Finastra (Misys International Banking Systems Limited)

Director, Vulnerability Management

Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field
  • Progressive experience in cybersecurity, specifically vulnerability management or related disciplines
  • Proven leadership experience managing security teams or initiatives
  • Demonstrated success in large-scale enterprise vulnerability management programs
  • Strong background in cyber risk management and governance
  • Deep understanding of vulnerability management frameworks and secure software development practices

Responsibilities

  • Own and mature the enterprise vulnerability management program across all technology domains
  • Establish risk-based prioritization methodologies considering exploitability and business criticality
  • Define and maintain standards, operational procedures, and governance frameworks for vulnerability management
  • Drive accountability for timely remediation of high-risk vulnerabilities
  • Lead executive reporting on vulnerability metrics and cyber risk status
  • Coordinate response efforts for critical vulnerabilities and zero-day threats
  • Collaborate with cross-functional teams to align with compliance and regulatory requirements

Benefits

  • Leadership role with the opportunity to shape organizational security strategy
  • Collaboration with diverse teams across engineering and operations initiatives
  • Focus on continuous improvement and innovative security practices
  • Potential for professional development and mentoring opportunities
  • Participation in executive-level discussions and strategic decision-making
Full Job Description

Position Overview

We areseekingan experienced and strategic Director of Vulnerability Managementto lead the organization's efforts toidentify, prioritize, remediate, and govern cybersecurity vulnerabilities across infrastructure, cloud environments, applications, and internally developed products.

This leader willbe responsible foradvancing a mature, risk-based vulnerability management program while partnering closely with Engineering, Product, Architecture, Infrastructure, DevOps, and Security Operations teams to embed security throughout the software development lifecycle. The successful candidate will combine strong technical expertise, program leadership, and stakeholder management skills to reduce enterprise risk and enable secure business growth.

Key Responsibilities 

Enterprise Vulnerability Management 

  • Own and mature the enterprise vulnerability management program across infrastructure, endpoints, cloud platforms, applications, containers, and third-party technologies. 

  • Establish risk-based prioritization methodologies that consider exploitability, business criticality, threat intelligence, and asset exposure. 

  • Define and maintain vulnerability management standards, operational procedures, remediation SLAs, exception processes, and governance frameworks. 

  • Drive accountability for remediation efforts and ensure timely resolution of critical and high-risk vulnerabilities. 

  • Lead executive reporting and board-level metrics related to vulnerability exposure, remediation performance, and cyber risk reduction. 

  • Coordinate enterprise response efforts for critical vulnerabilities, zero-day threats, and actively exploited security issues. 

Program Governance & Risk Management 

  • Collaborate with Risk, Compliance, Audit, Privacy, and Legal teams to ensure alignment with regulatory and industry requirements. 

  • Manage vulnerability exception processes and risk acceptance frameworks. 

  • Support regulatory examinations, customer security assessments, internal audits, and external audits. 

  • Develop and maintain meaningful KPIs and KRIs that demonstrate program effectiveness and risk reduction. 

Leadership & Organizational Development

  • Build, lead, and mentor a high-performing team of vulnerability managementprofessionals.

  • Foster strong partnerships across Engineering, Infrastructure, Operations, and business leadership teams.

  • Establish a culture of accountability, collaboration, innovation, and continuous improvement.

  • Provide strategic guidance and subject matterexpertiseto executive leadership on emerging threats, vulnerability trends, and secure product development practices.

Required Qualifications 

Education 

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related discipline. 

  • Equivalent combination of education and relevant experience will be considered. 

Experience 

  • Progressive cybersecurity experience, including vulnerability management, application security, product security, or related security disciplines. 

  • Leadership experience managing security teams, programs, or enterprise initiatives. 

  • Demonstrated success leading vulnerability management programs in large-scale enterprise environments. 

  • Experience partnering with software engineering organizations and implementing secure development practices. 

  • Strong background in cyber risk management, governance, and executive communications. 

Technical Expertise 

  • Deep understanding of vulnerability management frameworks, CVSS, exploitability analysis, threat intelligence integration, and remediation prioritization. 

  • Strong knowledge of secure software development practices and application security principles. 

  • Experience with vulnerability management and application security platforms such as Tenable, Qualys, Rapid7, Wiz, Prisma Cloud, Microsoft Defender, GitHub Advanced Security, CodeQL, Veracode, Checkmarx, or similar solutions. 

  • Familiarity with cloud environments, containers, Kubernetes, CI/CD pipelines, APIs, and modern software architectures.

  • Ability to communicate technical risks effectively to both technical and non-technical audiences.

Certifications (Preferred)

  • CISSP

  • CISM

  • Relevant cloud security certifications

Preferred Qualifications 

  • Experience leading Product Security or DevSecOps transformation initiatives. 

  • Experience implementing secure-by-design principles within enterprise software development environments. 

  • Familiarity with software supply chain security and emerging secure software development regulations. 

  • Experience supporting highly regulated industries, including financial services, healthcare, insurance, or critical infrastructure sectors. 

  • Experience leveraging automation and AI-driven security capabilities to improve vulnerability management and security operations. 

 

Leadership Competencies 

The ideal candidate will demonstrate: 

  • Strategic thinking and business acumen. 

  • Strong executive presence and communication skills. 

  • Ability to influence without direct authority. 

  • Data-driven decision-making and risk prioritization. 

  • Effective stakeholder management across technical and business functions.

  • A commitment to talent development, inclusiveness, and continuous improvement.

Success Measures 

Success in this role will be measured through: 

  • Reduction of enterprise vulnerability exposure and risk. 

  • Improvement in remediation performance and SLA compliance. 

  • Increased adoption of secure development practices across engineering teams. 

  • Enhanced visibility and reporting of cyber risk to executive leadership. 

  • Successful integration of security into product and technology delivery processes. 

  • Positive audit, regulatory, and customer security assessment outcomes. 

Applicants for this position need to be located in posted location or their immediate surrounding areas. Due to the requirements of this position, this job posting is not available for, and Finastra will not be considering any applicants who currently reside in New York City or California.

About Finastra (Misys International Banking Systems Limited)

Finastra is a financial technology company that provides software solutions to financial institutions. The company was formed in 2017 through the merger of Misys and D+H. Finastra has over 10,000 employees and operates in over 130 countries. The company's products are used by banks, credit unions, and other financial institutions to manage their operations, including lending, payments, and treasury management. Finastra is headquartered in London, UK.
Learn more about Finastra (Misys International Banking Systems Limited)
Size
10,000 employees
Industry

Similar Jobs

More Jobs at Finastra (Misys International Banking Systems Limited)

More Information Technology Jobs

Find similar Director, Vulnerability Management jobs: