Senior Vulnerability & Security Engineer

Brown Brothers Harriman & Co•Jersey City, NJ

About The Position

At BBH, Partnership is more than a form of ownership—it’s our approach to business and relationships. We know that supporting your professional and personal goals is the best way to help our clients and advance our business. We take that responsibility seriously. With a 200-year legacy and a shared passion for what’s next, this is the right place to build a fulfilling career. Reporting to the Head of Vulnerability Management within the Cybersecurity team, we are seeking a Senior Vulnerability & Security Engineer to lead the advancement of the organization's vulnerability management and security configuration programs. This is a technical cybersecurity role responsible for identifying, assessing, prioritizing, and managing security exposures across the enterprise. The successful candidate will combine strong engineering expertise with risk-based analysis to evaluate vulnerabilities and security configuration weaknesses, determine their business impact, and drive effective remediation and mitigation strategies. As a key subject matter expert, this individual will partner closely with infrastructure, cloud, application development, engineering, and security teams to improve the organization's security posture. The role requires the ability to translate complex technical findings into clear business risk insights and actionable recommendations for technical and non-technical stakeholders. In addition, this role will be responsible for engineering and continuous enhancement of the enterprise security configuration capabilities, including the development of security baselines, compliance monitoring, automated assessment capabilities, and remediation processes. The role will ensure configuration management practices are integrated with broader vulnerability management processes to provide a holistic view of cyber risk.

Requirements

  • 7+ years of cybersecurity experience, preferably within financial services or another highly regulated industry.
  • Strong technical knowledge of enterprise infrastructure, operating systems, networking, databases, applications, and cloud platforms.
  • Demonstrated experience analyzing vulnerabilities, assessing risk, and developing remediation strategies.
  • Experience engineering and operating enterprise vulnerability management and security configuration management programs.
  • Experience with vulnerability exception processes, compensating controls, risk acceptance methodologies, and remediation governance.
  • Strong understanding of cybersecurity frameworks, regulations, and industry practices, including NIST, ISO 27001, OWASP, NYDFS Part 500, DORA, CIS and STIG.
  • Experience interpreting cybersecurity control requirements and evaluating compliance with organizational standards.
  • Strong analytical, problem-solving, stakeholder management, communication, and influencing skills.
  • Ability to communicate complex technical issues effectively to both technical and business audiences.

Nice To Haves

  • CISSP or equivalent
  • Experience in automation and scripting (PowerShell, Python, or similar) to improve vulnerability and configuration management processes.
  • Advanced PowerPoint and Excel skills, including development of executive-level risk reporting, dashboards, metrics, and presentations.

Responsibilities

  • Analyze vulnerabilities identified through enterprise vulnerability scanning, endpoint detection and response (EDR) platforms, application security testing, penetration testing, and threat intelligence sources.
  • Conduct technical analysis of CVEs, vendor advisories, and threat intelligence to assess affected technologies, exploitability, attack vectors, business impact, and available mitigation options.
  • Evaluate vulnerabilities using both technical and business context to differentiate between vulnerabilities that represent material business risk and those that can be effectively managed through compensating controls.
  • Provide risk-based recommendations to support remediation planning, exception management, and cybersecurity governance processes.
  • Partner with infrastructure, cloud, application, platform, and engineering teams to develop effective remediation strategies.
  • Assess the effectiveness of proposed mitigations and determine whether residual risk remains acceptable.
  • Identify alternative remediation approaches when immediate patching or correction is not feasible.
  • Review, assess, and provide recommendations regarding vulnerability exceptions requests.
  • Design, implement, and continuously improve capabilities supporting the enterprise vulnerability and security configuration management programs.
  • Develop and maintain secure configuration baselines aligned with organizational standards and industry frameworks.
  • Engineer automated solutions to assess, monitor, measure, and report on configuration compliance across enterprise environments.
  • Integrate configuration assessment findings with vulnerability management workflows to improve risk visibility and prioritization.
  • Evaluate emerging technologies, tools, and methodologies to enhance vulnerability and configuration management capabilities.
  • Serve as the technical escalation point and subject matter expert for vulnerability and configuration management issues.
  • Provide technical leadership, mentorship, and guidance to cybersecurity team members.
  • Maintain awareness of emerging threats, vulnerabilities, exploitation techniques, and industry best practices.

Benefits

  • discretionary bonuses
  • profit-sharing
  • long-term savings
  • healthcare
  • income protection
  • professional development opportunities
  • time off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service