Job DescriptionJob Title: Head of Exposure ManagementWorking Pattern: FulltimeWorking Location: Indianapolis, IN or RemoteRelocation assistance will be provided if applicable.
Position SummaryThe Exposure Management Lead is responsible for leading and maturing the organization's Vulnerability Management Program to identify, assess, prioritize, and reduce cybersecurity risk across enterprise technology environments. This role provides strategic oversight of vulnerability management processes, technologies, reporting, and remediation activities while partnering closely with infrastructure, application, cloud, security, and business teams.
The Exposure Management Lead serves as the subject matter expert for vulnerability risk management and is accountable for ensuring vulnerabilities are identified, assessed, prioritized, tracked, and remediated in accordance with organizational policies and risk tolerance.
What you will be doing:- Develop, implement, and maintain the enterprise Exposure Management Program.
- Establish Exposure management policies, standards, procedures, and service level objectives.
- Oversee enterprise vulnerability scanning activities across on-premises, cloud, endpoint, network, and application environments.
- Ensure Exposure assessment coverage across all managed assets.
- Evaluate newly disclosed vulnerabilities and assess organizational exposure.
- Lead Exposure triage and prioritization efforts.
- Develop executive-level reporting and dashboards that communicate organizational risk exposure.
- Present vulnerability trends, remediation performance, and risk metrics to security leadership and business stakeholders.
- Partners with Threat Intelligence and Security Operations teams to prioritize vulnerabilities actively targeted by threat actors.
Basic Requirements:- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field with 5+ years of experience in Exposure Management, Security Operations, Security Engineering, Risk Management or related cybersecurity disciplines
- Master's degree in Cybersecurity, Computer Science, Information Technology, or related field with 3+ years of experience in Exposure Management, Security Operations, Security Engineering, Risk Management or related cybersecurity disciplines
- JD/PhD
- Must be a U.S. Citizen or Permanent Resident to be considered for this role
Preferred Requirements:- Experience managing vulnerabilities across cloud, container, and hybrid environments.
- Familiarity with threat intelligence integration and exploitation analysis.
- Experience with security automation and workflow orchestration.
- Knowledge of vulnerability remediation processes within large enterprise environments.
- Experience supporting regulatory, compliance, and audit requirements.
Our vision is to ensure that the quality and dynamism that shaped our history continues into our future. It's a bold pursuit, and we never stop striving to go further, faster, and better. We lead progress, creating the technologies that move us forward. If you're driven to grow, to learn, and to make a lasting difference, this is where you belong.
Infinite PotentialClosing Date: September 11, 2026
Job CategoryInformation Technology
Job Posting Date04 Sep 2026; 00:09
Pay RangePay ranges for remote employees are based on the state where the employee resides and may vary from the posted range.
$122,741 - $199,454-Annually
Location:Working from home US
BenefitsRolls-Royce provides a comprehensive and competitive Total Rewards package that includes base pay and a discretionary bonus plan. Eligible employees may have the opportunity to enroll in other benefits, including health, dental, vision, disability, life and accidental death & dismemberment insurance; a flexible spending account; a health savings account; a 401(k) retirement savings plan with a company match; Employee Assistance Program; Paid Time Off; certain paid holidays; paid parental and family care leave; tuition reimbursement; and a long-term incentive plan. The options available to an employee may vary depending on eligibility factors such as date of hire, employment type, and the applicability of collective bargaining agreements.