Corporate Vice President - Head of Enterprise Vulnerability & Remediation

Reposted 18 Days Ago
Be an Early Applicant
New York, NY, USA
Hybrid
148K-211K Annually
Senior level
Artificial Intelligence • Cloud • Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Powered by purpose. Driven by people. Built to evolve.
The Role
Oversee vulnerability management strategy and execution across enterprise IT and cloud, ensuring risk reduction and compliance through effective governance. Manage incident response, integrate security practices with operations, and lead a team to improve security posture and responsiveness.
Summary Generated by Built In
Location Designation: Hybrid - 3 days per week
Role Summary
Lead the enterprise operating model for vulnerability and patch remediation across infrastructure, cloud, endpoints, and application-dependent services. This role will build and lead a centralized remediation function that converts vulnerability findings into measurable risk reduction through structured intake, prioritization, ownership assignment, accelerated patch execution, application validation, exception governance, and evidence-based closure.
The role is accountable for driving remediation performance across multiple teams, including Patch & Vulnerability Ops, Endpoint Patching SRE, Infrastructure Patching SRE, App Remediation / SRE partners, Security, Cloud, DevOps, and CIO application teams. Success requires strong operating discipline, clear executive reporting, automation-first execution, and the authority to escalate blockers when remediation stalls.
This leader will also guide the enterprise response to Mythos-related remediation priorities, including Critical VITs, High-priority vulnerabilities, AWS remediation, EOL OS modernization, browser/server hardening, and application regression testing automation.
What You'll Do:
Enterprise Vulnerability & Patch Operating Model
  • Build and lead the centralized Enterprise Vulnerability & Remediation function across infrastructure, endpoint, cloud, and application-dependent services.
  • Define the end-to-end intake-to-closure workflow for vulnerabilities, patches, Critical VITs, zero-days, EOL remediation, and exception handling.
  • Establish severity-based remediation lanes, including:
    • Same-day / P1 response for zero-days
    • 24-hour automated response for Critical VITs
    • 3-day cycle for High-priority patches
    • 6-day accelerated cycle for priority remediation
  • Ensure every vulnerability has clear ownership, target dates, remediation plan, validation evidence, and closure disposition.
  • Drive daily operational governance and weekly executive reporting across remediation workstreams.

Patch & Vulnerability Operations
  • Oversee centralized vulnerability intake, prioritization, SLA tracking, remediation coordination, reporting, and escalation.
  • Ensure findings from Qualys, Tanium, cloud tools, security alerts, vendor advisories, and exception requests are triaged and routed to accountable owners.
  • Maintain enterprise dashboards for open vulnerabilities, aging, SLA adherence, exception status, rollback activity, automation coverage, and closure evidence.
  • Drive remediation discipline across platform, endpoint, cloud, and application teams.
  • Ensure vulnerabilities are not closed until validated through scan results, automated testing, system health checks, or approved risk acceptance.

Endpoint Patching SRE Oversight
  • Lead the endpoint patching reliability function responsible for endpoint patch execution, deployment waves, reboot compliance, endpoint health, and rollback coordination.
  • Standardize endpoint patching controls across pilot rings, production waves, user-impact monitoring, failed install tracking, and exception handling.
  • Ensure endpoint patching supports accelerated remediation timelines while maintaining controls for VPN, EDR, authentication, productivity tools, and user-impacting issues.
  • Partner with Endpoint Engineering, Service Desk, Security, and Operations teams to resolve endpoint patch failures and reduce repeat defects.

Infrastructure Patching SRE Oversight
  • Lead the infrastructure patching reliability function across Windows, Linux, middleware, databases, cloud-hosted servers, and related platform services.
  • Establish lower-environment, canary, and production patching waves with clear go/no-go criteria.
  • Standardize patch baselines, maintenance windows, reboot strategy, rollback readiness, compensating controls, and patch failure handling.
  • Drive cloud patching execution through approved tools such as Qualys Patch Management, Tanium, AWS Systems Manager Patch Manager, and related automation platforms.
  • Ensure post-patch validation includes reboot success, service startup, monitoring agent health, scan validation, and closure evidence.

Application Remediation / SRE Coordination
  • Partner with CIO application teams, DevOps, and SREs to ensure application readiness does not become a blocker to vulnerability remediation.
  • Establish structured application-team engagement for ownership confirmation, business criticality, testing windows, release constraints, reboot approvals, and production sign-off.
  • Drive application regression testing automation to reduce manual validation time and enable accelerated patch cycles.
  • Ensure application teams define smoke tests, API checks, service checks, transaction validation, dependency checks, and pass/fail criteria.
  • Support application-level remediation for libraries, middleware compatibility, certificates, runtimes, code fixes, configuration changes, and dependency upgrades.
  • Escalate application readiness, code/configuration, or sign-off delays that threaten Mythos, CBS, AWS remediation, EOL remediation, or Critical VIT timelines.

AWS, Cloud, and EOL Remediation
  • Lead remediation governance for AWS/cloud patching, including non-production rollout, production rollout, BAU transition, tool enablement, and execution risk management.
  • Oversee remediation blockers such as non-reporting agents, root-volume constraints, reboot dependencies, application/SRE coordination, and access limitations.
  • Coordinate EOL OS modernization strategy with platform, cloud, vendor, and application teams.
  • Ensure EOL remediation is tracked through fresh build, replatforming, hardened AMIs, Terraform automation, CI/CD pipelines, EKS for container-ready workloads, and EC2 for non-container workloads.
  • Drive executive visibility into EOL exposure, impacted applications, SLT ownership, modernization waves, and dependency risks.

Automation, Tooling, and Evidence
  • Define the automation roadmap for patch deployment, health checks, application regression testing, scan validation, dashboards, and closure evidence.
  • Partner with DevOps and CIO teams to evaluate New Relic monitors, synthetic checks, service health dashboards, alert policies, and performance baselines as near-term accelerators for post-patch validation.
  • Ensure tooling supports vulnerability-informed remediation, automated deployment, compliance reporting, evidence capture, and closure workflows.
  • Drive integration across Qualys, Tanium, AWS Systems Manager, CI/CD platforms, CMDB, ITSM, monitoring tools, and reporting dashboards.

Exception, Risk, and Escalation Governance
  • Define and enforce exception standards, including business justification, compensating controls, expiration dates, remediation commitments, and approval authority.
  • Challenge unsupported or open-ended exceptions.
  • Escalate missed deadlines, unresolved blockers, owner gaps, testing delays, and unmanaged risk through formal governance channels.
  • Ensure remediation issues move to one of the required outcomes: deploy, fix, roll back, compensate, exception, or validated closure.

Authority and Scope
This role requires senior leadership endorsement to operate across organizational boundaries. The role holder is empowered to:
  • Set enterprise remediation expectations, timelines, and SLA discipline.
  • Require remediation plans and target dates from infrastructure, endpoint, cloud, application, and vendor teams.
  • Escalate unresolved blockers, missed timelines, and unmanaged risk.
  • Require time-bound exceptions with compensating controls and accountable owners.
  • Coordinate remediation activity spanning endpoints, servers, cloud, middleware, applications, EOL platforms, and critical vulnerabilities.
  • Drive CIO/application-team engagement where application validation, code changes, dependency fixes, or production sign-off are required.

Success Measures and Key Outcomes: First 6-12 Months
  • Operating model launched: Centralized vulnerability and patch remediation function established with clear roles, RACI, workflows, dashboards, and escalation paths.
  • Accelerated patch lanes operational: 24-hour Critical VIT, 3-day High-priority, and 6-day accelerated priority patching cycles implemented.
  • AWS/cloud patching stabilized: Qualys/cloud patching enabled, non-reporting agents and root-volume constraints tracked, and production patching moved into BAU.
  • EOL modernization governed: EOL OS exposure tracked by application, SLT, platform, modernization wave, and dependency status.
  • Application validation accelerated: Critical applications onboarded to smoke tests, health checks, New Relic or CI/CD validation, and exception-based review.
  • SLA performance improved: Reduction in aging Critical and High vulnerabilities, overdue remediation, and repeat exposure.
  • Evidence quality improved: Closure based on scan validation, automated test results, health checks, and documented remediation evidence.
  • Exception backlog controlled: Exceptions are time-bound, risk-reviewed, and actively managed.
  • Executive visibility established: Leadership reporting in place for backlog, SLA compliance, aging, closure, rollback, exceptions, automation coverage, and unresolved blockers.

What You'll Bring:
  • 12-15+ years of experience in IT Operations, Infrastructure, Security Engineering, Cloud Operations, SRE, or Enterprise Technology leadership.
  • 5+ years leading vulnerability management, patching, remediation, infrastructure operations, or enterprise reliability functions at scale.
  • Deep understanding of enterprise platforms, including Windows, Linux, endpoints, middleware, databases, AWS/cloud infrastructure, containers, and application-dependent services.
  • Experience with vulnerability and patching tools such as Qualys, Tanium, AWS Systems Manager Patch Manager, endpoint management platforms, CMDB, ITSM, and reporting dashboards.
  • Strong knowledge of patch management, change management, configuration management, exception governance, and evidence-based closure.
  • Experience coordinating application teams for testing, dependency remediation, code/configuration changes, release windows, and production sign-off.
  • Strong understanding of cloud remediation, EOL modernization, hardened images, Terraform, CI/CD, EKS, EC2, and DevOps operating models.
  • Demonstrated ability to influence senior stakeholders, drive accountability across organizational boundaries, and escalate unmanaged risk.
  • Strong executive communication skills with the ability to translate technical remediation risk into clear business impact and action plans.

Nice to Have
  • Experience in financial services or another highly regulated industry.
  • Familiarity with NIST CSF, CIS Controls, SOX, NYDFS, PCI, or similar regulatory/control frameworks.
  • Experience with New Relic, synthetic monitoring, application regression automation, CI/CD test orchestration, and evidence capture.
  • Certifications such as CISSP, CISM, CRISC, CCSP, AWS, ITIL, or SRE-related credentials.
  • Experience building remediation factories, centralized vulnerability operations, or large-scale EOL modernization programs.

Working Model
Hybrid role based in New York, NY with regular in-person collaboration for governance forums, planning sessions, executive reviews, and major remediation events. Occasional off-hours engagement will be required for zero-day response, Critical VIT remediation, production patching, cloud patching events, or major remediation campaigns.
This role operates at the intersection of IT Operations, Cybersecurity, Cloud, Endpoint, Infrastructure, DevOps, and CIO application teams to reduce enterprise risk while maintaining platform reliability and business continuity.
Pay Transparency
Salary Range: $147,500-$211,000
Overtime eligible: Exempt
Discretionary bonus eligible: Yes
Sales bonus eligible: No
Actual base salary will be determined based on several factors but not limited to individual's experience, skills, qualifications, and job location. Additionally, employees are eligible for an annual discretionary bonus. In addition to base salary, employees may also be eligible to participate in an incentive program.
Company Overview
At New York Life, our 180-year legacy of purpose and integrity fuels our future. As we evolve into a more technology-, data-, and AI-enabled organization, we remain grounded in the values that drive lasting impact.
Our diverse business portfolio creates opportunities to make a difference across industries and communities-inviting bold thinking, collaborative problem-solving, and purpose-driven innovation. Here, you'll find the rare balance of long-standing stability and forward momentum, supported by an inclusive team that honors tradition while embracing progress.
As a Fortune 100 mutual company, we offer a place to grow your skills, contribute to meaningful work, and deliver solutions that matter. Your ideas drive what's next, and your growth powers it.
Our Benefits
We provide a full package of benefits for employees - and have unique offerings for a modern workforce, including leave programs, adoption assistance, and student loan repayment programs. Based on feedback from our employees, we continue to refine and add benefits to our offering, so that you can flourish both inside and outside of work.Click hereto discover more about our comprehensive benefit options or visit our NYL Benefits Site.
Our Commitment to Inclusion
At New York Life, fostering an inclusive workplace is fundamental to who we are and how we serve our communities. We have a longstanding commitment to creating an environment where individuals can contribute their best and succeed together. This foundation is rooted in our core values of humanity and integrity, ensuring that every employee feels valued and supported. By embracing a broad range of perspectives and experiences, we achieve greater success and fulfill our promise of providing financial security and peace of mind to families across all communities. Click here to learn more about New York Life's leadership in this space.
Recognized as one of Fortune's World's Most Admired Companies, New York Life is committed to improving local communities through a culture of employee giving and volunteerism, supported by the Foundation. We're proud that due to our mutuality, we operate in the best interests of our policy owners. To learn more about career opportunities at New York Life, please visit the Careers page of www.NewYorkLife.com.
Visit our LinkedIn to see how our employees and agents are leading the industry and impacting communities.
Visit our Newsroom to learn more about how our company is constantly evolving to meet our clients' and employees' needs.
Job Requisition ID: 94038
#BI-Hybrid

Skills Required

  • 12-15+ years of experience in Infrastructure/IT Operations, Security Engineering, or SRE
  • 5+ years in senior leadership roles owning vulnerability management and/or patching
  • Deep understanding of enterprise infrastructure and platforms
  • Hands-on familiarity with vulnerability management tooling
  • Strong experience integrating vulnerability platforms with ITSM/CMDB
  • Proven track record building and running risk-based remediation programs
  • Solid knowledge of security frameworks and regulatory requirements
  • Demonstrated ability to influence senior stakeholders
  • Excellent communication, storytelling, and presentation skills
  • Experience in financial services or other highly regulated industries
  • Relevant certifications: CISSP, CISM, CRISC, cloud security certs, or ITIL/SRE credentials

What the Team is Saying

Tyrone
Emma
Deepa
Patricia
Joel
Nishit

New York Life Insurance Company Compensation & Benefits Highlights

  • Retirement Support The package includes a 401(k) with company match alongside a defined‑benefit pension for many eligible roles, with contributions and the match vested from day one. That increasingly rare combination strengthens long‑term financial security.
  • Parental & Family Support Paid New Parent leave was doubled to eight weeks for all parents, with birthing parents typically reaching up to about fourteen paid weeks when combined with short‑term disability. The offering also highlights fertility support, adoption assistance, and subsidized backup childcare.
  • Healthcare Strength Medical, dental, and vision coverage are paired with spending accounts, life and disability insurance, and an EAP, with some plans including a company‑funded HRA and wellness incentives. Additional resources such as virtual care and digital physical therapy are noted.

New York Life Insurance Company Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
12,000 Employees
Year Founded: 1845

What We Do

At New York Life, our 180-year legacy of integrity, mutuality, and financial strength fuels a future defined by bold transformation. As the largest mutual life insurance company in the U.S., we operate on behalf of our policy owners—not shareholders. That structure allows us to take a long-term view, investing in people, purpose, and innovation that endures. Guided by a clear enterprise vision to become a technology-, data-, and AI-powered company, we’re modernizing our platforms, rearchitecting experiences, and embedding intelligence across our products and services. Our mission has always been about helping people through life’s most meaningful moments. Today, technology is amplifying that mission—enabling us to serve clients, advisors, and communities in more personalized, proactive ways. With a diversified business portfolio spanning insurance, investments, retirement, group benefits, and direct-to-consumer offerings, New York Life delivers the stability of a Fortune 100 company with the agility of one that’s continuously evolving. We’re powered by a values-led culture, inclusive teams, and a shared belief that when our people thrive, so does our company. Here, tradition fuels momentum—and your ideas, energy, and growth power what’s next.

Why Work With Us

New York Life is transforming from the inside out—blending 180 years of trust with the velocity of innovation. What makes us different is our culture: grounded in integrity, humanity, and shared success—values that show up in how we work, lead, and grow. If you want a place where innovation has purpose—build what's next with us.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

New York Life Insurance Company Teams

Team
Internships and Early Career Programs
About our Teams

New York Life Insurance Company Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Typical time on-site: Not Specified
Company Office Image
HQNew York, NY
Company Office Image
Jersey City, NJ
Philadelphia, PA
Company Office Image
Tampa, FL
Company Office Image
White Plains, NY
Learn more

Similar Jobs

New York Life Insurance Company Logo New York Life Insurance Company

Associate Auditor

Artificial Intelligence • Cloud • Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Hybrid
New York, NY, USA
12000 Employees
52K-68K Annually

New York Life Insurance Company Logo New York Life Insurance Company

Associate - Statutory Accounting & Reporting

Artificial Intelligence • Cloud • Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Hybrid
New York, NY, USA
12000 Employees
65K-93K Annually

New York Life Insurance Company Logo New York Life Insurance Company

Scrum Master

Artificial Intelligence • Cloud • Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Hybrid
New York, NY, USA
12000 Employees
100K-143K Annually

New York Life Insurance Company Logo New York Life Insurance Company

Recruiter

Artificial Intelligence • Cloud • Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Hybrid
New York, NY, USA
12000 Employees
100K-128K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account