SVP, Exposure Management, Technology Group

GIC Private Limited•New York, NY
•$178,000 - $255,000•Hybrid

About The Position

The Technology Group (TG) is a key enabler to keep GIC's business moving forward and is constantly exploiting state-of-the-art information technologies to enhance GIC’s ability to be the leading global long-term investment firm. The Infrastructure Cybersecurity & Resilience (ICR) team's mission is to fortify GIC's infrastructure and cybersecurity capabilities by embedding security and resilience into everything they do, providing stable, secure and dependable services and solutions. The individual will be part of the Cybersecurity Assurance & Defence (CSAD) team and will play a key role in strengthening the firm’s security posture through proactive vulnerability management, adversarial attack simulation planning, and continuous improvement of security. The individual will serve as a control owner, driving threat prioritization, root cause analysis, and cross-team collaboration to remediate and prevent recurrence of vulnerabilities. This role will drive the strategic and operational excellence needed to safeguard GIC’s technology ecosystem. By leading efforts to identify, assess, and remediate vulnerabilities across infrastructure, applications, and cloud environments, the SVP will ensure proactive risk reduction and resilience against evolving cyber threats. The impact of this role will be seen in stronger enterprise-wide security posture, improved regulatory and compliance alignment, and enhanced confidence among stakeholders that critical assets are protected through timely, data-driven, and coordinated vulnerability management practices.

Requirements

  • 15+ years of experience in cybersecurity, with at least 7 years in senior leadership roles overseeing exposure and vulnerability management operations.
  • Proven experience establishing or maturing a threat exposure management or equivalent risk-based exposure management program at enterprise scale.
  • Deep understanding of regulatory environments, financial services operations, and technology risk management.
  • Proven track record of leading large-scale cybersecurity programs.
  • Expertise across the exposure management lifecycle — attack surface management, vulnerability management tools, exposure assessment and prioritization, penetration testing, continuous/automated validation (e.g., breach and attack simulation), threat intelligence, and the use of AI and automation technologies.
  • Strong grasp of risk-based prioritization, attack-path analysis, and exposure validation to focus remediation on genuinely exploitable, high-impact risk.
  • Strong communication and stakeholder management skills, with the ability to influence at various levels of the firm.
  • Degree in Computer Science, Information Security, or related field preferred; relevant certifications (SANS, OFFSEC, CISSP, CISM, CRISC, etc.) desirable.

Responsibilities

  • Define and execute the exposure and vulnerability management strategy, aligned with enterprise risk appetite, regulatory requirements, and business objectives.
  • Establish a forward-looking roadmap that operationalizes continuous threat management, integrating threat intelligence, security analytics, and automation to strengthen the discovery, prioritization, validation, and remediation of exposures.
  • Maintain continuous visibility of the enterprise attack surface — spanning external, cloud, on-premises, hybrid, and identity-based exposures — to move from reactive scanning to proactive exposure reduction.
  • Lead and govern scanning and assessment ensuring consistent standards, accuracy, timely mitigation, and transparent reporting.
  • Drive risk-based prioritization of vulnerabilities and exposures using threat context, exploitability, attack-path analysis, and business criticality — focusing remediation effort on what is genuinely exploitable and impactful.
  • Employ exposure validation techniques (e.g., attack path modelling, breach and attack simulation, and penetration testing) to confirm real-world risk and measure the effectiveness of controls.
  • Partner with technology teams to embed best practices into technology and orchestrate the mobilization and remediation of exposures across accountable owners.
  • Collaborate with risk and audit teams to align technical exposure and vulnerability management with broader risk management practices and act as a key point of contact for audit matters.
  • Communicate complex technical exposures to drive informed, risk-based decision-making at all levels of the firm.
  • Develop, update, and manage the firm's exposure, vulnerability, and security patch management standards.
  • Develop and track performance metrics, key risk indicators (KRIs), and key performance indicators (KPIs) to measure program maturity and impact.
  • Build and lead a high-performing team.
  • Drive continuous improvement of program processes, tooling, and automation to accelerate mean-time-to-remediate and reduce recurring exposures.
  • Stay abreast of global cybersecurity trends, emerging vulnerabilities, exploits, and regulatory developments.

Benefits

  • Competitive compensation package
  • Base salary range: $178,000 - $255,000
  • Bonus determined based on company and individual performance
  • Flexibility (teams come into the office four days per week, with flexibility to choose days and adjust arrangements)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service