AVP Cybersecurity, Threat and Vulnerability Management

4 days ago


Irving, Texas, United States GM Financial Full time
Description

Flexible hybrid work environment: 4-days a week in office.

Why GMF Cybersecurity?

Our Cybersecurity team is tasked with security engineering, regulatory response, third party risk, and incident response capabilities necessary to secure GM Financial, the captive auto finance subsidiary of General Motors. Reporting directly to the CEO, our Cybersecurity team enjoys unprecedented support to deliver the highest level of security capabilities using cutting edge technologies and automating mundane tasks, allowing our teams to focus on interesting and rewarding security work. 

As a part of GM Financial, you'll have the opportunity to work on Cybersecurity projects across financial services, automotive, manufacturing, high-tech, and military industries. We are looking for team players who want the freedom to innovate leading edge capabilities to join our growing Cybersecurity team. 

Responsibilities

The Assistant Vice President, Threat & Vulnerability Management will lead the strategy and execution of our enterprise vulnerability management program. This role is responsible for identifying, prioritizing, and driving remediation of vulnerabilities across infrastructure, applications, and cloud environments. You will lead a team of professionals, implement risk-based processes, and partner with technology and business stakeholders to reduce exposure and strengthen our security posture.

In this role, you will:

Strategic Leadership

Develop and execute a comprehensive threat and vulnerability management strategy aligned with business objectives and risk appetite.

  • Establish governance for vulnerability scanning, prioritization, and remediation across all technology domains.

  • Define and track key performance indicators (KPIs) and service-level agreements (SLAs) to measure program effectiveness.

  • Build and mentor a high-performing team, fostering a culture of accountability and continuous learning.

Technical Oversight

  • Oversee vulnerability scanning and assessment for infrastructure, applications, and cloud platforms.

  • Implement risk-based prioritization using factors such as asset criticality, exploitability, and threat intelligence.

  • Ensure integration of vulnerability management processes into the software development lifecycle (SDLC) and change management workflows.

  • Maintain awareness of emerging threats, tools, and best practices to continuously improve program maturity.

Communication & Collaboration

  • Partner with IT, development, and business teams to ensure timely remediation of vulnerabilities.

  • Provide clear, actionable reporting to technical teams and concise risk summaries for senior leadership.

  • Act as a subject matter expert on vulnerability management and related security practices.

Qualifications

What makes you a dream candidate?

  • Strategic Leadership in TVM: Proven ability to lead enterprise-wide Threat & Vulnerability Management programs, aligning vulnerability remediation with business priorities and risk appetite.

  • Deep Expertise in Vulnerability Lifecycle: Advanced knowledge of vulnerability identification, risk scoring, prioritization, and remediation processes across complex, global environments.

  • Risk-Based Approach: Skilled in leveraging frameworks such as CVSS, NIST, and MITRE to assess and communicate risk effectively to technical and executive stakeholders.

  • Technology and Process Integration: Hands-on experience with vulnerability scanning tools (e.g., Qualys, Tenable, Rapid7) and application security and code scanning platforms (e.g., Checkmarx One, Veracode, SonarQube) and vulnerability reporting platforms for automated workflows and expedited reporting.

  • Regulatory and Compliance Alignment: Ensures TVM operations meet or exceed standards such as NIST, FFIEC, NYDFS, GDPR, CCPA/CPRA, and other global regulatory requirements.

  • Influential Communicator: Exceptional ability to translate technical risk into business impact, influencing senior leaders and driving accountability across IT and business units.

  • People-Centric Leadership: Strong track record in building and leading high-performing teams, fostering collaboration, and developing talent through coaching and mentorship.

  • Operational Excellence: Adept at managing multiple initiatives, prioritizing based on risk, and delivering measurable improvements in vulnerability posture under tight deadlines.

  • Industry Insight: Experience in financial services and automotive sectors, with a commitment to continuous improvement and innovation in vulnerability management practices.

Experience

  • Information Security Certifications preferred

  • Subject to stressful situations 

  • After-hours work and periodic 24x7 on call support may be required 

  • Some travel (estimated at 20%) may be required to support business needs 

  • 6 years of experience in large and complex business environments with a successful track record working directly with senior level management Req 

  • 5-7 years of experience in one or more of the following domains: Cybersecurity, Information Security, Network Engineering or Operations, Information Technology,

  • Application Development, Access Control, Security Governance, Risk Management, Software Development Security, Cryptography, Security Architecture and Design,

  • Operational Security, Business Continuity & Disaster Recovery, Legal Regulations, Investigations and Compliance, Physical (Environmental) Security, IT or Security

  • Audit, IT or Security Compliance required

  • Bachelor's Degree or equivalent experience Preferred 

What We Offer: Generous benefits package available on day one to include: 401K matching, bonding leave for new parents (12 weeks, 100% paid), tuition assistance, training, GM employee auto discount, community service pay and nine company holidays. 

Our Culture: Our team members define and shape our culture. We have an environment that welcomes new ideas, fosters integrity, and creates a sense of community and belonging. Here we do more than. work — we thrive. 

Compensation: Competitive salary and bonus eligibility; this role is eligible for company vehicle program. 

Work Life Balance: Flexible hybrid work environment, 4-days a week in office.

I-JI1

#LI-Hybrid

#GMFjobs



  • Irving, Texas, United States TEAM International Full time

    SENIOR VULNERABILITY MANAGEMENT ENGINEERNO 3RD PARTIES HERE PLEASEInformation SecurityIrving, TX - Hybrid (Monday, Wednesday, Thursday on-site | Tuesday, Friday remote)Contract Position (through May 2026)JOB DESCRIPTIONWe are seeking an experienced Senior Vulnerability Management Engineer to support and strengthen our client's enterprise vulnerability...


  • Irving, Texas, United States GM Financial Full time

    Hybrid work environment: 4 days onsite and 1 day remoteWhy GM Financial Cybersecurity?Innovation isn't just a talking point at GM Financial, it's how we operate. By joining our team, you'll work in a mission-focused environment with specialized teams, including Engineering, Threat Intelligence, Vulnerability Management, Incident Response, Firewall,...


  • Irving, Texas, United States Meriton Full time

    Meriton is a national team of experts driving HVAC innovation through a network of high-performing companies. From strategy and support to systems and solutions, we work behind the scenes to strengthen operations and build value—for our partners and our people.If you're looking to make an impact, we're glad you're here. At Meriton, you'll join a team that...


  • Irving, Texas, United States Trend Micro Full time

    Trend Micro, a global cybersecurity leader, helps make the world safe for exchanging digital information across enterprises, governments, and consumers.Fueled by decades of security expertise, global threat research, and continuous innovation, Trend harnesses AI to protect organizations and individuals across clouds, networks, devices, and endpoints.The...


  • Irving, Texas, United States Citi Full time $96,400 - $144,600

    Overview of the Role Citi, the leading global bank, has approximately 200 million customer accounts and does business in more than 160 countries and jurisdictions. Citi provides consumers, corporations, governments, and institutions with a broad range of financial products and services, including consumer banking and credit, corporate and investment banking,...


  • Irving, Texas, United States McKesson Full time $121,300 - $202,100

    McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve – we care.What you do at McKesson matters. We foster a...


  • Irving, Texas, United States NTT DATA North America Full time

    Req ID: 346537NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a Sr. Cybersecurity PM to join our team in REMOTE, Texas (US-TX), United States (US).**Job Description:Position Summary...


  • Irving, Texas, United States NTT DATA Full time

    Req ID: 346537NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a Sr. Cybersecurity PM to join our team in REMOTE, Texas (US-TX), United States (US). Job Description:Position Summary...


  • Irving, Texas, United States Robert Half Full time

    Full Time Direct Hire Permanent Role100% OnsiteNo SponsorshipNo C2CWe are seeking a skilled and motivated Sr Cloud Security Engineer to join our growing cybersecurity team. In this role, you will be responsible for securing cloud infrastructure, applications, and data across our Azure cloud platform. You will collaborate with DevOps, Infrastructure, and...


  • Irving, Texas, United States GM Financial Full time $105,000 - $175,000 per year

    Flexible hybrid work environment, 4 days a week in the office.Why GM Financial Cybersecurity?Innovation isn't just a talking point at GM Financial, it's how we operate. By joining our team, you'll work in a mission-focused environment with specialized teams, including Engineering, Threat Intelligence, Vulnerability Management, Incident Response, Firewall,...