AVP Vulnerability Management Program Manager

Posted 4 Days Ago
Be an Early Applicant
Centro, Maripí, Boyacá, COL
In-Office
Senior level
Fintech
The Role
Leads the enterprise vulnerability management program, including governance, risk-based prioritization, remediation coordination, exception management, reporting, audit evidence, regulatory readiness, and continuous improvement. Partners across cybersecurity, technology, risk, audit, compliance, business units, and third-party providers to reduce exposure and maintain accountability. Provides executive communication, oversees program resources, develops metrics and evidence, and supports the maturity of vulnerability management processes and controls.
Summary Generated by Built In

Address

We’re always looking for bright individuals to join our growing organization. As a part of the First Financial Family, we will invest in your development and provide a dynamic work environment where you’re challenged, valued and empowered every day. We strive to be the best destination for the industry’s top talent, creating a diverse, collaborative workplace that celebrates innovation and change. We are one team, working together to get things done.

Job Description:

Office Location:

Abilene, Texas, United States

ROLE SUMMARY

The Assistant Vice President, Vulnerability Management Program Manager leads the ongoing administration, governance, and continuous improvement of First Financial Bankshares' enterprise Vulnerability Management Program. This role ensures vulnerabilities are identified, prioritized, tracked, remediated, validated, reported, and evidenced in accordance with approved standards, risk management expectations, and applicable regulatory requirements.

The position provides dedicated program leadership across Information Security, technology operations, application teams, risk management, Internal Audit, third-party providers, and other stakeholders. The role translates technical exposure into clear business risk, drives remediation accountability, coordinates governance and reporting, and helps maintain a sustainable and demonstrably effective program.

KEY RESPONSIBILITIES

Program Leadership & Governance
  • Lead the day-to-day administration and ongoing maturity of the enterprise Vulnerability Management Program.
  • Maintain the program roadmap, governance documentation, operating procedures, standards alignment, and recurring review activities.
  • Coordinate the Vulnerability Management Council, including agendas, decisions, action items, escalations, and follow-through.
  • Promote consistent execution of program requirements across technology functions, support organizations, and applicable business units.
Risk-Based Vulnerability Oversight
  • Oversee the vulnerability lifecycle from identification and validation through prioritization, remediation, exception management, risk acceptance, and closure.
  • Ensure prioritization considers exploitability, asset criticality, business impact, exposure, and other approved risk factors.
  • Monitor aging, overdue items, recurring issues, and material exposure; coordinate timely escalation and corrective action.
  • Provide oversight of vulnerabilities affecting internally managed, jointly managed, and vendor-managed technology environments.
Remediation Coordination & Accountability
  • Coordinate remediation activity across infrastructure, endpoints, networks, applications, databases, cloud services, and third-party technology providers.
  • Partner with accountable technology owners to establish remediation plans, remove execution barriers, and confirm sustainable closure.
  • Oversee dedicated vulnerability remediation resources and coordinate supplemental partner support as appropriate.
  • Validate that closure and exception records contain sufficient evidence to demonstrate appropriate disposition.
Performance Reporting & Executive Communication
  • Produce and maintain recurring program reporting for management and established governance bodies, including performance, risk, trend, maturity, and enhancement information.
  • Monitor approved service levels, key performance indicators, key risk indicators, backlog, aging, exceptions, and remediation outcomes.
  • Present program status and material issues in clear business terms to executive management, risk committees, Internal Audit, and other stakeholders.
  • Maintain consistent definitions, methodologies, and supporting evidence for reported measures.
Audit, Regulatory & Evidence Readiness
  • Coordinate vulnerability management evidence for Internal Audit, independent reviews, and regulatory examinations.
  • Maintain organized, complete, and repeatable evidence of program operation, governance decisions, remediation activity, reporting, exceptions, and management oversight.
  • Support responses to audit and regulatory requests and track related commitments through resolution.
  • Identify control or evidence gaps and coordinate timely corrective action.
Program Improvement & Capability Development
  • Assess program effectiveness and recommend improvements to processes, governance, reporting, technology enablement, automation, and resource alignment.
  • Monitor relevant threat, vulnerability, regulatory, and industry developments and evaluate their implications for the program.
  • Promote integration of vulnerability management practices into technology operations, change management, asset management, configuration management, and third-party oversight.
  • Support training, awareness, and role clarity for stakeholders with vulnerability management responsibilities.
Leadership & Collaboration
  • Provide direction, coaching, and performance support for assigned team members and program resources.
  • Build productive relationships across cybersecurity, technology, risk, audit, compliance, and business functions.
  • Influence outcomes without relying solely on direct authority and foster shared accountability for risk reduction.
  • Perform other duties and responsibilities as assigned.

MINIMUM QUALIFICATIONS

  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Business Administration, Risk Management, or a related field, or an equivalent combination of education and relevant experience.
  • Seven or more years of progressive experience in cybersecurity, information security, technology risk, technology operations, or a related discipline.
  • Three or more years of experience leading vulnerability management, cyber risk, security operations, governance, or comparable enterprise programs.
  • Demonstrated experience coordinating cross-functional remediation or risk-reduction initiatives in a complex technology environment.
  • Working knowledge of vulnerability assessment, risk-based prioritization, remediation governance, exception management, validation, metrics, and evidence practices.
  • Experience communicating technical risk, program performance, and decisions to management and non-technical stakeholders.
  • Strong written communication, facilitation, organization, analytical judgment, and stakeholder management skills.

PREFERED QUALIFICATIONS

  • MBA or advanced technical degree (Computer Science, Cybersecurity, Information Systems)
  • Experience in banking, financial services, or another highly regulated industry.
  • Experience supporting Internal Audit, independent assessments, or regulatory examinations.
  • Experience building, formalizing, or maturing an enterprise vulnerability management or cyber risk program.
  • Knowledge of recognized cybersecurity and control frameworks, including NIST Cybersecurity Framework, NIST Special Publication 800-53, CIS Controls, and FFIEC cybersecurity guidance.
  • Professional certification such as CISSP, CISM, CRISC, CGRC, GIAC, PMP, or a comparable credential.
  • Experience with enterprise vulnerability assessment, workflow, reporting, data visualization, or security automation platforms.

WORK ENVIRONMENT AND EXPECTATIONS

Onsite presence is required in accordance with company expectations for the position.  Hybrid work arrangement will be considered based on the candidate’s qualifications.

May require occasional work outside normal business hours to support urgent vulnerability response, material escalations, examinations, or business needs.

Must maintain the confidentiality and integrity of sensitive security, risk, audit, regulatory, employee, customer, and company information.

Commitment to a professional workplace that supports collaboration, respect, equal opportunity, and inclusion.

The above statements reflect the general details considered necessary to decide the principal functions of the job identified and shall not be construed as a detailed description of all work requirements that may be

inherent in the job.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor’s legal duty to furnish information. 41 CFR 60-1.35(c)

Skills Required

  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Business Administration, Risk Management, or a related field, or equivalent education and relevant experience
  • Seven or more years of progressive experience in cybersecurity, information security, technology risk, technology operations, or a related discipline
  • Three or more years of experience leading vulnerability management, cyber risk, security operations, governance, or comparable enterprise programs
  • Experience coordinating cross-functional remediation or risk-reduction initiatives in a complex technology environment
  • Working knowledge of vulnerability assessment, risk-based prioritization, remediation governance, exception management, validation, metrics, and evidence practices
  • Experience communicating technical risk, program performance, and decisions to management and non-technical stakeholders
  • Strong written communication, facilitation, organization, analytical judgment, and stakeholder management skills
  • MBA or advanced technical degree
  • Experience in banking, financial services, or another highly regulated industry
  • Experience supporting Internal Audit, independent assessments, or regulatory examinations
  • Experience building, formalizing, or maturing an enterprise vulnerability management or cyber risk program
  • Knowledge of NIST Cybersecurity Framework, NIST Special Publication 800-53, CIS Controls, and FFIEC cybersecurity guidance
  • Professional certification such as CISSP, CISM, CRISC, CGRC, GIAC, PMP, or comparable credential
  • Experience with enterprise vulnerability assessment, workflow, reporting, data visualization, or security automation platforms

First Financial Bank Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about First Financial Bank and has not been reviewed or approved by First Financial Bank.

  • Retirement Support Offerings include a 401(k) with employer match, profit-sharing, and a company pension plan, with ESOP/KSOP options that can provide an ownership stake. Financial education and planning tools are referenced to support long‑term savings.
  • Leave & Time Off Breadth Paid vacation and sick time are available to both part‑time and full‑time employees, along with paid holidays and paid volunteer time. Parental leave further expands time‑off options for family needs.
  • Healthcare Strength Comprehensive healthcare coverage includes health, dental, and vision insurance, with long‑term disability and life insurance also mentioned. These core protections create a robust baseline for health and income security.

First Financial Bank Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Cincinnati, OH
1,998 Employees

What We Do

First Financial Bank has been in the business of client service and success for more than 150 years. With more than 150 banking centers across Ohio, Indiana, Kentucky and Illinois, we combine world-class financial expertise with personal community service that builds lifelong relationships. We have combined the resources and expertise of a mega-bank with the care and perspective of a neighborhood community bank. We make our decisions locally so we can provide clients with the appropriate guidance and solutions to achieve their financial goals.

Similar Jobs

Cloudflare Logo Cloudflare

Senior Customer Engineer, LATAM - MCR Bogotá, Colombia.

Cloud • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
Colombia
4400 Employees

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Sr. Sales Associate III

eCommerce • Fashion • Retail • Sales • Wearables • Design
Remote or Hybrid
14 Locations
16000 Employees
15-20 Hourly

Domino Data Lab Logo Domino Data Lab

Support Engineer

Artificial Intelligence • Machine Learning
Remote or Hybrid
10 Locations
200 Employees

Luxury Presence Logo Luxury Presence

Product Engineer

Marketing Tech • Real Estate • Software • PropTech • SEO
Easy Apply
Remote or Hybrid
12 Locations
500 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account