadership and stakeholder management skills, with experience engaging CTO, CISO, CIO, and regulatory bodies.
  • CISSP, CISM, OSCP, CRISC, or GIAC certifications.
  • Hands-on experience integrating vulnerability data with SIEM, SOAR, and ITSM platforms.
  • Knowledge of DevSecOps practices and secure CI/CD pipeline integration.
  • In-depth understanding of compliance in regulated industries (e.g., financial services, healthcare).
  • Experience working with audit and risk management processes.
  • Facilitate collaboration between application, infrastructure, and business teams to drive efficiency and innovation.
  • Demonstrated ability to partner with line-of-business leaders, security teams, and developers to drive collaborative outcomes.
  • Excellent communication and influence skills to balance business, technology, and compliance needs.

Responsibilities

  • Develop and lead the enterprise-wide vulnerability remediation team, aligning with cybersecurity, risk, and compliance frameworks.
  • Establish policies, standards, and best practices for vulnerability identification, prioritization, and remediation.
  • Align vulnerability management processes with FFIEC, OCC, GLBA, NIST, SOX, and PCI-DSS regulatory requirements.
  • Collaborate with risk management, audit, and compliance teams to ensure regulatory reporting and risk mitigation strategies are met.
  • Define and implement a risk-based vulnerability management lifecycle, including scanning, analysis, remediation, and validation.
  • Develop and enforce Service Level Agreements (SLAs) for vulnerability remediation based on risk severity.
  • Work with IT, DevOps, and engineering teams to integrate security patching and vulnerability remediation into operational workflows.
  • Establish automated patching and compensating controls for high-risk vulnerabilities.
  • Own the selection, implementation, and optimization of vulnerability management, and remediation tools.
  • Leverage AI, automation, and security orchestration tools to accelerate vulnerability detection and remediation.
  • Integrate vulnerability data with SIEM, ITSM, and risk management platforms for real-time visibility and response.
  • Lead the end-to-end vulnerability detection, risk assessment, and remediation execution across cloud, on-premises, and third-party environments.
  • Collaborate with IT infrastructure, application security, and DevSecOps teams to ensure timely patching, configuration hardening, and secure coding practices.
  • Drive continuous improvement initiatives to enhance vulnerability detection, threat intelligence, and risk reduction.
  • Develop and implement a risk-based vulnerability prioritization model using CVSS scores, threat intelligence, and business impact analysis.
  • Establish executive-level dashboards and reporting on vulnerability trends, risk posture, and compliance adherence.
  • Provide regular briefings to senior leadership, cybersecurity committees, and regulatory bodies.
  • Act as a key stakeholder in security incident response, coordinating with SOC, threat intelligence, and forensics teams on vulnerability exploitation scenarios.
  • Lead post-mortem analyses on critical vulnerabilities and breaches to strengthen future resilience.

Benefits

  • medical
  • dental
  • vision
  • life insurance
  • disability
  • accidental death and dismemberment
  • tax-preferred savings accounts
  • 401k plan
  • vacation
  • sick days
  • paid holidays
  • defined benefit pension plan
  • restricted stock units
  • deferred compensation plan
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service