Manager, Cyber Exposure Management
At Regions, we believe associates deserve more than just a job. We believe in offering performance-driven individuals a place where they can build a career — a place to expect more opportunities. If you are focused on results, dedicated to quality, strength and integrity, and possess the drive to succeed, then we are your employer of choice.
About the role
The Cyber Security Manager is responsible for leading a diverse team of engineers and analysts charged with the daily operations of enforcing, monitoring, and managing cyber security controls to protect the assets of the bank, customers, and associates. This role monitors the domains of security controls including, but not limited to, malware defense, network security, Internet security, security analytics, threat intelligence and defense, cybercrime, data protection, vulnerability management, and customer authentication.
Responsibilities
- Develops cyber security architecture/designs, controls, processes, standards, and strategies to ensure alignment with Information Security standards, emerging threats, and overall Information Security strategy
- Develops and implements incident response protocols for ongoing threats and attacks
- Communicates status of current threat environment, incidents, and projected threats to senior management and executives
- Manages the evaluation and testing of hardware, firmware, and software for possible impact on systems security
- Coordinates with other managers to integrate Information Security project components with other projects including application development, network, server, and mainframe
- Partners across Technology, Operations, Digital, and Data (TODD) to ensure controls are designed, implemented, and monitored to strengthen risk management, compliance, and cyber security, effectively mitigating risk to levels within the company’s risk appetite
- Ensures disciplined change management by evaluating risk and control impacts when designing or implementing changes to processes, systems, products, and/or services
- Leads the Exposure Management strategy, including Continuous Threat Exposure Management (CTEM), and risk-based prioritization of remediation activities
- Builds an in-house portal to enable technology owners to understand their own individual exposures and prioritization requirements
- Drives automation initiatives to improve vulnerability identification, prioritization, tracking, and reporting efficiencies
- Provides strategic oversight of attack surface management, threat exposure analysis, and trigger risk remediation initiatives
- Integrates threat intelligence and adversary tactics, techniques, and procedures (TTPs) into exposure prioritization and remediation strategies
- Develops and implements risk-based methodologies to identify, assess, prioritize, and mitigate cyber exposures across on-premises, cloud, and hybrid environments
- Manages exposure management escalations, ensuring critical vulnerabilities and high-risk findings are addressed within defined service-level objectives
- Partners with IT, Security Operations, Infrastructure, Application Development, and business stakeholders to drive remediation efforts and reduce organizational risk
- Hires, builds, mentors, and leads a high-performing security team while managing vendor relationships and security technology investments
Requirements
- Bachelor's degree in a related field and six (6) years of related experience
- Or High School Diploma or GED and ten (10) years of related experience
Preferences
- Two (2) years of lead or supervisory/managerial experience
- Experience managing Information Technology and/or Information Security projects
- Experience with security operations and incident response/handling
Skills and Competencies
- Ability to prioritize assignments while working on multiple projects
- Demonstrated ability to effectively engage project teams and leadership within a corporate setting
- Excellent writing and oral communication skills
- Strong ability to predict and plan for unknown threats
- Strong ability to work well with others and place a premium on the group’s success
- Strong technical aptitude skills
- Understanding of and ability to interpret applicable rules, regulations, and industry guidance
Schedule
This position is intended to be onsite, now or in the near future. Associates will have regular work hours, including full days in the office three or more days a week. The manager will set the work schedule for this position, including in-office expectations.
This position is exempt from timekeeping requirements under the Fair Labor Standards Act and is not eligible for overtime pay. This position is incentive eligible.
Pay
The target pay range for this role is based on the Metropolitan Statistical Area Market Range for where the position is located and level of the position.
- Minimum Job Range Target: $140,670.75 USD
- Median: $184,390.00 USD
This role is eligible to participate in the annual discretionary incentive plan. Employees are eligible to receive a discretionary award based on individual, business, and/or company performance. Opportunity to participate in the Long Term Incentive Plan.
Benefits
Regions offers a benefits package that is flexible, comprehensive and recognizes that "one size does not fit all" for benefits-eligible associates.
- Paid Vacation/Sick Time
- 401K with Company Match
- Medical, Dental and Vision Benefits
- Disability Benefits
- Health Savings Account
- Flexible Spending Account
- Life Insurance
- Parental Leave
- Employee Assistance Program
- Associate Volunteer Program
Please note, benefits and plans may be changed, amended, or terminated with respect to all or any class of associate at any time.
This position is located in Hoover, Alabama (Riverchase Operations Center). The available locations for this role are Birmingham, AL, Atlanta, GA, Nashville, TN, or Charlotte, NC. Regions will not provide relocation assistance or sponsor applicants for work visas for this position. Applicants must currently be authorized to work in the United States on a full-time basis.