Reporting to the Head of Vulnerability Management within the Cybersecurity team, we are seeking a Senior Vulnerability & Security Engineer to lead the advancement of the organization's vulnerability management and security configuration programs.
This is a technical cybersecurity role responsible for identifying, assessing, prioritizing, and managing security exposures across the enterprise. The successful candidate will combine strong engineering expertise with risk-based analysis to evaluate vulnerabilities and security configuration weaknesses, determine their business impact, and drive effective remediation and mitigation strategies.
As a key subject matter expert, this individual will partner closely with infrastructure, cloud, application development, engineering, and security teams to improve the organization's security posture. The role requires the ability to translate complex technical findings into clear business risk insights and actionable recommendations for technical and non-technical stakeholders.
In addition, this role will be responsible for engineering and continuous enhancement of the enterprise security configuration capabilities, including the development of security baselines, compliance monitoring, automated assessment capabilities, and remediation processes. The role will ensure configuration management practices are integrated with broader vulnerability management processes to provide a holistic view of cyber risk.
Key Responsibilities
Vulnerability Assessment & Risk Analysis
- Analyze vulnerabilities identified through enterprise vulnerability scanning, endpoint detection and response (EDR) platforms, application security testing, penetration testing, and threat intelligence sources.
- Conduct technical analysis of CVEs, vendor advisories, and threat intelligence to assess affected technologies, exploitability, attack vectors, business impact, and available mitigation options.
- Evaluate vulnerabilities using both technical and business context to differentiate between vulnerabilities that represent material business risk and those that can be effectively managed through compensating controls.
- Provide risk-based recommendations to support remediation planning, exception management, and cybersecurity governance processes.
Vulnerability Remediation & Mitigation
- Partner with infrastructure, cloud, application, platform, and engineering teams to develop effective remediation strategies.
- Assess the effectiveness of proposed mitigations and determine whether residual risk remains acceptable.
- Identify alternative remediation approaches when immediate patching or correction is not feasible.
- Review, assess, and provide recommendations regarding vulnerability exceptions requests.
Vulnerability & Security Configuration Engineering
- Design, implement, and continuously improve capabilities supporting the enterprise vulnerability and security configuration management programs.
- Develop and maintain secure configuration baselines aligned with organizational standards and industry frameworks.
- Engineer automated solutions to assess, monitor, measure, and report on configuration compliance across enterprise environments.
- Integrate configuration assessment findings with vulnerability management workflows to improve risk visibility and prioritization.
- Evaluate emerging technologies, tools, and methodologies to enhance vulnerability and configuration management capabilities.
- Serve as the technical escalation point and subject matter expert for vulnerability and configuration management issues.
- Provide technical leadership, mentorship, and guidance to cybersecurity team members.
- Maintain awareness of emerging threats, vulnerabilities, exploitation techniques, and industry best practices.
Required Qualifications
- 7+ years of cybersecurity experience, preferably within financial services or another highly regulated industry.
- Strong technical knowledge of enterprise infrastructure, operating systems, networking, databases, applications, and cloud platforms.
- Demonstrated experience analyzing vulnerabilities, assessing risk, and developing remediation strategies.
- Experience engineering and operating enterprise vulnerability management and security configuration management programs.
- Experience with vulnerability exception processes, compensating controls, risk acceptance methodologies, and remediation governance.
- Strong understanding of cybersecurity frameworks, regulations, and industry practices, including NIST, ISO 27001, OWASP, NYDFS Part 500, DORA, CIS and STIG.
- Experience interpreting cybersecurity control requirements and evaluating compliance with organizational standards.
- Strong analytical, problem-solving, stakeholder management, communication, and influencing skills.
- Ability to communicate complex technical issues effectively to both technical and business audiences.
Preferred Qualifications
- CISSP or equivalent
- Experience in automation and scripting (PowerShell, Python, or similar) to improve vulnerability and configuration management processes.
- Advanced PowerPoint and Excel skills, including development of executive-level risk reporting, dashboards, metrics, and presentations.
Salary Range
MA: $140,000 - $190,000 + annual target bonus
NJ: $150,000 - $195,000 + annual target bonus
BBH and its affiliates' compensation program includes base salary, discretionary bonuses, and profit-sharing. The anticipated base salary range(s) shown above are only for the indicated location(s) and may differ in other locations due to cost of living and labor considerations. Base salaries may vary based on factors such as skill, experience and qualification for the role. BBH's total rewards package recognizes your contributions with more than just a paycheck—providing you with benefits that enhance your experience at BBH from long-term savings, healthcare, and income protection to professional development opportunities and time off, our programs support your overall well-being.
We value diverse experiences. We value diverse experiences and transferrable skillsets. If your career hasn’t followed a traditional path, includes alternative experiences, or doesn’t meet every qualification or skill listed in the job description, please do go ahead and apply.