Patching Governance Lead, Officer

2 weeks ago


Princeton NJ United States State Street Corporation Full time
Who We are Looking For:
This role will be member of the Global Infrastructure Operations Continuous Service Improvement (CSI) team as part of 24*7*365 Production Management organization. An organization that delivers highly secure, reliable, efficient infrastructure technology operations services that are focused on the needs of all State Street business. Responsible for delivering continuous improvement across various infrastructure operations towers by supporting the ITIL framework to improve processes, which ultimately improve our business.
We are seeking a skilled Patch Management Governance Lead to join our team, responsible for establishing and overseeing the governance framework for patch management across the organization. The ideal candidate will have a strong background in cybersecurity, experience in patch management, and the ability to develop and enforce policies and procedures to ensure effective patching practices.

What you will be responsible for:
The right person for this role will have a strong track record of program management experience, the demonstrated ability to deliver multiple high priority projects simultaneously, the ability to drive alignment across teams with competing priorities and be a strong advocate for risk management.
Job Responsibilities
  • Develop and implement patch management policies, procedures, and standards to ensure the security and integrity of the organization's IT infrastructure.
  • Establish governance structures, roles, and responsibilities for patch management processes, including coordination with IT teams, business units, and third-party vendors.
  • Define and maintain patch management metrics, KPIs, and reporting mechanisms to measure the effectiveness of patching activities and compliance with policies.
  • Coordinate with stakeholders to prioritize patches based on risk assessment, business impact, and compliance requirements.
  • Establish change management processes and controls to manage the deployment of patches across different environments, including development, testing, and production.
  • Conduct regular assessments and audits of patch management practices to identify areas for improvement and ensure adherence to policies and standards.
  • Collaborate with security teams to incorporate threat intelligence, vulnerability assessments, and risk analysis into patch prioritization and deployment strategies.
  • Provide guidance and training to IT teams, system administrators, and end-users on patch management best practices, procedures, and tools.
  • Monitor industry trends, emerging threats, and regulatory requirements related to patch management and incorporate them into governance frameworks.
  • Continuously evaluate and enhance patch management processes, tools, and automation capabilities to streamline operations and improve efficiency.
  • Lead the vulnerability reporting process, including the collection, documentation, and dissemination of vulnerability information to relevant stakeholders.
  • Coordinate with internal teams, including IT security, network operations, software development, and system administrators, to gather vulnerability data from various sources, including scanning tools, penetration tests, and security advisories.
  • Analyze vulnerability data to determine severity, impact, and potential risk to the organization's assets and systems.
  • Prepare and distribute regular vulnerability reports to key stakeholders, including management, IT teams, and business units, providing insights into the current state of vulnerabilities and trends over time.
  • Develop and maintain a centralized vulnerability tracking system or database to manage and prioritize vulnerabilities based on severity, affected systems, and available remediation resources.
  • Collaborate with stakeholders to establish and enforce vulnerability reporting and remediation timelines and ensure compliance with internal policies and external regulations.
  • Serve as a subject matter expert on vulnerability reporting processes, tools, and best practices, providing guidance and support to internal teams as needed.
  • Communicate effectively with external vendors and partners regarding vulnerabilities affecting third-party software or services used by the organization.
  • Continuously evaluate and improve the vulnerability reporting process to enhance efficiency, accuracy, and effectiveness.

Qualifications:
  • Bachelor's degree in cybersecurity, information technology, or related field.
  • 1+ years of experience in cybersecurity or IT governance, with a focus on patch management.
  • In-depth knowledge of patch management principles, processes, and best practices.
  • Understanding of vulnerability assessment tools, such as Nessus, Qualys, Rapid7, or similar, and their output formats.
  • Excellent analytical and problem-solving skills, with the ability to assess and prioritize vulnerabilities based on risk and potential impact.
  • Proficiency in data analysis and reporting tools, such as Microsoft Excel, Power BI, or similar.
  • Strong communication and interpersonal skills, with the ability to effectively communicate technical information to non-technical stakeholders.
  • Experience with vulnerability tracking and management systems, such as JIRA, ServiceNow, or similar.
  • Knowledge of common vulnerability databases and classification systems, such as CVE, CVSS, and CWE.
  • Ability to work independently and collaboratively in a fast-paced environment with multiple stakeholders and competing priorities.
  • Strong understanding of cybersecurity frameworks, compliance standards (e.g., NIST, CIS), and regulatory requirements related to patch management


Salary Range:
$75,000 - $120,000 Annual
The range quoted above applies to the role in the primary location specified. If the candidate would ultimately work outside of the primary location above, the applicable range could differ.


  • Princeton, United States SciTec Full time

    SciTec has been awarded multiple government contracts and is growing our creative Team! SciTec, Inc. is a dynamic small business with the mission to deliver advanced sensor data processing technologies and scientific instrumentation capabilities in support of National Security and Defense. We support customers throughout the Department of Defense and U.S....


  • Princeton, United States Bristol Myers Squibb Full time

    Working with Us Challenging. Meaningful. Life-changing. Those aren't words that are usually associated with a job. But working at Bristol Myers Squibb is anything but usual. Here, uniquely interesting work happens every day, in every department. From optimizing a production line to the latest breakthroughs in cell therapy, this is work that transforms the...


  • Princeton, New Jersey, United States S&P Global Full time

    About the Role:Grade Level (for internal use):13Job DescriptionS&P Dow Jones Indices is seeking a Director, Cloud Engineering to be a key player in the Infrastructure Engineering team to secure AWS Cloud environment used for running index applications in accordance with industry best practices and internal policies. This role requires a seasoned engineer who...


  • Northeastern United States Albury Wodonga Health Full time

    Dynamic work environment and team focussed culture Career opportunities and support for professional development Picturesque NE Victoria location close to regional attractions Who are we? Albury Wodonga Health (AWH) is the largest regional health service between Sydney and Melbourne, located in the twin cities of Albury and Wodonga. Our dedicated...


  • Princeton, NJ, United States State Street Corporation Full time

    Who we are looking for The State Street Middleware Application Infrastructure Team supports IBM MQ and Kafka suites across the Bank. The successful candidate will provide technical expertise and leadership to the Messaging Operations Team. The position requires effective communication and technical skills with a willingness to learn and implement...


  • Quincy, MA, United States State Street Corporation Full time

    Who we are looking for The Emerging Technologies Governance Lead will establish and lead emerging technologies governance, commensurate with evolving risk profile, global footprint and corporate and regulatory expectations. The role supports State Street's strategic objectives to prioritize risk excellence and deliver innovative solutions in a safe and...

  • IT Network

    4 weeks ago


    Princeton, United States NJ CURE Full time

    Job DescriptionJob DescriptionREGISTER - CURE Auto Insurance Careers (candridsoftware.com)The IT Network & Security Team Lead takes a lead in the day-to-day activities and operations of the IT environment of the organization, ensuring that systems, services, and infrastructure work reliably and securely. The IT Network & Security Team Lead is a hands-on...


  • Princeton, New Jersey, United States S&P Global Full time

    About the Role:Grade Level (for internal use):14S&P Global delivers essential intelligence that powers decision making. We provide the world's leading organizations with the right data, connected technologies and expertise they need to move ahead. As part of our team, you'll help solve complex challenges that equip businesses, governments, and individuals...


  • Princeton, United States Royal DSM Full time

    Project Management Office Lead, Key Global Accounts Princeton, NJ Hybrid The role concerns global business support for Key Global Accounts. Being a business partner, supporting on strategy, collaborating across the organization, sharing best practice Project Management, Office, Management, Global, Lead, Account, Business Services, Manufacturing

  • Network Lead

    7 days ago


    Princeton, United States Omni Inclusive Full time

    Key Pointers: Preferred location is for Boston, MA and Princeton, NJ onsiteMinimum 11years exp in NetworkingVersa SDWAN Experience is a mustVersa Certification is mustProficiency in troubleshooting, build and configuration of Versa (Mandatory) and Wireless Network technologies including standalone/stacked Routers, Switches, Nexus Switches, Firewall,...


  • Princeton, United States Princeton University Full time

    Overview This position is responsible for leading the development and implementation of the PPPL electrical safety program, consistent with Laboratory Environment, Safety, and Health (ES&H) policies and US Department of Energy requirements. The objective of this program is to limit the risks to employees, the general public, the environment, and equipment...

  • Lead Service Designer

    1 month ago


    Princeton, United States Maximus Services, LLC Full time

    **Description & Requirements** At Maximus, we are leading the way in digital transformation for our government clients. The Lead Service Designer will play a pivotal role in our Digital Solutions organization and tell the story of how we are fundamentally changing public program experiences to improve service delivery aligned with the mission requirements of...


  • Princeton, United States PeopleShare Full time

     PeopleShare is hiring an Office Admin with great customer service skills for a well known family owned produce farm in Princeton NJ!Job Details for an Office Admin:Pay: $20-21/hrSCHEDULE/HOURS: 25 hours per week (flexible schedule)Responsibilities for Office Admin:Provide customer service, answer phones and emailAccounts payable and accounts...

  • Privacy Officer

    2 weeks ago


    Somerset, NJ, United States Barnabas Health Medical Group Full time

    Privacy Officer for RWJBarnabas Health Medical GroupResponsible for the privacy activities of the RWJBarnabas Health Medical Group. The Privacy Officer will identify opportunities to reduce privacy risks and establish a safer experience for our employees and patients. This position serves as a resource for providers and staff and partners with the...


  • Princeton, United States PeopleShare Inc Full time

    PeopleShare is hiring an Office Admin with great customer service skills for a well known family owned produce farm in Princeton NJ! Job Details for an Office Admin: Pay: $20-21/hr SCHEDULE/HOURS: 25 hours per week (flexible schedule) Responsibilities for Office Admin: Provide customer service, answer phones and email Accounts payable and accounts...

  • VP, Brand Management

    22 hours ago


    Princeton, NJ, United States NRG Energy Full time

    As an NRG employee, we encourage you to take charge of your career and development journey. Your growth is key to our ongoing success-take the lead in shaping your career development, goals and future! NRG is seeking a VP, Data Privacy to join our legal team and lead the management of our Data Security across the organization, including customer privacy....


  • New York, NY, United States Focus Capital Markets Full time

    We are looking for a leader with past experience in building and implementing a data governance program in a technically innovative firm to optimize the value of our data assets and digital products that provide revenue-generating insights. In this role, you will oversee the strategy of data governance from its conception to implementation, creating unified...


  • Milwaukee, WI, United States Northwestern Mutual Full time

    At Northwestern Mutual, we are strong, innovative and growing. We invest in our people. We care and make a positive difference. * *This position is a hybrid position. On-site days will be required (2 days if in the NYC office or 3 days if in the Milwaukee office) What's the Role? If you are a motivated and...


  • Princeton, United States AppLab Systems Inc Full time

    Role : Azure Lead DevOps Engineer Location : Chicago IL - 3 Days in client office & 2 days remote The Azure Lead DevOps Engineer will work within the global Azure Cloud Services team who are responsible for building highly resilient, scalable, reusable and performant Azure infrastructure in an automated and efficient manner. The Azure Lead DevOps Engineer...


  • Bridgewater, NJ, United States Cognizant Full time

    Business Information Security Officer (BISO) Lead, Cognizant Consulting Banking and Financial Services New Jersey ABOUT US Cognizant is one of the world's leading professional services companies, transforming clients' business, operating, and technology models for the digital era. Our unique industry-based, consultative approach helps clients envision,...