Jobs · Engineering

Director, Cyber Exposure & Vulnerability Management

Fifth Third Bank · Cincinnati, OH · 3 wk ago
RemoteRemoteEngineeringFull-time

About The Role

Fifth Third Bank is seeking a Director of Cyber Exposure & Vulnerability Management to lead two critical cybersecurity functions: Enterprise Vulnerability Remediation and Exposure Analysis & Coordination. This leader is responsible for reducing enterprise cyber risk by driving vulnerability remediation and coordinating the response to significant technology exposures across the Bank. The role combines strategic leadership and operational execution, partnering with senior technology leaders to prioritize remediation efforts, improve exposure management processes, and strengthen the Bank's cybersecurity posture.

In addition to leading the vulnerability remediation program, this Director will help mature a growing Exposure Analysis & Coordination capability focused on rapidly assessing and coordinating the Bank's response to emerging cybersecurity risks that require urgent action and cross-functional engagement. This is a highly visible leadership role that partners closely with Information Security, Technology, Risk Management, and executive leadership.

Responsibilities

  • Lead Enterprise Vulnerability Remediation
    • Lead the enterprise vulnerability remediation program, including governance, reporting, escalation, and stakeholder coordination.
    • Partner with application, infrastructure, cloud, and security teams to drive timely risk reduction.
    • Establish remediation priorities, performance metrics, and service-level expectations.
    • Support audits, regulatory examinations, and enterprise risk governance activities.
    • Continuously improve remediation workflows, reporting, and prioritization processes.
  • Lead Exposure Analysis & Coordination
    • Lead the Bank's Exposure Analysis & Coordination function.
    • Coordinate enterprise response to significant technology exposures, including:
      • Zero-day vulnerabilities
      • Emerging and pre-CVE threats
      • Vendor advisories
      • Third-party technology exposures
      • Cloud security exposures
    • Drive cross-functional assessment, prioritization, mitigation tracking, and executive communications.
    • Ensure significant exposure events are consistently governed, documented, escalated, and resolved.
    • Lead post-event reviews and operational improvements.
  • Drive Risk-Based Decision Making
    • Translate vulnerability, threat, and exposure data into actionable risk decisions.
    • Advise senior leaders on remediation priorities, business impact, and risk tradeoffs.
    • Identify systemic issues and opportunities for long-term risk reduction.
  • Lead Strategy & Continuous Improvement
    • Define strategy, roadmaps, metrics, and maturity objectives for the Remediation and Exposure Management functions.
    • Establish scalable operating processes, playbooks, and governance models.
    • Drive continuous improvement using Agile and Lean practices.
    • Align cybersecurity priorities with technology investment, capacity, and risk reduction objectives.
  • Build High-Performing Teams
    • Lead and develop security engineers and analysts.
    • Coach emerging leaders and strengthen organizational capabilities.
    • Build a culture of accountability, collaboration, and continuous improvement.
    • Ensure teams can effectively support both planned remediation efforts and rapidly evolving cyber threats.

Requirements

  • 10+ years of experience in cybersecurity, technology risk, security operations, vulnerability management, or related disciplines.
  • Experience leading enterprise-scale remediation, risk reduction, security operations, or response coordination programs.
  • Strong knowledge of vulnerability management practices, risk prioritization methodologies, and cyber risk governance.
  • Demonstrated ability to lead large cross-functional initiatives across complex organizations.
  • Experience presenting to senior leaders and executive audiences.
  • Strong executive communication and stakeholder management skills.
  • Proven ability to influence outcomes without direct authority.
  • Experience managing teams, budgets, priorities, and strategic initiatives.

Preferred Qualifications

  • Experience within a large regulated financial services organization and FFIEC and PCI requirements.
  • Experience supporting regulatory examinations, audits, and enterprise risk governance activities.
  • Familiarity with vulnerability management, security analytics, asset management, GRC, and workflow management platforms.
  • Experience with cloud, infrastructure, application, and third-party technology security.
  • Experience operating within Agile or SAFe environments.
  • Professional certifications such as CISSP, CISM, CRISC, GIAC, or equivalent.

Pay

Total Base Pay Range: $121,900.00 - $262,100.00 USD Annual

At Fifth Third, we understand the importance of recognizing our employees for the role they play in improving the lives of our customers, communities and each other. Our Total Rewards include comprehensive benefits and differentiated compensation offerings to give each employee the opportunity to be their best every day. The base salary for this position is reflective of the range of salary levels for all roles within this pay grade across the U.S. Individual salaries within this range will vary based on factors such as role, relevant skillset, relevant experience, education and geographic location. In addition to the base salary, this role is eligible to participate in an incentive compensation plan, with any such payment based upon company, line of business and/or individual performance.

Benefits

Our extensive benefits programs are designed to support the individual needs of our employees and their families, encompassing physical, financial, emotional and social well-being. You can learn more about those programs on our 53.com Careers page.

Schedule

LOCATION: Virtual, Ohio

Similar jobs