... Director leads the firm's global resilience testing, exercising and vulnerability management capability. The role is accountable for establishing the enterprise framework, strategy and annual ...
... Director leads the firm's global resilience testing, exercising and vulnerability management capability. The role is accountable for establishing the enterprise framework, strategy and annual ...
Senior Vulnerability Management Analyst
Springfield, VA · On-site
$107K - $125K/yr
... direct support of the war fighter and their missions. We are seeking a creative and driven ... Conduct and Manage ACAS Vulnerability Scanning, including Tenable.sc, Nessus Agent and Nessus ...
Senior Vulnerability Management Analyst
Springfield, VA · On-site
$107K - $125K/yr
... direct support of the war fighter and their missions. We are seeking a creative and driven ... Conduct and Manage ACAS Vulnerability Scanning, including Tenable.sc, Nessus Agent and Nessus ...
Vulnerability Analyst
Charleston, WV · Remote
Direct experience supporting vulnerability management in at least two of the following cloud providers: AWS, Azure, GCP * Background working within at least one compliance framework (for example ...
Quick apply
Vulnerability Analyst
Charleston, WV · Remote
Direct experience supporting vulnerability management in at least two of the following cloud providers: AWS, Azure, GCP * Background working within at least one compliance framework (for example ...
Testing, Exercising & Vulnerability Management, Managing Director
Boston, MA · On-site
$170K - $252K/yr
... Director leads the firm's global resilience testing, exercising and vulnerability management capability. The role is accountable for establishing the enterprise framework, strategy and annual ...
Testing, Exercising & Vulnerability Management, Managing Director
Boston, MA · On-site
$170K - $252K/yr
... Director leads the firm's global resilience testing, exercising and vulnerability management capability. The role is accountable for establishing the enterprise framework, strategy and annual ...
Enterprise Vulnerability Management Lead SME with Security Clearance
Fairfax, VA · On-site
$174K - $189K/yr
The Enterprise Vulnerability Management Lead SME serves as the principal authority for vulnerability lifecycle management across WDP's classified and unclassified enterprise environments, directing ...
Enterprise Vulnerability Management Lead SME with Security Clearance
Fairfax, VA · On-site
$174K - $189K/yr
The Enterprise Vulnerability Management Lead SME serves as the principal authority for vulnerability lifecycle management across WDP's classified and unclassified enterprise environments, directing ...
The Consulting Director, Attack Surface Management defines strategy, adoption, and governance of automation, AI, and agentic AI across application security, vulnerability management, ethical hacking ...
The Consulting Director, Attack Surface Management defines strategy, adoption, and governance of automation, AI, and agentic AI across application security, vulnerability management, ethical hacking ...
Our Vulnerability Management team plays a pivotal role in identifying, assessing, and mitigating ... direct authority. What you should have: * U.S. Citizenship or Permanent Residency (Green Card ...
Our Vulnerability Management team plays a pivotal role in identifying, assessing, and mitigating ... direct authority. What you should have: * U.S. Citizenship or Permanent Residency (Green Card ...
Our Vulnerability Management team plays a pivotal role in identifying, assessing, and mitigating ... direct authority. What you should have: * U.S. Citizenship or Permanent Residency (Green Card ...
Our Vulnerability Management team plays a pivotal role in identifying, assessing, and mitigating ... direct authority. What you should have: * U.S. Citizenship or Permanent Residency (Green Card ...
Our Vulnerability Management team plays a pivotal role in identifying, assessing, and mitigating ... direct authority. What you should have: * U.S. Citizenship or Permanent Residency (Green Card ...
Our Vulnerability Management team plays a pivotal role in identifying, assessing, and mitigating ... direct authority. What you should have: * U.S. Citizenship or Permanent Residency (Green Card ...
SOC Vulnerability Management ACAS Lead - Senior
Fairfax, VA · On-site
$105K - $143K/yr
... directing scan planning, execution, validation, and reporting across supported ARNG enterprise ... Coordinate vulnerability management activities with SOC functions and enterprise cyber operations ...
SOC Vulnerability Management ACAS Lead - Senior
Fairfax, VA · On-site
$105K - $143K/yr
... directing scan planning, execution, validation, and reporting across supported ARNG enterprise ... Coordinate vulnerability management activities with SOC functions and enterprise cyber operations ...
Our Vulnerability Management team plays a pivotal role in identifying, assessing, and mitigating ... direct authority. What you should have: * U.S. Citizenship or Permanent Residency (Green Card ...
Our Vulnerability Management team plays a pivotal role in identifying, assessing, and mitigating ... direct authority. What you should have: * U.S. Citizenship or Permanent Residency (Green Card ...
Our Vulnerability Management team plays a pivotal role in identifying, assessing, and mitigating ... direct authority. What you should have: * U.S. Citizenship or Permanent Residency (Green Card ...
Our Vulnerability Management team plays a pivotal role in identifying, assessing, and mitigating ... direct authority. What you should have: * U.S. Citizenship or Permanent Residency (Green Card ...
Our Vulnerability Management team plays a pivotal role in identifying, assessing, and mitigating ... direct authority. What you should have: * U.S. Citizenship or Permanent Residency (Green Card ...
Our Vulnerability Management team plays a pivotal role in identifying, assessing, and mitigating ... direct authority. What you should have: * U.S. Citizenship or Permanent Residency (Green Card ...
Senior Vulnerability Reporting Analyst
Miami, FL · On-site
$115K/yr
Direct HIre Compensation: $115,000 Work Requirements: US Citizen, GC Holders or Authorized to Work ... The Senior Vulnerability Management Reporting Analyst serves as a key contributor within the ...
Senior Vulnerability Reporting Analyst
Miami, FL · On-site
$115K/yr
Direct HIre Compensation: $115,000 Work Requirements: US Citizen, GC Holders or Authorized to Work ... The Senior Vulnerability Management Reporting Analyst serves as a key contributor within the ...
Vice President - Technology (Vulnerability Management & Security Engineering)
New York, NY · On-site
$196K - $253K/yr
Provide leadership and mentorship to junior security team members; manage and direct external teams as needed. Engineering * Support and maintain the vulnerability management platform infrastructure ...
Vice President - Technology (Vulnerability Management & Security Engineering)
New York, NY · On-site
$196K - $253K/yr
Provide leadership and mentorship to junior security team members; manage and direct external teams as needed. Engineering * Support and maintain the vulnerability management platform infrastructure ...
The Analyst, Vulnerability Management - Cloud supports JetBlue's vulnerability management program ... direct exposure, strengthen compensating controls, and improve cloud security visibility. Other ...
The Analyst, Vulnerability Management - Cloud supports JetBlue's vulnerability management program ... direct exposure, strengthen compensating controls, and improve cloud security visibility. Other ...
Analyst Sr., Vulnerability Reporting
Miami, FL · On-site
$84K - $111K/yr
The Senior Vulnerability Management Reporting Analyst serves as a key contributor within the ... manager and below level start with 14 days/year; director and above level start with 19 days/year.
Analyst Sr., Vulnerability Reporting
Miami, FL · On-site
$84K - $111K/yr
The Senior Vulnerability Management Reporting Analyst serves as a key contributor within the ... manager and below level start with 14 days/year; director and above level start with 19 days/year.
The Lead will manage a comprehensive vulnerability management program for The Department of U.S. Customs and Border Protection (CBP). The Lead will direct a team of analysts responsible for ...
The Lead will manage a comprehensive vulnerability management program for The Department of U.S. Customs and Border Protection (CBP). The Lead will direct a team of analysts responsible for ...
Analyst Sr., Vulnerability Reporting
$84K - $111K/yr
The Senior Vulnerability Management Reporting Analyst serves as a key contributor within the ... manager and below level start with 14 days/year; director and above level start with 19 days/year.
Analyst Sr., Vulnerability Reporting
$84K - $111K/yr
The Senior Vulnerability Management Reporting Analyst serves as a key contributor within the ... manager and below level start with 14 days/year; director and above level start with 19 days/year.
The Lead will manage a comprehensive vulnerability management program for The Department of U.S. Customs and Border Protection (CBP). The Lead will direct a team of analysts responsible for ...
The Lead will manage a comprehensive vulnerability management program for The Department of U.S. Customs and Border Protection (CBP). The Lead will direct a team of analysts responsible for ...
Director Vulnerability Management information
What are some common challenges faced by a Director of Vulnerability Management, and how can they be addressed?
Can I make $200,000 a year in cyber security?
Can you make $500,000 a year in cyber security?
What does a Director of Vulnerability Management do?
Who is Trump's director of cyber security?
Is 40 too old for cyber security?
What are the key skills and qualifications needed to thrive as a Director of Vulnerability Management, and why are they important?
What is the difference between Director Vulnerability Management vs Security Manager?
| Aspect | Director Vulnerability Management | Security Manager |
|---|---|---|
| Primary Focus | Overseeing vulnerability assessment and remediation strategies | Managing overall security policies and team operations |
| Certifications | Certifications like CISSP, CISA, GIAC | Certifications like CISSP, CISM, CompTIA Security+ |
| Work Environment | Security teams, vulnerability scanning tools, incident response | Security teams, policy development, risk management |
| Industry Usage | Common in large enterprises with dedicated vulnerability teams | Widespread across organizations managing overall security |
The main difference is that the Director Vulnerability Management focuses specifically on identifying and addressing security vulnerabilities, while the Security Manager oversees broader security policies and team management. Both roles require similar certifications and work in security-focused environments, but their scope and responsibilities differ.
Testing, Exercising & Vulnerability Management, Managing Director
Boston, MA
$170K - $252K/yr
Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 5 days ago
Job description
Role Purpose
The Managing Director leads the firm's global resilience testing, exercising and vulnerability management capability. The role is accountable for establishing the enterprise framework, strategy and annual programme, ensuring a risk-based, regulator-ready approach that identifies vulnerabilities, drives remediation and strengthens resilience across critical business services, functions and third-party dependencies.
The role provides enterprise-wide oversight of testing activities and operates a Centre of Excellence to support consistent execution across business and functional teams, while driving continuous improvement through innovation, automation and AI.
Key Responsibilities
Framework, Strategy & Governance
- Define and maintain global frameworks, standards, methodologies and controls
- Establish consistent approaches to scenario design, execution, reporting and remediation
- Lead the annual testing strategy aligned to critical services, risks and dependencies
- Ensure robust governance across central and federated testing activities
Global Testing & Exercising Programme
- Design and deliver a global, risk-based testing programme
- Ensure coverage across business services, operations, technology, cyber and third parties
- Oversee full lifecycle of exercises (planning, execution, evaluation, follow-up)
- Deliver diverse and realistic testing (e.g. crisis simulations, cross-functional exercises, severe-but-plausible scenarios)
Vulnerability Management & Remediation
- Own identification, analysis and reporting of vulnerabilities from testing activities
- Ensure actionable remediation plans with clear ownership, timelines and prioritisation
- Drive root cause analysis and identification of systemic issues
- Track closure and escalate delays or recurring deficiencies
Centre of Excellence & Advisory
- Provide standards, tools, templates and guidance across the enterprise
- Offer expert challenge, advisory and quality assurance
- Build capability and promote consistency across business-led testing
Policy, Compliance & Assurance
- Ensure alignment with internal policies, governance and regulatory expectations
- Partner with risk, compliance and audit functions
- Maintain audit-ready documentation, reporting and evidence
Innovation, Tooling & AI
- Drive adoption of automation, workflow tools and AI
- Enhance data capture, reporting, analytics and action tracking
- Support a scalable, data-driven testing capability
Emerging Risks & External Developments
- Incorporate emerging threats, cyber risks and geopolitical developments into scenarios
- Monitor regulatory and industry practices
- Continuously evolve methodologies and testing approaches
Stakeholder & Regulatory Engagement
- Engage senior stakeholders, regulators, clients and third parties
- Present programme outcomes, vulnerabilities and remediation priorities
- Drive enterprise ownership, participation and accountability
Leadership
- Lead and develop a global team of resilience professionals
- Foster a high-performance, accountable and collaborative culture
- Build organisational capability across testing, exercising and analysis
Scope of Responsibility
- Global remit across all business lines, functions, legal entities and jurisdictions
- Oversight of testing across critical services, operations and third-party ecosystems
- Accountability for enterprise standards, execution oversight, advisory and remediation governance
- Engagement with senior executives, regulators and external stakeholders
Experience & Qualifications
- Senior leadership experience in resilience, testing/exercising, risk or related disciplines
- Proven experience leading enterprise-wide resilience testing programmes in regulated environments
- Strong track record in cross-functional and regulator-facing engagement
- Experience with technology, automation, analytics and AI in resilience
- Degree required; advanced qualifications or relevant certifications preferred
Knowledge, Skills & Capabilities
- Deep expertise in resilience testing methodologies and governance
- Strong understanding of operational resilience and scenario design
- Ability to translate testing outputs into clear insights and remediation actions
- Strong executive communication and influencing skills
- Strategic mindset with strong execution discipline
- Ability to drive change across complex global organisations
Salary Range:
$170,000 - $252,500 AnnualThe range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.
Employees are eligible to participate in State Street's comprehensive benefits program, which includes: our retirement savings plan (401K) with company match; insurance coverage including basic life, medical, dental, vision, long-term disability, and other optional additional coverages; paid-time off including vacation, sick leave, short term disability, and family care responsibilities; access to our Employee Assistance Program; incentive compensation including eligibility for annual performance-based awards (excluding certain sales roles subject to sales incentive plans); and, eligibility for certain tax advantaged savings plans.
For a full overview, visit https://hrportal.ehr.com/statestreet/Home.
About State StreetAcross the globe, institutional investors rely on us to help them manage risk, respond to challenges, and drive performance and profitability. We keep our clients at the heart of everything we do, and smart, engaged employees are essential to our continued success.
We are committed to fostering an environment where every employee feels valued and empowered to reach their full potential. As an essential partner in our shared success, you'll benefit from inclusive development opportunities, flexible work-life support, paid volunteer days, and vibrant employee networks that keep you connected to what matters most. Join us in shaping the future.
As an Equal Opportunity Employer, we consider all qualified applicants for all positions without regard to race, creed, color, religion, national origin, ancestry, ethnicity, age, disability, genetic information, sex, sexual orientation, gender identity or expression, citizenship, marital status, domestic partnership or civil union status, familial status, military and veteran status, and other characteristics protected by applicable law.
Discover more information on jobs at StateStreet.com/careers
Read our CEO Statement
Job Application Disclosure:
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
About State Street Global Advisors
Sourced by ZipRecruiter
Industry
Finance and insurance
Company size
1,001 - 5,000 Employees
Headquarters location
Boston, MA, US
Year founded
1978