BNY Mellon

SVP, Vulnerability Management & Cloud Security Posture Platform Engineering

BNY Mellon
Apply
4 months ago

Responsibilities

  • Own engineering and operational accountability for enterprise vulnerability management and cloud security posture management tooling.
  • Run platform health, configuration, access, integrations, upgrades, onboarding, troubleshooting, vendor support, and production stability activities.
  • Engineer improvements for reliability, scalability, coverage, automation, performance, data quality, and operational resilience.
  • Manage tenant administration, access models, scanner and agent lifecycles, cloud connectors, onboarding standards, and service health.
  • Support scanning across servers, endpoints, databases, network devices, appliances, cloud assets, containers, and external-facing assets.
  • Build automation, APIs, configuration management, dashboards, reporting workflows, and data pipeline integrations.
  • Drive asset discovery, inventory reconciliation, coverage reporting, ownership validation, and CMDB integrations.
  • Enable remediation tracking, SLA governance, exception workflows, major vulnerability response, and downstream risk reporting.
  • Own monitoring, health checks, incident response, vendor escalations, disaster recovery readiness, and business continuity procedures.
  • Support SSO, RBAC, privileged access, service accounts, API tokens, access recertification, segregation of duties, audit evidence, and regulatory reporting.
  • Troubleshoot issues across tools, agents, scanners, APIs, cloud connectors, networks, identity systems, data pipelines, vendor platforms, and reporting consumers.
  • Mentor engineers, improve runbooks and documentation, and provide hands-on technical leadership.

Requirements

  • Hands-on experience running and engineering enterprise cybersecurity platforms, particularly vulnerability management, scanning, asset discovery, cloud security posture, or cloud-native application protection platforms.
  • Strong production operations experience covering incident response, change management, service health monitoring, vendor escalation, and lifecycle management.
  • Strong automation, API integration, configuration management, deployment, data quality, and toil-reduction skills.
  • Strong knowledge of vulnerability management operating models, remediation tracking, SLA governance, exceptions, ownership validation, and major vulnerability response.
  • Strong networking knowledge including TCP/IP, routing, DNS, firewalls, proxies, load balancers, network segmentation, NAT, packet flows, latency, and reachability troubleshooting.
  • Experience scanning and assessing servers, endpoints, network devices, databases, appliances, cloud assets, containers, and externally exposed systems.
  • Experience with AWS, Azure, GCP, cloud connectors, IAM, APIs, and security control frameworks.
  • Experience integrating cybersecurity platforms with CMDBs, ticketing systems, reporting platforms, data pipelines, cloud platforms, vulnerability management systems, and enterprise dashboards.
  • Strong understanding of SSO, MFA, RBAC, privileged access, service accounts, API tokens, and access recertification.
  • Programming and automation skills using Python, Go, Java, or similar languages.
  • Experience supporting audits, regulatory reporting, evidence retention, operational controls, and production change management.
  • Experience with Kubernetes and container vulnerability management, including cluster visibility, image assessment, runtime context, registry integrations, cloud-native asset inventory, and remediation workflows.
  • Bachelor’s degree in computer science or a related discipline, or equivalent work experience, is required.
  • 10–12 years of experience in information security or related technology experience is required.
  • Advanced degree, financial services or securities industry experience, Qualys, Wiz.io, Lumeta, FedRAMP-authorized or FedRAMP-aligned cloud experience, and familiarity with FedRAMP controls are preferred.

Benefits

  • The role is based in New York, NY; Pittsburgh, PA; or Washington, DC.
  • The position offers high-impact technical ownership and direct influence over enterprise security posture, vulnerability response, regulatory confidence, and operational resilience.
BNY Mellon

About BNY Mellon

10,000+ employees
Contact me