Jobs · Information Technology · North Carolina

Manager, Cyber Exposure Management

Regions Bank · Charlotte, NC · 2 wk ago
On-siteInformation Technology$141k/yrFull-time

About the Role

The Cyber Security Manager is responsible for leading a diverse team of engineers and analysts charged with the daily operations of enforcing, monitoring, and managing cyber security controls to protect the assets of the bank, customers, and associates. This role monitors the domains of security controls including, but not limited to, malware defense, network security, Internet security, security analytics, threat intelligence and defense, cybercrime, data protection, vulnerability management, and customer authentication.

Primary Responsibilities

  • Develops cyber security architecture/designs, controls, processes, standards, and strategies to ensure alignment with Information Security standards, emerging threats, and overall Information Security strategy
  • Develops and implements incident response protocols for ongoing threats and attacks
  • Communicates status of current threat environment, incidents, and projected threats to senior management and executives
  • Manages the evaluation and testing of hardware, firmware, and software for possible impact on systems security
  • Coordinates with other managers to integrate Information Security project components with other projects including application development, network, server, and mainframe
  • Partners across Technology, Operations, Digital, and Data (TODD) to ensure controls are designed, implemented, and monitored to strengthen risk management, compliance, and cyber security, effectively mitigating risk to levels within the company's risk appetite
  • Ensures disciplined change management by evaluating risk and control impacts when designing or implementing changes to processes, systems, products, and/or services

Additional Responsibilities

  • Lead the Exposure Management strategy, including Continuous Threat Exposure Management (CTEM), and risk-based prioritization of remediation activities
  • Build an in-house portal to enable technology owners to understand their own individual exposures and understand prioritization requirements
  • Drive automation initiatives to improve vulnerability identification, prioritization, tracking, and reporting efficiencies
  • Provide strategic oversight of attack surface management, threat exposure analysis, and trigger risk remediation initiatives
  • Integrate threat intelligence and adversary tactics, techniques, and procedures (TTPs) into exposure prioritization and remediation strategies
  • Develop and implement risk-based methodologies to identify, assess, prioritize, and mitigate cyber exposures across on-premises, cloud, and hybrid environments
  • Manage exposure management escalations, ensuring critical vulnerabilities and high-risk findings are addressed within defined service-level objectives
  • Partner with IT, Security Operations, Infrastructure, Application Development, and business stakeholders to drive remediation efforts and reduce organizational risk
  • Hire, build, mentor, and lead a high-performing security team while managing vendor relationships and security technology investments

Requirements

  • Bachelor's degree in a related field and six (6) years of related experience
  • Or High School Diploma or GED and ten (10) years of related experience

Preferences

  • Two (2) years of lead or supervisory/managerial experience
  • Experience managing Information Technology and/or Information Security projects
  • Experience with security operations and incident response/handling

Skills and Competencies

  • Ability to prioritize assignments while working on multiple projects
  • Demonstrated ability to effectively engage project teams and leadership within a corporate setting
  • Excellent writing and oral communication skills
  • Strong ability to predict and plan for unknown threats
  • Strong ability to work well with others and place a premium on the group's success
  • Strong technical aptitude skills
  • Understanding of and ability to interpret applicable rules, regulations, and industry guidance

Pay

Minimum Job Range Target: $140,670.75 USD. Median: $184,390.00 USD.

Schedule

This position is intended to be onsite, now or in the near future. Associates will have regular work hours, including full days in the office three or more days a week. The manager will set the work schedule for this position, including in-office expectations.

Benefits

  • Paid Vacation/Sick Time
  • 401K with Company Match
  • Medical, Dental and Vision Benefits
  • Disability Benefits
  • Health Savings Account
  • Flexible Spending Account
  • Life Insurance
  • Parental Leave
  • Employee Assistance Program
  • Associate Volunteer Program

Similar jobs