Head of Vulnerability

2 weeks ago


New York NY United States MassMutual Full time

Overview:
We are seeking a highly skilled and strategic leader to join our organization as the Head of Vulnerability & Business Information Risk Management. In this role, you will be responsible for overseeing and enhancing our vulnerability management program and application security practices. You will lead a team of experts to identify, assess, prioritize, and mitigate vulnerabilities across our systems and applications, ensuring the integrity and security of our technology infrastructure.


Key Responsibilities

  • Leadership and Strategy:
    • Develop and execute a comprehensive vulnerability management strategy aligned with organizational goals and industry best practices.
    • Provide strategic direction and vision for application security initiatives, integrating security into the software development lifecycle (SDLC).
  • BISO and Enterprise Advisory Services:
    • Working closely with business leaders, technology leaders, and privacy professionals to assure the organization meets current standards, complies with regulatory requirements, and addresses the future direction of the business.
  • Team Management:
    • Lead and mentor a team of vulnerability management and application security professionals, fostering a culture of excellence, innovation, and collaboration.
    • Define roles, responsibilities, and career development paths within the team to promote growth and maximize performance.
  • Vulnerability Assessment and Remediation:
    • Oversee the identification, assessment, and prioritization of vulnerabilities across infrastructure, networks, and applications.
    • Implement effective remediation strategies and controls to mitigate identified vulnerabilities promptly.
  • Application Security Governance:
    • Establish and enforce application security policies, standards, and guidelines to ensure compliance with regulatory requirements and industry standards (e.g., OWASP).
    • Conduct regular security assessments and audits of applications to identify security gaps and recommend solutions.
    • Work with developers and architects to ensure security is appropriately built in the development cycle. Coordinate the performance of internal and external network and systems vulnerability assessments and penetration tests.
  • Collaboration and Communication:
    • Collaborate with cross-functional teams including IT operations, development, architecture, and risk management to integrate security into the overall IT strategy.
    • Communicate security risks and recommendations to senior leadership and stakeholders, advocating for necessary investments and resources.
  • Incident Response and Continuous Improvement:
    • Develop and maintain incident response plans and procedures related to vulnerabilities and application security incidents.
    • Drive continuous improvement initiatives to enhance the effectiveness and efficiency of vulnerability management and application security processes.

Required Skills and Qualifications:

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field; advanced degree preferred.
  • Proven experience (8+ years) in vulnerability management, application security, or related cybersecurity roles, with at least 5 years in a leadership capacity.
  • Deep technical expertise in vulnerability assessment tools, application security testing methodologies, and threat modeling.
  • Strong understanding of regulatory requirements, compliance frameworks (e.g., PCI-DSS, GDPR), and industry standards (e.g., NIST, ISO 27001).
  • Demonstrated ability to develop and execute strategic initiatives, manage budgets, and drive organizational change.
  • Excellent communication skills, with the ability to articulate complex technical concepts to non-technical stakeholders and influence decision-making at all levels.
     

Preferred Qualifications:

  • Industry certifications such as CISSP, CISM, CEH, or GIAC certifications (e.g., GPEN, GWAPT).
  • Experience with cloud security architecture and technologies (e.g., AWS, Azure, GCP).
  • Knowledge of DevSecOps principles and practices, including automation of security testing and monitoring.

#LI-MC1

MassMutual is an Equal Employment Opportunity employer Minority/Female/Sexual Orientation/Gender Identity/Individual with Disability/Protected Veteran. We welcome all persons to apply. Note: Veterans are welcome to apply, regardless of their discharge status.

If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need.

  • New York, United States MassMutual Full time

    Overview: We are seeking a highly skilled and strategic leader to join our organization as the Head of Vulnerability & Business Information Risk Management. In this role, you will be responsible for overseeing and enhancing our vulnerability management program and application security practices. You will lead a team of experts to identify, assess,...

  • Head of Vulnerability

    2 weeks ago


    New York, United States MassMutual Full time

    Job DescriptionOverview:We are seeking a highly skilled and strategic leader to join our organization as the Head of Vulnerability & Business Information Risk Management. In this role, you will be responsible for overseeing and enhancing our vulnerability management program and application security practices. You will lead a team of experts to identify,...


  • New York, New York, United States Crdit Agricole S.A. Full time

    Job SummaryThe Head of Vulnerability Management and Security Operations reports to the Chief Information Security Officer and is responsible for managing senior and junior IT Security engineers in security monitoring, remediating all security-related alerts & reports, and overseeing all IT Security engineering security projects.Key ResponsibilitiesDevelop...

  • Head of Vulnerability

    2 weeks ago


    Hartford, CT, United States MassMutual Full time

    Overview:We are seeking a highly skilled and strategic leader to join our organization as the Head of Vulnerability & Business Information Risk Management. In this role, you will be responsible for overseeing and enhancing our vulnerability management program and application security practices. You will lead a team of experts to identify, assess, prioritize,...

  • Head Nurse

    2 weeks ago


    New York, New York, United States Hope for Haiti Full time

    Job Title: Head NurseHope for Haiti is seeking a highly skilled and experienced Head Nurse to join our team in Les Cayes, Haiti. As a key member of our healthcare team, the Head Nurse will be responsible for ensuring the delivery of high-quality patient care, supervising nursing staff, and contributing to the development of our healthcare programs.Key...


  • New York, New York, United States Crédit Agricole S.A. Full time

    Job DescriptionJob Title: Head of Vulnerability Management and Security Operations, AmericasJob Summary:The Head of Vulnerability Management and Security Operations reports to the Chief Information Security Officer and is responsible for managing senior and junior IT Security engineers in security monitoring, remediating all security-related alerts &...


  • New York, New York, United States Abridge Full time

    Job Title: Head of Information TechnologyAbridge is seeking an experienced Head of Information Technology to lead our IT function and drive the development, implementation, and maintenance of our technology infrastructure. As a key member of our leadership team, you will be responsible for ensuring the security, reliability, and scalability of our systems,...


  • New York, New York, United States MarketAxess Full time

    About UsMarketAxess is a leading financial technology company that is revolutionizing the way the world trades fixed-income securities. Our mission is to provide a secure, efficient, and transparent platform for our clients to buy and sell securities. We are committed to innovation and excellence in everything we do.The RoleWe are seeking a highly skilled...


  • New York, United States The Phoenix Group Full time

    Head of Cyber Security -- 2 days on-site per weekResponsibilities:Lead and support Engineering teams, customers, and the Cyber Security organization in managing and driving critical programs.Provide strategic leadership to the IT Infrastructure and Security teams, ensuring effective oversight of all cybersecurity operations.Collaborate with other business...


  • New York, United States The Phoenix Group Full time

    Head of Cyber Security -- 2 days on-site per weekResponsibilities:Lead and support Engineering teams, customers, and the Cyber Security organization in managing and driving critical programs.Provide strategic leadership to the IT Infrastructure and Security teams, ensuring effective oversight of all cybersecurity operations.Collaborate with other business...


  • New York, New York, United States MarketAxess Full time

    About UsMarketAxess is a leading financial technology company that is revolutionizing the way the world trades. Our mission is to provide a secure, efficient, and transparent platform for buying and selling securities.We are on a journey to digitally transform one of the world's largest financial markets, enabling the shift from analog, phone-based trading...

  • Head Mixologist

    1 week ago


    New York, New York, United States FUSION OF FOODS NY CORP Full time

    Job Title: Head BartenderWe are seeking a highly skilled and experienced Head Bartender to join our team at Fusion of Foods NY Corp. As a key member of our bar team, you will be responsible for delivering exceptional service and crafting high-quality drinks that exceed our customers' expectations.Key Responsibilities:Supervise and train bartenders, barbacks,...


  • Marysville, OH, United States Honda Development and Manufacturing of America Full time

    What Makes a Honda, is Who makes a HondaHonda has a clear vision for the future, and it’s a joyful one.  We are looking for individuals with the skills, courage, persistence, and dreams that will help us reach our future-focused goals. At our core is innovation. Honda is constantly innovating and developing solutions to drive our business with record...


  • Marysville, OH, United States Honda Development and Manufacturing of America Full time

    What Makes a Honda, is Who makes a HondaHonda has a clear vision for the future, and it’s a joyful one.  We are looking for individuals with the skills, courage, persistence, and dreams that will help us reach our future-focused goals. At our core is innovation. Honda is constantly innovating and developing solutions to drive our business with record...


  • New York, United States MarketAxess Full time

    About Us  MarketAxess is on a journey to digitally transform one of the world’s largest financial markets, enabling the shift from analog, phone-based trading to a fully electronic marketplace. Why does this matter? Because our platform makes trading fixed-income more accessible, ultimately improving transparency, efficiency, and competition in the...


  • New York, United States MarketAxess Full time

    About Us  MarketAxess is on a journey to digitally transform one of the world’s largest financial markets, enabling the shift from analog, phone-based trading to a fully electronic marketplace. Why does this matter? Because our platform makes trading fixed-income more accessible, ultimately improving transparency, efficiency, and competition in the...

  • Unit Head

    1 month ago


    New York, United States City of New York Full time

    Company DescriptionJob Description TASK FORCE: HOUSING AND HOMELESSNESS POLICY DEVELOPMENT AND IMPLEMENTATION UNIT:Asylum Seekers JOB TITLE: One (1) Unit Head CONTROL CODE: HHPDI-25-01 SUMMARY: The Mayor's Office of Management and Budget (OMB) is the City government's chief financial agency. OMB's staff assembles and oversees the Mayor's expense and capital...


  • new york city, United States The Phoenix Group Full time

    Head of Cyber Security -- 2 days on-site per weekResponsibilities:Lead and support Engineering teams, customers, and the Cyber Security organization in managing and driving critical programs.Provide strategic leadership to the IT Infrastructure and Security teams, ensuring effective oversight of all cybersecurity operations.Collaborate with other business...


  • New York, New York, United States Academy of Warren Full time

    About the PositionWe are seeking an experienced and skilled professional to lead our Claims Management team as the Head of Claims Management. This is an exciting opportunity to join the Academy of Warren, a leading health insurance provider in Tasmania, and contribute to the success of our organization.Key ResponsibilitiesOversee the implementation of the...

  • Head of Engineering

    1 month ago


    New York, United States Dune Security Full time

    Role Overview:Dune Security is seeking a visionary and strategic Head of Engineering to lead our dynamic engineering team, which is the driving force behind Dune Security’s groundbreaking solutions. In this pivotal role, you will be responsible for shaping the technical direction of the company, driving innovation, and ensuring that our engineering...