Nelnet

Manager, Exposure Management

Nelnet$120K — $160K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience.
  • 3–6 years of cybersecurity experience, primarily in vulnerability management or application security.
  • 1–2 years of team lead or management experience.
  • Knowledge of vulnerability management platforms like Tenable or Wiz, and application security concepts like SAST and DAST.
  • Ability to drive cross-team outcomes without direct authority and excellent communication skills.
  • Understanding of risk-based prioritization and Continuous Threat Exposure Management (CTEM) principles.
  • Relevant cybersecurity certifications such as CISSP or CISM are highly desirable.

Responsibilities

  • Lead and mentor a team of vulnerability analysts and application security practitioners.
  • Oversee and optimize a comprehensive exposure management pipeline.
  • Implement a Continuous Threat Exposure Management (CTEM) cycle for scoping and remediation.
  • Integrate security findings into a unified risk-based view.
  • Develop risk-based prioritization strategies beyond traditional metrics like CVSS.
  • Guide application security programs and collaborate with development teams.
  • Engage with stakeholders to translate technical exposure into business contexts.

Benefits

  • Medical, dental, and vision insurance options.
  • Generous earned time off and a robust wellness program.
  • 401K student loan repayment assistance.
  • Life insurance and AD&D coverage.
  • Employee assistance program and stock purchase program.
  • Tuition reimbursement and performance-based incentives.
Full Job Description
Nelnet is seeking an experienced and motivated Cybersecurity Manager, Exposure Management to lead our vulnerability operations, attack surface management, and application security functions. The ideal candidate will combine strong cybersecurity knowledge with exceptional leadership and stakeholder-management skills, and a demonstrated ability to drive remediation outcomes across engineering, infrastructure, and business teams.

In this role you will lead a single, unified exposure management program — bringing findings from code, configuration, cloud, infrastructure, and external attack surface into one prioritized, risk-based view. You will guide the team through a transformative evolution of how the function operates, adopting a Continuous Threat Exposure Management (CTEM) approach and leveraging AI and automation to optimize the prioritization of work activity. As the Manager, Exposure Management, you will be responsible for reducing enterprise risk by ensuring the right exposures are identified, prioritized, and remediated through strong partnerships across the organization.

This position requires work in support of the Company’s contract with the United States Department of Education (“ED”). As such, the United States Government requires that any applicant for this position must complete United States Government security clearance. Effective June 1, 2018, ED has informed Nelnet that security clearance applications for foreign nationals are not being accepted or processed. In light of this direction from ED, Nelnet will be unable to hire applicants without United States citizenship for such positions.

This position offers a hybrid work option. Nelnet values flexibility and understands the importance of work-life integration. Our hybrid work environment allows associates within 30 miles of an office to work remotely for part of the week, while also fostering collaboration and team connection through in-office presence.

Please note that we are unable to provide visa sponsorship for this position. To be considered, candidates must already be authorized to work in the United States without the need for current or future sponsorship as security clearance is required.

Responsibilities:

Leadership and Team Development:

  • Provide leadership, guidance, and mentorship to a team of vulnerability analysts and application security practitioners.
  • Foster a collaborative, high-performance environment and lead the team through a transformative evolution of its operating model.
  • Conduct performance evaluations, identify training needs, and support professional development.
  • Evolve team roles toward judgment, validation, and stakeholder engagement as automation and AI-assisted workflows mature.

Exposure Management Operations:

  • Oversee a unified exposure management pipeline — intake, enrichment, prioritization, and remediation orchestration — across a dynamic, continuously changing vulnerability portfolio.
  • Operate the program as a Continuous Threat Exposure Management (CTEM) cycle of scoping, discovery, prioritization, validation, and mobilization.
  • Integrate findings across code, configuration, cloud, infrastructure, and external Attack Surface Management (ASM) into a single, risk-based view.
  • Develop and maintain exposure management policies, procedures, and workflows.

Prioritization and Risk-Based Remediation:

  • Apply risk-based prioritization beyond CVSS — including exploitability, reachability, asset criticality, and threat-intelligence context — to focus effort where risk is greatest.
  • Leverage AI and automation to enrich, rank, and continuously optimize the prioritization of work activity.
  • Establish and maintain a documented risk-acceptance workflow with clear business-owner accountability.
  • Define and report remediation SLAs, velocity, and risk-reduction metrics that leadership can trust.

Application Security:

  • Guide enterprise application security programs, including code analysis, secure development standards, developer guidance, and a security champions program.
  • Partner with development teams to integrate security into the SDLC and CI/CD workflows.

Stakeholder Engagement and Collaboration:

  • Build credibility and drive remediation outcomes with development, infrastructure, and platform teams across the organization.
  • Translate exposure into the appropriate framing for each audience — technical detail for engineers, delivery impact for managers, and business risk for executives.
  • Partner with GRC and internal audit to ensure defensible process, evidence, and risk-register alignment.
  • Deliver clear, concise exposure narratives to the CISO and executive leadership, including a board-ready view of enterprise exposure.
  • Satisfy FSA/OSA and similar regulated-process obligations as a baseline of the program.

Qualifications:

  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience.
  • Minimum of 3–6 years of experience in cybersecurity, including exposure to vulnerability management, application security, and/or attack surface management.
  • Minimum of 1–2 years of team lead or management experience.
  • Working knowledge of vulnerability management platforms (e.g., Tenable, Wiz, or equivalents), attack surface management tooling, and application security concepts (e.g., SAST, DAST, SCA).
  • Understanding of risk-based prioritization and modern exposure management concepts, including Continuous Threat Exposure Management (CTEM).
  • Demonstrated ability to influence and drive outcomes across teams without direct reporting authority.
  • Excellent communication, presentation, and interpersonal skills, with the ability to translate technical risk into clear business language.
  • Strong analytical, problem-solving, and decision-making skills.
  • Ability to work effectively in a fast-paced and evolving environment.
  • Relevant certifications such as CISSP, CISM, or SANS GIAC certifications (e.g., GCIH, GSEC) are highly desirable.

Preferred Qualifications:

  • Experience operating, building, or maturing a CTEM or exposure management program.
  • Familiarity with AI- and automation-assisted security workflows.
  • Familiarity with cloud security concepts and technologies (e.g., AWS, Azure, GCP).
  • Knowledge of relevant regulatory and compliance frameworks (e.g., NIST, ISO 27001, PCI DSS).
  • Experience with secure SDLC practices and security champions programs.
  • Experience with scripting languages (e.g., Python, PowerShell).

Compensation range for this role is $120,000-$160,000 annually, depending on experience.

#LI-Hybrid

#LI-CW1

Our benefits package includes medical, dental, vision, HSA and FSA, generous earned time off, 401K/student loan repayment, life insurance & AD&D insurance, employee assistance program, employee stock purchase program, tuition reimbursement, performance-based incentive pay, short- and long-term disability, and a robust wellness program. Click here to learn more about our benefits: .

About Nelnet

Nelnet, Inc. provides educational services in loan servicing, payment processing, education planning, and asset management. The company is headquartered in Lincoln, Nebraska and has additional offices in Omaha, Nebraska; Aurora, Colorado; Tigard, Oregon; and Sacramento, California. Nelnet was founded in 1978 and is one of the largest student loan servicers in the United States. Nelnet also provides software and data management services for the education finance industry. The company has three primary business segments: Loan Systems and Servicing, Tuition Payment Processing, and Communications. Nelnet is publicly traded on the New York Stock Exchange under the ticker symbol NNI.
Learn more about Nelnet
Size
7,988 employees
Market Cap
$3.3 billion
Industry
Net Income
$352.4 million
Founded
1977
5 Year Trend
+3%
Revenue
$1.4 billion
NASDAQ

Similar Jobs

More Jobs at Nelnet

More Information Technology Jobs

Find similar Manager, Exposure Management jobs: