SVP, Vulnerability Management & Cloud Security Posture Platform Engineering

BNY

New York (NY)

On-site

USD 150,000 - 200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible global resources
Paid volunteer time
Health, dental, vision insurance

Job summary

BNY is seeking an SVP for Vulnerability Management & Cloud Security to run and engineer enterprise cybersecurity platforms. The role focuses on enhancing security posture and managing risk across various cloud environments.

Candidates need to have a strong background in vulnerability management and cloud security, along with excellent operational discipline and knowledge of networking technologies.

BNY offers competitive compensation and benefits, including flexible resources to support personal resilience and financial goals.

Qualifications

  • Hands-on experience running and engineering enterprise cybersecurity platforms, especially in large financial institutions.
  • Strong operational discipline including service health monitoring, change management, and lifecycle management.
  • Strong networking knowledge including TCP/IP, DNS, firewalls, and routing.

Responsibilities

  • Own engineering and operational accountability for vulnerability management tooling.
  • Run critical cybersecurity platforms, ensuring platform health and production stability.
  • Engineer platform improvements to enhance reliability and performance.

Skills

Vulnerability management
Cloud security posture management
Automation
API integration
Incident response

Education

Bachelor’s degree in computer science or related discipline

Tools

Qualys
AWS
Azure

Job description

SVP, Vulnerability Management & Cloud Security Posture Platform Engineering

Location: New York, NY; Pittsburgh, PA; or Washington, DC.

This high-impact, deeply technical individual contributor role focuses on running and engineering enterprise cybersecurity platforms that support vulnerability management, asset discovery, network and infrastructure scanning, cloud security posture management, cloud-native risk visibility, reporting, and remediation enablement.

The role sits at the intersection of hands‑on platform operations, deployment and execution, troubleshooting, automation engineering, service ownership, and technical leadership.

Responsibilities
  • Own engineering and operational accountability for enterprise vulnerability management and cloud security posture management tooling.
  • Run critical cybersecurity platforms day to day, including platform health, configuration, access, integrations, upgrades, onboarding, troubleshooting, vendor support, and production stability.
  • Engineer platform improvements that increase reliability, scalability, coverage, automation, performance, data quality, and operational resilience.
  • Manage platform configuration, tenant administration, access models, scanner and agent lifecycle, cloud connectors, onboarding standards, and service health.
  • Support scanning across servers, endpoints, databases, network devices, appliances, cloud assets, containers, external-facing assets, and other enterprise technologies.
  • Partner with network and infrastructure teams on scanner placement, network zones, routing, firewall rules, segmentation, latency, reachability, authenticated scanning, and scan troubleshooting.
  • Drive asset discovery, inventory reconciliation, coverage reporting, ownership validation, and integration with CMDB and authoritative asset sources.
  • Build and maintain automation, APIs, configuration management, dashboards, reporting workflows, and data pipeline integrations, including integrations that ingest asset, ownership, cloud, and configuration data from enterprise systems and publish vulnerability and posture data to downstream remediation, reporting, and risk platforms.
  • Partner with vulnerability management teams to enable prioritization, remediation tracking, SLA governance, exception workflows, and major vulnerability response.
  • Own platform monitoring, health checks, operational dashboards, incident response, vendor escalations, disaster recovery readiness, and business continuity procedures.
  • Support SSO, RBAC, privileged access, service accounts, API tokens, access recertification, segregation of duties, audit evidence, and regulatory reporting.
  • Troubleshoot complex issues across tools, agents, scanners, APIs, cloud connectors, networks, identity systems, data pipelines, vendor platforms, and downstream reporting consumers.
  • Create dynamic engineering solutions using languages such as Python, Go, Java, or similar.
  • Mentor engineers, improve runbooks and documentation, and raise the technical bar through hands‑on platform expertise.
Qualifications
  • Hands‑on experience running and engineering enterprise cybersecurity platforms, especially vulnerability management, scanning, asset discovery, cloud security posture, or cloud-native application protection platforms in large financial institutions.
  • Strong operational discipline, including production support, incident response, change management, service health monitoring, vendor escalation, and lifecycle management.
  • Strong engineering mindset, including automation, API integration, configuration management, repeatable deployment patterns, data quality improvement, and toil reduction.
  • Strong understanding of vulnerability management operating models, including remediation tracking, SLA governance, exceptions, ownership validation, and major vulnerability response.
  • Strong networking knowledge, including TCP/IP, routing, DNS, firewalls, proxies, load balancers, network segmentation, NAT, packet flows, latency, and reachability troubleshooting.
  • Experience scanning and assessing diverse enterprise technologies, including servers, endpoints, network devices, databases, appliances, cloud assets, containers, and externally exposed systems.
  • Knowledge of scanner architecture, agent health, network zones, scan routes, authenticated scanning, credential management, and scan troubleshooting.
  • Experience with cloud environments, including AWS, Azure, and GCP, cloud connectors, IAM, APIs, and security control frameworks.
  • Experience integrating cybersecurity platforms with CMDB, ticketing systems, reporting platforms, data pipelines, cloud platforms, vulnerability management systems, and enterprise dashboards.
  • Strong understanding of access management, including SSO, MFA, RBAC, privileged access, service accounts, API tokens, and recertification.
  • Programming and automation skills using Python, Go, Java, or similar.
  • Ability to debug complex issues across platforms, agents, scanners, cloud connectors, APIs, data pipelines, identity systems, networks, firewalls, routing paths, and vendor services.
  • Experience supporting audit, regulatory reporting, evidence retention, operational controls, and production change management.
  • A mindset focused on automation, scalability, governance, resilience, and reducing operational friction.
  • Experience with Kubernetes and container vulnerability management, including cluster visibility, container image assessment, runtime context, registry integrations, cloud-native asset inventory, and remediation workflows.
Preferred Qualifications
  • Experience with the following tooling: Qualys, Wiz.io, Lumeta, or similar vulnerability management, asset discovery, network visibility, and cloud security posture platforms.
  • Experience operating or engineering cybersecurity platforms in FedRAMP-authorized or FedRAMP-aligned cloud environments.
  • Familiarity with FedRAMP control expectations, evidence collection, vulnerability scanning requirements, continuous monitoring, access governance, and cloud security operations.
Success Profile
  • Becomes a senior technical authority for both operating and engineering vulnerability management and cloud security posture tooling.
  • Bachelor’s degree in computer science or a related discipline, or equivalent work experience required, advanced degree preferred.
  • 10‑12 years of experience in information security or related technology experience required, experience in the securities or financial services industry is a plus.
  • Keeps critical cybersecurity platforms stable, healthy, upgraded, monitored, documented, and supportable.
  • Improves platform reliability, scan health, agent health, connector health, data quality, and operational visibility.
  • Expands coverage across infrastructure, applications, business units, cloud accounts, containers, network devices, appliances, and external-facing assets.
  • Enables reliable reporting, remediation tracking, SLA governance, audit evidence, and regulatory support.
  • Reduces manual effort through automation, repeatable onboarding, self-service intake, standardized runbooks, and engineered controls.
  • Strengthens access governance, platform controls, service ownership discipline, and production resilience.

This role is for someone who wants to run, own, and engineer the platforms that define cyber risk visibility across the enterprise. Day-to-day platform execution and long-term engineering decisions will directly impact security posture, vulnerability response, regulatory confidence, and operational resilience across BNY.

Benefits

BNY offers highly competitive compensation, benefits, and wellbeing programs rooted in a strong culture of excellence and our pay-for-performance philosophy. We provide access to flexible global resources and tools for your life’s journey. Focus on your health, foster your personal resilience, and reach your financial goals as a valued member of our team, along with generous paid leaves, including paid volunteer time, that can support you and your family through moments that matter.

BNY assesses market data to ensure a competitive compensation package for employees. Base salary for this position varies by location and experience, and may include discretionary incentive awards. Eligible employees may participate in a 401(k) plan and health, dental, vision, and basic life insurance plans, as well as paid time off benefits.

Equal Opportunity

BNY is an Equal Employment Opportunity/Affirmative Action Employer – Underrepresented racial and ethnic groups, Females, Individuals with Disabilities, Protected Veterans.

If hired, the employee will be in an at-will position and the company reserves the right to modify compensation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SVP, Vulnerability Management & Cloud Security Posture Platform Engineering
SVP, Vulnerability Management & Cloud Security Posture Platform Engineering

BNY Mellon • New York (NY)

On-site
USD 150,000 - 200,000
Flexible working resources
Generous paid leaves
401(k) plan
Senior Vice President, Resiliency Lead
Senior Vice President, Resiliency Lead

BNY Mellon • New York (NY)

Hybrid
USD 130,000 - 160,000
Competitive compensation
Generous paid leaves
Wellbeing programs
Senior Vice President, Senior Cloud Security Engineer
Senior Vice President, Senior Cloud Security Engineer

慨正橡扯 • New York (NY)

On-site
USD 83,000 - 209,000
Flexible global resources
Generous paid leaves
Wellbeing programs
Senior Vice President, Senior Cloud Security Engineer New York, NY, United States and 1 Posted [...]
Senior Vice President, Senior Cloud Security Engineer New York, NY, United States and 1 Posted [...]

BNY Mellon • New York (NY)

On-site
USD 83,000 - 209,000
Competitive compensation
Flexible global resources
Generous paid leaves
SVP, Vulnerability & Cloud Security Platform Engineering
SVP, Vulnerability & Cloud Security Platform Engineering

BNY • New York (NY)

On-site
USD 150,000 - 200,000
Flexible global resources
Paid volunteer time
Health, dental, vision insurance
Senior Director of Network Security – Engineering Lead
Senior Director of Network Security – Engineering Lead

BNY Mellon • New York (NY)

On-site
USD 136,000 - 350,000
Highly competitive compensation
Generous paid leaves
Access to flexible global resources
Director, Head of Engineering – Operational Risk
Director, Head of Engineering – Operational Risk

BNY • New York (NY)

On-site
USD 250,000 - 350,000
Competitive compensation
401(k) plan
Health insurance
+1
Senior Vice President, Resiliency Lead
Senior Vice President, Resiliency Lead

BNY • New York (NY)

On-site
USD 200,000 - 350,000
Senior Vice President, Business & Function Finance
Senior Vice President, Business & Function Finance

BNY • Pittsburgh

On-site
USD 250,000 - 360,000
Cybersecurity Architect
Cybersecurity Architect

BNY Mellon • Pittsburgh

On-site
USD 140,000 - 190,000
Generous paid leaves including paidvol
Volunteer time off