Threat & Vulnerability Management Lead

First-Horizon-Bank

Raleigh (NC)

On-site

USD 180,000 - 290,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

First-Horizon-Bank in Raleigh is seeking a senior cybersecurity leader to guide a multi-discipline security team covering application security, threat detection, vulnerability management, and red/purple team activities. The role sits at the intersection of secure development, threat readiness, and real-world risk reduction within a large, multi-cloud online banking environment.

You will lead 6–12 security professionals, own detection-focused outcomes, collaborate with SOC and risk leaders, and

Qualifications

  • 10+ years in cybersecurity across multiple domains
  • 3–5+ years leading multi-disciplinary security teams
  • Experience reducing attack surface and speeding detection
  • Strong knowledge of AppSec, threat detection, and cloud-native CI/CD

Responsibilities

  • Lead a multi-discipline security team (6–12 direct reports)
  • Oversee threat detection, vulnerability management, and red/purple team activities
  • Align security tooling with engineering and risk leaders
  • Drive secure development practices and incident readiness
  • Escalate high-risk cyber issues to executives

Skills

People leadership
Threat detection
Application security
Penetration testing
Adversary simulation
CI/CD
Executive presence

Tools

Veracode
Invicti
Burp

Job description

This is a senior cybersecurity leader leads a multi-discipline security team covering application security, threat detection, vulnerability management, red/purple team activities, and security automation, with a heavy emphasis on detection, readiness, and real-world risk reduction.

The role is at the intersection of secure development, threat detection, and operational maturity within a large, multi-cloud online banking environment. Large-bank experience is preferred.

What the Manager Owns
  • People leadership for a multi-discipline cyber team (6 to 12 direct reports)

  • Threat detection

  • Penetration testing readiness and follow-through

  • Red / blue / purple team integration

  • Reducing enterprise attack surface

Key Responsibilities

Leadership & Team Management

  • Manage and develop a team of security professionals across vulnerability management, threat detection & threat intelligence, red/purple team disciplines, and security automation

  • Act as the escalation point for high-risk or high-impact cyber issues

Application Security

  • Oversee SAST, DAST, SCA, manual testing, and penetration testing programs

  • Drive shift-left AppSec - IDE scanning, CI/CD integration, and secure coding practices

  • Reduce testing cycles and downstream findings by improving early detection

  • Operate tool-agnostic (e.g., Veracode, Invicti, Burp)

  • Ensure AppSec supports modern cloud-native and DevOps environments

  • Build trusted relationships with Shadow IT owners, and progressively align with security tooling, testing, and IT security practices.

Threat Detection & Purple Teaming

  • Own detection-focused security outcomes, not just vulnerability reporting

  • Work closely with SOC and IR teams to improve detection signals

  • Use pen-test and red-team insights to strengthen blue-team defenses

  • Apply purple-team thinking to close gaps between offense and defense

Penetration Testing & Offensive Readiness

  • Ensure strong internal and third-party penetration testing coverage

  • Validate that findings are meaningful, prioritized, and remediated

  • Use offensive testing to drive real defensive improvements

Vulnerability & Configuration Risk Reduction

  • Oversee vulnerability and configuration management programs

  • Maintain hardening standards, baselines, and remediation tracking

  • Reduce enterprise attack surface across cloud, applications, and infrastructure

  • Integrate AppSec, pen-test, and vulnerability data into risk-based prioritization

Environment & Scope
  • Multi-cloud environment

  • High-availability online banking systems

  • Highly regulated financial services setting

  • Heavy collaboration with engineering, cloud, risk, and executive leaders

Required Experience
  • 10+ years in cybersecurity spanning AppSec, threat detection, incident response, and vulnerability management

  • 3–5+ years leading multi-disciplinary security teams

  • Demonstrated success reducing attack surface and improving detection speed

  • Strong understanding of application security; threat detection & response; penetration testing & adversary simulation; and CI/CD and cloud-native environments

  • Comfortable presenting to and influencing executives

  • Large-bank experience preferred, with the adaptability to thrive in a smaller-bank environment

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat & Vulnerability Management Lead
Threat & Vulnerability Management Lead

First Horizon Corp. • Raleigh (NC), Northern (KY)

Hybrid
USD 180,000 - 260,000
Threat & Vulnerability Management Lead
Threat & Vulnerability Management Lead

First Horizon Bank • Raleigh (NC)

On-site
USD 170,000 - 250,000
Senior Threat & Vulnerability Lead – Cloud & AppSec
Senior Threat & Vulnerability Lead – Cloud & AppSec

First-Horizon-Bank • Raleigh (NC)

On-site
USD 180,000 - 290,000
Cybersecurity Incident Response Team Lead – Vice President
Cybersecurity Incident Response Team Lead – Vice President

Crédit Agricole Group • New York (NY)

On-site
USD 150,000 - 185,000
Senior Threat & Vulnerability Leader | AppSec & Detection
Senior Threat & Vulnerability Leader | AppSec & Detection

First Horizon Corp. • Raleigh (NC), Northern (KY)

Hybrid
USD 180,000 - 260,000
Principal Security Engineer
Principal Security Engineer

Valley Bank • Morristown (NJ)

On-site
USD 180,000 - 240,000
Cyber Security Manager
Cyber Security Manager

Vaco Recruiter Services • Kerrville (TX)

On-site
USD 140,000 - 190,000
Cloud Security Engineering Manager
Cloud Security Engineering Manager

CIBR Warriors • Town of Texas (WI)

On-site
USD 150,000 - 210,000
Director, Cybersecurity
Director, Cybersecurity

Socket.dev • Dallas (TX)

On-site
USD 140,000 - 230,000
Senior Director, Threat Management
Senior Director, Threat Management

ECOLAB • Saint Paul (MN)

On-site
USD 180,000 - 300,000