Your role and responsibilities
The CISO Remediation Team is seeking a manager of security remediation to lead a team of cybersecurity Remediation Engineers. This role is responsible for driving the successful execution of remediation efforts across the IBM enterprise, ensuring security risks are addressed effectively, sustainably, and at scale.
The manager operates at the intersection of people leadership, technical oversight, and cross-organizational coordination, partnering closely with Security Operations, Incident Response, Product, Infrastructure, and Architecture teams. The role balances technical depth with leadership, enabling engineers to execute remediation while aligning work to enterprise risk priorities.
Key Responsibilities
- People & Team Leadership:
- Lead, coach, and develop a team of Remediation Engineers, supporting career growth.
- Set clear expectations for execution, ownership, and technical quality.
- Foster a culture of accountability, collaboration, and continuous improvement.
- Participate in hiring, onboarding, performance management, and succession planning.
- Technical & Delivery Oversight:
- Provide technical guidance and review for remediation strategies, ensuring solutions address root causes and reduce recurring risk.
- Provide guidance on the appropriate use of automation and AI-assisted tooling in remediation workflows, ensuring human judgment, security, and compliance requirements are maintained.
- Ensure remediation efforts are prioritized based on enterprise risk, impact, and feasibility.
- Balance hands-on technical engagement with delegation and oversight as appropriate.
- Support engineers during high-severity incidents, escalations, and complex remediation efforts.
- Coach engineers on effective technical communication, including how to explain remediation approaches and risk to non-technical stakeholders.
- Cross-Team & Stakeholder Engagement:
- Partner with Security Operations, Incident Response, Product, and Infrastructure leaders to drive remediation outcomes.
- Influence remediation priorities and decisions across federated teams without direct authority.
- Translate technical remediation needs into clear risk-based messaging for leadership and stakeholders.
- Resolve blockers related to ownership, prioritization, or execution of remediation work.
- Represent remediation efforts in leadership forums, communicating progress, tradeoffs, and risk in clear, outcome-focused language.
- Strategy, Process, and Continuous Improvement:
- Contribute to or define remediation standards, patterns, and best practices.
- Promote the responsible adoption of automation and AI to improve remediation effectiveness and reduce mean time to remediation (MTTR.)
- Identify systemic gaps and drive improvements to remediation processes, tooling, and workflows.
- Track and communicate remediation progress, trends, and risk reduction outcomes.
- Ensure alignment between remediation activities and broader CISO objectives.
This is not a SOC operations or detection leadership role. The focus is on post-finding and post-incident remediation, vulnerability reduction, and systemic security improvements.
Level, scope, and strategic responsibility will align with experience and band.
Leaders are expected to spend time with their teams and clients and therefore are generally expected to be in the workplace a minimum of three days a week, subject to business needs.
Required education
Bachelor's Degree
Required technical and professional expertise
- Demonstrated experience leading technical teams in security, infrastructure, cloud, or platform engineering.
- Strong understanding of vulnerability management, incident response lifecycles, and remediation practices.
- Ability to guide engineers through ambiguous, high-pressure technical challenges.
- Proven ability to influence across organizations and drive outcomes without direct control.
- Strong communication skills, with the ability to translate technical issues into business and risk context.
- Experience operating in large, complex, federated enterprise environments.
Preferred technical and professional experience
- Experience managing or leading security remediation, vulnerability management, or post-incident response efforts.
- Background in one or more technical domains: cloud, networking, operating systems, automation, or security platforms.
- Experience working with Agile or product-aligned engineering teams.
- Experience applying enterprise security frameworks and risk management practices to prioritize and guide remediation decisions (e.g., NIST CSF, NIST 800-series).
- Certifications are a plus but not required (e.g., CISSP, CISM, cloud security certifications).
OTHER RELEVANT JOB DETAILSIBM offers a competitive and comprehensive benefits program. Eligible employees may have access to:
- Healthcare benefits including medical & prescription drug coverage, dental, vision, and mental health & well being
- Financial programs such as 401(k), cash balance pension plan, the IBM Employee Stock Purchase Plan, financial counseling, life insurance, short & long- term disability coverage, and opportunities for performance based salary incentive programs
- Generous paid time off including 12 holidays, minimum 56 hours sick time, 120 hours vacation, 12 weeks parental bonding leave in accordance with IBM Policy, and other Paid Care Leave programs. IBM also offers paid family leave benefits to eligible employees where required by applicable law
- Training and educational resources on our personalized, AI-driven learning platform where IBMers can grow skills and obtain industry-recognized certifications to achieve their career goals
- Diverse and inclusive employee resource groups, giving & volunteer opportunities, and discounts on retail products, services & experiences
We consider qualified applicants with criminal histories, consistent with applicable law.
This position was posted on the date cited in the key job details section and is anticipated to remain posted for 21 days from this date or less if not needed to fill the role.
IBM will not be providing visa sponsorship for this position now or in the future. Therefore, in order to be considered for this position, you must have the ability to work without a need for current or future visa sponsorship.
The compensation range and benefits for this position are based on a full-time schedule for a full calendar year. The salary will vary depending on your job-related skills, experience and location. Pay increment and frequency of pay will be in accordance with employment classification and applicable laws. For part time roles, your compensation and benefits will be adjusted to reflect your hours. Benefits may be pro-rated for those who start working during the calendar year.