Manager, Exposure Management

Nelnet

Centennial (CO)

Hybrid

USD 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical insurance
Dental insurance
Vision insurance
HSA
FSA
Paid time off
401K

Job summary

Nelnet is seeking an experienced Cybersecurity Manager, Exposure Management to lead vulnerability operations, attack surface management, and application security programs. The role focuses on unifying exposure data across code, config, cloud, and external surfaces, advancing a CTEM-based approach with AI-assisted prioritization.

The ideal candidate has 3–6 years in cybersecurity, 1–2 years leadership, strong communication, and experience with vulnerability platforms like Tenable or Wiz.

Qualifications

  • Bachelor’s degree in Computer Science, Information Security, or related field; or equivalent experience.
  • 3–6 years in cybersecurity including exposure to vulnerability management, application security, and/or attack surface management.
  • 1–2 years in team lead or management roles.
  • Working knowledge of vulnerability management platforms (e.g., Tenable, Wiz) and ASM tooling; understanding of SAST/DAST/SCA.
  • Understanding of risk-based prioritization and CTEM concepts.
  • Ability to influence outcomes without direct reporting lines.
  • Strong communication, presentation, and interpersonal skills.
  • Analytical, problem-solving, and decision-making abilities.
  • Familiarity with security certifications (CISSP, CISM, GIAC) is desirable.

Responsibilities

  • Provide leadership, guidance, and mentorship to a team of vulnerability analysts and application security practitioners.
  • Lead the evolution of the exposure management operating model and drive team development.
  • Evolve roles toward judgment, validation, and stakeholder engagement as automation matures.
  • Oversee a unified exposure management pipeline across a dynamic vulnerability portfolio.
  • Operate the CTEM cycle of scoping, discovery, prioritization, validation, and mobilization.
  • Integrate findings across code, configuration, cloud, and external ASM into a single risk view.

Skills

Leadership
Vulnerability management
Application security
CTEM
AI/automation
Cloud security
Communication
Decision making

Education

Bachelor’s degree in Computer Science or related field

Tools

Tenable/Wiz (vulnerability platforms)
Attack Surface Management tooling
SAST/DAST/SCA

Job description

Nelnet is a diversified and innovative company committed to enriching lives through the power of service as a student loan servicer, professional services company, consumer loan originator and servicer, payments processor, renewable energy solutions, and K-12 and higher education expert. For over 40 years, Nelnet has been serving its customers, associates, and communities.

The perks of working at Nelnet go beyond our benefits package. When you join the Nelnet team, you're part of a community invested in the success of each individual. That support comes through in our work, as we are united by our mission of creating opportunities for people where they live, learn, and work.

Nelnet is seeking an experienced and motivated Cybersecurity Manager, Exposure Management to lead our vulnerability operations, attack surface management, and application security functions. The ideal candidate will combine strong cybersecurity knowledge with exceptional leadership and stakeholder-management skills, and a demonstrated ability to drive remediation outcomes across engineering, infrastructure, and business teams.

In this role you will lead a single, unified exposure management program --- bringing findings from code, configuration, cloud, infrastructure, and external attack surface into one prioritized, risk-based view. You will guide the team through a transformative evolution of how the function operates, adopting a Continuous Threat Exposure Management (CTEM) approach and leveraging AI and automation to optimize the prioritization of work activity. As the Manager, Exposure Management, you will be responsible for reducing enterprise risk by ensuring the right exposures are identified, prioritized, and remediated through strong partnerships across the organization.

This position requires work in support of the Company's contract with the United States Department of Education ("ED"). As such, the United States Government requires that any applicant for this position must complete United States Government security clearance. Effective June 1, 2018, ED has informed Nelnet that security clearance applications for foreign nationals are not being accepted or processed. In light of this direction from ED, Nelnet will be unable to hire applicants without United States citizenship for such positions.

This position offers a hybrid work option. Nelnet values flexibility and understands the importance of work-life integration. Our hybrid work environment allows associates within 30 miles of an office to work remotely for part of the week, while also fostering collaboration and team connection through in-office presence.

Please note that we are unable to provide visa sponsorship for this position. To be considered, candidates must already be authorized to work in the United States without the need for current or future sponsorship as security clearance is required.

Responsibilities
  • Leadership and Team Development:
  • Provide leadership, guidance, and mentorship to a team of vulnerability analysts and application security practitioners.
  • Foster a collaborative, high-performance environment and lead the team through a transformative evolution of its operating model.
  • Conduct performance evaluations, identify training needs, and support professional development.
  • Evolve team roles toward judgment, validation, and stakeholder engagement as automation and AI-assisted workflows mature.
  • Exposure Management Operations:
  • Oversee a unified exposure management pipeline --- intake, enrichment, prioritization, and remediation orchestration --- across a dynamic, continuously changing vulnerability portfolio.
  • Operate the program as a Continuous Threat Exposure Management (CTEM) cycle of scoping, discovery, prioritization, validation, and mobilization.
  • Integrate findings across code, configuration, cloud, infrastructure, and external Attack Surface Management (ASM) into a single, risk-based view.
  • Develop and maintain exposure management policies, procedures, and workflows.
  • Prioritization and Risk-Based Remediation:
  • Apply risk-based prioritization beyond CVSS --- including exploitability, reachability, asset criticality, and threat-intelligence context --- to focus effort where risk is greatest.
  • Leverage AI and automation to enrich, rank, and continuously optimize the prioritization of work activity.
  • Establish and maintain a documented risk-acceptance workflow with clear business-owner accountability.
  • Define and report remediation SLAs, velocity, and risk-reduction metrics that leadership can trust.
  • Application Security:
  • Guide enterprise application security programs, including code analysis, secure development standards, developer guidance, and a security champions program.
  • Partner with development teams to integrate security into the SDLC and CI/CD workflows.
  • Stakeholder Engagement and Collaboration:
  • Build credibility and drive remediation outcomes with development, infrastructure, and platform teams across the organization.
  • Translate exposure into the appropriate framing for each audience --- technical detail for engineers, delivery impact for managers, and business risk for executives.
  • Partner with GRC and internal audit to ensure defensible process, evidence, and risk-register alignment.
  • Deliver clear, concise exposure narratives to the CISO and executive leadership, including a board-ready view of enterprise exposure.
  • Satisfy FSA/OSA and similar regulated-process obligations as a baseline of the program.
Qualifications
  • Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent experience.
  • Minimum of 3--6 years of experience in cybersecurity, including exposure to vulnerability management, application security, and/or attack surface management.
  • Minimum of 1--2 years of team lead or management experience.
  • Working knowledge of vulnerability management platforms (e.g., Tenable, Wiz, or equivalents), attack surface management tooling, and application security concepts (e.g., SAST, DAST, SCA).
  • Understanding of risk-based prioritization and modern exposure management concepts, including Continuous Threat Exposure Management (CTEM).
  • Demonstrated ability to influence and drive outcomes across teams without direct reporting authority.
  • Excellent communication, presentation, and interpersonal skills, with the ability to translate technical risk into clear business language.
  • Strong analytical, problem-solving, and decision-making skills.
  • Ability to work effectively in a fast-paced and evolving environment.
  • Relevant certifications such as CISSP, CISM, or SANS GIAC certifications (e.g., GCIH, GSEC) are highly desirable.
  • Preferred Qualifications:
  • Experience operating, building, or maturing a CTEM or exposure management program.
  • Familiarity with AI- and automation-assisted security workflows.
  • Familiarity with cloud security concepts and technologies (e.g., AWS, Azure, GCP).
  • Knowledge of relevant regulatory and compliance frameworks (e.g., NIST, ISO 27001, PCI DSS).
  • Experience with secure SDLC practices and security champions programs.
  • Experience with scripting languages (e.g., Python, PowerShell).

Compensation range for this role is $120,000-$160,000 annually, depending on experience.

#LI-Hybrid

#LI-CW1

Our benefits package includes medical, dental, vision, HSA and FSA, generous earned time off, 401K/student loan repayment, life insurance & AD&D insurance, employee assistance program, employee stock purchase program, tuition reimbursement, performance-based incentive pay, short- and long-term disability, and a robust wellness program. Click here to learn more about our benefits: LINK (http://nelnetinc.com/careers/benefits/) .

Nelnet is committed to providing a welcoming and respectful workplace where all associates have the opportunity to succeed. As an Equal Opportunity Employer, we ensure that all qualified applicants are considered for employment. Employment decisions are made without regard to race, color, religion/creed, national origin, gender, sex, marital status, age, disability, use of a guide dog or service animal, sexual orientation, military/veteran status, or any other status protected by federal, state, or local law. We value the unique contributions of every team member and believe that a positive work environment benefits everyone.

Qualified individuals with disabilities who require reasonable accommodations in order to apply or compete for positions at Nelnet may request such accommodations by contacting Corporate Recruiting at 402-486-5725 or corporaterecruiting@nelnet.net .

Nelnet is a Drug Free and Tobacco Free Workplace.

Use of Artificial Intelligence in Hiring

We may use automated or artificial intelligence enabled tools to assist with the initial review of applications, such as identifying relevant skills or experience. These tools are used to support human review and do not make hiring decisions. A recruiter reviews applications and determines which candidates move forward in the hiring process. For more information, see our Privacy Policy and Pre-Use Notice: Automated Tools in Hiring

You may know Nelnet as the nation's largest student loan servicer -- but we do more than that. *A lot more.* We're also a professional services company, consumer loan originator and servicer, payment processor, renewable energy innovator, and K-12 and higher education expert (and that's just a shortlist). For over 40 years, we've been serving our customers, associates, and communities to make dreams possible.

EEO Info (https://nelnetinc.com/wp-content/uploads/EEO-poster.pdf) | EEO Letter (https://nelnet.com/wp-content/uploads/EEO-Jeffs-Letter.pdf) | EPPA Info (https://nelnetinc.com/wp-content/uploads/Employee-Polygraph-Protection-Act-Poster.pdf) | FMLA Info (https://nelnetinc.com/wp-content/uploads/FMLA-Leave.pdf)

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability Management Engineer
Vulnerability Management Engineer

Nelnet, Inc. • Centennial (CO)

Hybrid
USD 75,000 - 125,000
Medical
Dental
Vision
+6
Cybersecurity Application Security Engineer
Cybersecurity Application Security Engineer

Nelnet, Inc. • Centennial (CO)

Hybrid
USD 90,000 - 125,000
Medical
Vulnerability Management Engineer
Vulnerability Management Engineer

your Jared • Centennial (CO), Northern (KY)

Hybrid
USD 75,000 - 125,000
Medical insurance
Dental insurance
Vision insurance
+4
CyberSecurity Senior Analyst
CyberSecurity Senior Analyst

Nelnet, Inc. • Centennial (CO)

Hybrid
USD 85,000 - 130,000
Medical
Dental
Vision
+3
Senior DevOps and Cloud Engineer - NBS
Senior DevOps and Cloud Engineer - NBS

nelnet • Lincoln (NE)

On-site
USD 120,000 - 130,000
medical
dental
vision
+10
Sr Application Security Engineer
Sr Application Security Engineer

nelnet • Lincoln (NE)

On-site
USD 135,000 - 150,000
Medical insurance
Dental insurance
Vision insurance
+6
Vulnerability Management Engineer
Vulnerability Management Engineer

nelnet • Centennial (CO)

Hybrid
USD 75,000 - 125,000
Medical benefits
Dental benefits
Vision benefits
+2
Security Advisor
Security Advisor

Nelnet • Columbus (OH)

On-site
USD 110,000 - 125,000
Medical, dental, and vision insurance
401K and student loan repayment
Generous earned time off
+2
Program Manager, Managed Services - CampusGuard
Program Manager, Managed Services - CampusGuard

Nelnet • Hartford (CT)

On-site
USD 70,000 - 100,000
Medical, dental, vision
401K
Tuition reimbursement
+1
Program Manager, Managed Services - CampusGuard
Program Manager, Managed Services - CampusGuard

Nelnet • Columbus (OH)

On-site
USD 70,000 - 100,000
Medical, dental, vision
HSA and FSA
401K/student loan repayment
+4