
SVP, Vulnerability Management & Cloud Security Posture Platform Engineering
BNY Mellon4 months ago
Responsibilities
- Own engineering and operational accountability for enterprise vulnerability management and cloud security posture management tooling.
- Run platform health, configuration, access, integrations, upgrades, onboarding, troubleshooting, vendor support, and production stability activities.
- Engineer improvements for reliability, scalability, coverage, automation, performance, data quality, and operational resilience.
- Manage tenant administration, access models, scanner and agent lifecycles, cloud connectors, onboarding standards, and service health.
- Support scanning across servers, endpoints, databases, network devices, appliances, cloud assets, containers, and external-facing assets.
- Build automation, APIs, configuration management, dashboards, reporting workflows, and data pipeline integrations.
- Drive asset discovery, inventory reconciliation, coverage reporting, ownership validation, and CMDB integrations.
- Enable remediation tracking, SLA governance, exception workflows, major vulnerability response, and downstream risk reporting.
- Own monitoring, health checks, incident response, vendor escalations, disaster recovery readiness, and business continuity procedures.
- Support SSO, RBAC, privileged access, service accounts, API tokens, access recertification, segregation of duties, audit evidence, and regulatory reporting.
- Troubleshoot issues across tools, agents, scanners, APIs, cloud connectors, networks, identity systems, data pipelines, vendor platforms, and reporting consumers.
- Mentor engineers, improve runbooks and documentation, and provide hands-on technical leadership.
Requirements
- Hands-on experience running and engineering enterprise cybersecurity platforms, particularly vulnerability management, scanning, asset discovery, cloud security posture, or cloud-native application protection platforms.
- Strong production operations experience covering incident response, change management, service health monitoring, vendor escalation, and lifecycle management.
- Strong automation, API integration, configuration management, deployment, data quality, and toil-reduction skills.
- Strong knowledge of vulnerability management operating models, remediation tracking, SLA governance, exceptions, ownership validation, and major vulnerability response.
- Strong networking knowledge including TCP/IP, routing, DNS, firewalls, proxies, load balancers, network segmentation, NAT, packet flows, latency, and reachability troubleshooting.
- Experience scanning and assessing servers, endpoints, network devices, databases, appliances, cloud assets, containers, and externally exposed systems.
- Experience with AWS, Azure, GCP, cloud connectors, IAM, APIs, and security control frameworks.
- Experience integrating cybersecurity platforms with CMDBs, ticketing systems, reporting platforms, data pipelines, cloud platforms, vulnerability management systems, and enterprise dashboards.
- Strong understanding of SSO, MFA, RBAC, privileged access, service accounts, API tokens, and access recertification.
- Programming and automation skills using Python, Go, Java, or similar languages.
- Experience supporting audits, regulatory reporting, evidence retention, operational controls, and production change management.
- Experience with Kubernetes and container vulnerability management, including cluster visibility, image assessment, runtime context, registry integrations, cloud-native asset inventory, and remediation workflows.
- Bachelor’s degree in computer science or a related discipline, or equivalent work experience, is required.
- 10–12 years of experience in information security or related technology experience is required.
- Advanced degree, financial services or securities industry experience, Qualys, Wiz.io, Lumeta, FedRAMP-authorized or FedRAMP-aligned cloud experience, and familiarity with FedRAMP controls are preferred.
Benefits
- The role is based in New York, NY; Pittsburgh, PA; or Washington, DC.
- The position offers high-impact technical ownership and direct influence over enterprise security posture, vulnerability response, regulatory confidence, and operational resilience.