Principal, Exposure Analysis & Coordination

Fifth Third Bank

Cincinnati (OH)

On-site

USD 97,000 - 208,000

Full time

19 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Fifth Third Bank in Cincinnati, OH seeks a Principal, Exposure Analysis & Coordination to lead the enterprise exposure response across security, risk, legal and business teams.

You will develop playbooks, drive cross-functional coordination, and provide executive updates on active exposures, remediation progress and program maturity. Strong automation and communication skills are essential to improve responses to emerging threats.

Qualifications

  • Bachelor's degree in Computer Science/Information Systems (or equivalent).
  • 8+ years IT experience, incl. 6+ years in security development.
  • Experience leading large cross-functional response or remediation.
  • Strong understanding of vulnerability and exposure management.
  • Proven ability to influence stakeholders in a matrixed org.

Responsibilities

  • Lead the Exposure Analysis & Coordination function and enterprise exposure response.
  • Develop procedures, playbooks, and escalation criteria.
  • Drive enterprise-wide coordination among tech, security, risk, and business teams.
  • Provide executive updates and risk-based recommendations.
  • Lead post-event root cause analysis and continuous improvement.
  • Identify automation opportunities for exposure intake and reporting.

Job description

Make banking a Fifth Third better®

We connect great people to great opportunities. Are you ready to take the next step? Discover a career in banking at Fifth Third Bank.

We connect great people to great opportunities. Are you ready to take the next step? Discover a career in banking at Fifth Third Bank.

The Principal, Exposure Analysis & Coordination is responsible for leading the Bank's capability to assess, coordinate, and manage response to urgent cybersecurity exposures. This role focuses on emerging threats that require rapid enterprise coordination, including zero-day vulnerabilities, pre-CVE and non-CVE security issues, vendor advisories, third‑party product exposures, cloud security concerns, and other significant cybersecurity risks that may not fit traditional vulnerability management processes.

Working across Information Security, Technology, Risk, Legal, and business teams, the Principal provides leadership during active exposure events while building a sustainable, repeatable process that improves the organization's ability to respond to future threats.

Exposure Analysis & Coordination Leadership
  • Lead the Exposure Analysis & Coordination function and serve as the primary authority for enterprise exposure response.
  • Establish and maintain operating procedures, response playbooks, escalation criteria, and engagement models.
  • Provide leadership and guidance during active exposure events.
  • Drive enterprise-wide coordination across technology, security, risk, and business stakeholders.
  • Ensure response activities remain aligned with enterprise risk priorities and regulatory expectations.
Reporting, Metrics & Program Maturity
  • Develop and maintain reporting that provides visibility into active exposures, response effectiveness, remediation progress, and operational trends.
  • Define and monitor key performance indicators and operational metrics.
  • Identify recurring themes, process gaps, and systemic issues through analysis of historical events.
  • Provide executive-level reporting and recommendations to support risk-based decision making.
  • Drive ongoing maturity of the program through continuous measurement and improvement.
Root Cause Analysis & Continuous Improvement
  • Lead post-event reviews and root cause analysis activities.
  • Identify opportunities to reduce future exposure through process improvements, control enhancements, automation, and governance changes.
  • Translate lessons learned into actionable improvements.
  • Maintain and improve response playbooks, procedures, and documentation standards.
Automation & Process Optimization
  • Identify, prioritize, and implement opportunities to automate exposure intake, validation, evidence collection, status tracking, reporting, and closure activities.
  • Define automation requirements and partner with security and technology teams to develop secure, reliable and scalable workflows.
  • Establish controls, monitoring, and exception-handling processes to ensure automated workflows remain accurate, auditable, and aligned with risk-management expectations.
  • Measure automation effectiveness and use operational data to reduce manual effort, improve response speed, and strengthen process consistency.
Stakeholder & Executive Engagement
  • Communicate effectively with technical teams, business leaders, and executive stakeholders.
  • Translate technical exposure and remediation information into clear, concise updates tailored to executives and technology owners.
  • Communicate changes in risk, scope, priority, dependencies, and target dates promptly, and confirm stakeholder understanding of required actions.
  • Provide clear and concise status updates during active events.
  • Escalate significant risks, unresolved issues, and critical decisions as appropriate.
  • Build strong partnerships across security, technology, and business functions.
Qualifications
Required
  • Bachelor's degree in Computer Science/Information Systems or equivalent combination of education and experience. Master's degree a plus.
  • Industry Standard Certifications such as, but not limited to: CompTIA A+, CompTIA Network +, CompTIA Security +, ISC2 CISSP, and EWS are preferred.
  • Eight+ years of IT work experience relevant to the position, including at least six years in a hands‑on information security development role.
  • Extensive experience in cybersecurity, vulnerability management, incident response, security operations, technology risk, or related disciplines.
  • Experience leading large‑scale, cross‑functional response or remediation efforts.
  • Strong understanding of vulnerability and exposure management practices.
  • Proven ability to influence stakeholders across a matrixed organization.
  • Exceptional verbal and written communication skills.
  • Experience identifying and delivering workflow automation or orchestration opportunities in vulnerability management.
  • Ability to define automation requirements, acceptance criteria, controls, exception handling, and measurable outcomes in partnership with technical teams.
  • Strong written and verbal communication skills, including the ability to translate complex technical risk into clear actions and executive‑level summaries.
Technical Requirements
  • Hands‑on proficiency with Python scripting for workflow automation, data processing, validation, and operational reporting.
  • Ability to develop, test, troubleshoot, document, and maintain secure, reusable scripts with appropriate logging, error handling, and exception management.
  • Experience integrating systems and working with structured data formats such as JSON and CSV.
  • Working knowledge of source control and collaborative development practices.
  • Ability to query, transform, and analyze operational or security data using SQL, Python data libraries, or comparable tools.
  • Familiarity with security platforms, ticketing systems, workflow‑orchestration tools, and dashboarding technologies used to automate and monitor exposure‑management processes.
  • Experience applying generative AI capabilities to vulnerability management use cases.
Preferred
  • Hands‑on offensive security experience validating real‑world exploitability and reachability, including attack paths, access, exposed services, privileges, and security controls.
  • Experience using approved offensive security techniques, proof‑of‑concept testing, and security tools to validate vulnerability conditions and distinguish theoretical severity from demonstrated exposure.
  • Ability to partner across security teams and clearly document validation evidence, compensating controls, limitations, and conclusions to inform risk prioritization, remediation, leadership decisions, and auditability.
  • Validate the effectiveness of compensating controls (countermeasures) to determine whether existing security controls materially reduce exploitability, reachability, or potential impact, and incorporate the results into exposure and remediation decisions.
  • Experience within large, regulated organizations.
  • Familiarity with cloud security, application security, threat intelligence, and vulnerability management technologies.
  • Experience presenting to senior leadership and executive audiences.
Position not available for immigration sponsorship
Principal, Exposure Analysis & Coordination

Total Base Pay Range 96,500.00 - 207,500.00 USD Annual

At Fifth Third, we understand the importance of recognizing our employees for the role they play in improving the lives of our customers, communities and each other. Our Total Rewards include comprehensive benefits and differentiated compensation offerings to give each employee the opportunity to be their best every day.

The base salary for this position is reflective of the range of salary levels for all roles within this pay grade across the U.S. Individual salaries within this range will vary based on factors such as role, relevant skillset, relevant experience, education and geographic location. In addition to the base salary, this role is eligible to participate in an incentive compensation plan, with any such payment based upon company, line of business and/or individual performance.

Our extensive benefits programs are designed to support the individual needs of our employees and their families, encompassing physical, financial, emotional and social well‑being. You can learn more about those programs on our 53.com Careers page at: https://www.53.com/content/fifth-third/en/careers/benefits.html or by consulting with your talent acquisition partner.

LOCATION -- Cincinnati, Ohio 45202

Attention search firms and staffing agencies: do not submit unsolicited resumes for this posting. Fifth Third does not accept resumes from any agency that does not have an active agreement with Fifth Third. Any unsolicited resumes – no matter how they are submitted – will be considered the property of Fifth Third and Fifth Third will not be responsible for any associated fee.

Fifth Third Bank, National Association is proud to have an engaged and inclusive culture and to promote and ensure equal employment opportunity in all employment decisions regardless of race, color, gender, national origin, religion, age, disability, sexual orientation, gender identity, military status, veteran status or any other legally protected status.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal, Exposure Analysis & Coordination
Principal, Exposure Analysis & Coordination

Fifth Third • Cincinnati (OH)

On-site
USD 97,000 - 208,000
Principal Cyber Threat Intelligence Analyst
Principal Cyber Threat Intelligence Analyst

Fifth Third Bank, National Association • United States

Remote
USD 97,000 - 208,000
Product Security Governance Principal
Product Security Governance Principal

Fifth Third Bank • Ohio

Hybrid
USD 97,000 - 208,000
Financial Institutions Group – Insurance Corporate Client Director
Financial Institutions Group – Insurance Corporate Client Director

Fifth Third Bank • Charlotte (NC)

On-site
USD 97,000 - 208,000
Financial Institutions Group – Insurance Corporate Client Director
Financial Institutions Group – Insurance Corporate Client Director

Fifth Third • Cincinnati (OH)

On-site
USD 97,000 - 208,000
Investment Banking Senior Associate - Tech and Telecom
Investment Banking Senior Associate - Tech and Telecom

Fifth Third Bank • Charlotte (NC)

On-site
USD 110,000 - 180,000
Senior Technology Risk Advisor
Senior Technology Risk Advisor

Fifth Third • Cincinnati (OH), Northern (KY)

On-site
USD 110,000 - 160,000
Investment Banking Principal/VP
Investment Banking Principal/VP

Fifth Third Bank • Charlotte (NC)

On-site
USD 150,000 - 210,000
Investment Banking Principal/VP
Investment Banking Principal/VP

Fifth Third Bank • Cleveland (OH)

On-site
USD 180,000 - 260,000
Commercial Support Client Specialist
Commercial Support Client Specialist

Fifth Third Bank • Farmington Hills (MI)

On-site
USD 45,000 - 65,000