Who We Are
At Kyndryl, we run and reimagine the mission-critical technology systems that drive advantage for the world’s leading businesses. We are at the heart of progress; with proven expertise and a continuous flow of AI-powered insight, enabling smarter decisions, faster innovation, and a lasting competitive edge. For our people—Kyndryls—that means doing purposeful work that powers human progress. Join us and experience a flexible, supportive environment where your well-being is prioritized and your potential can thrive.
The Role
Who We Are
Kyndryl's Chief Information Security Office (CISO) is responsible for protecting the enterprise through effective cyber risk management, security governance, exposure reduction, and security validation. As cyber threats continue to evolve, our focus is not only on identifying vulnerabilities, but on ensuring risks are understood, prioritized, remediated, and validated through measurable outcomes.
We are seeking a highly motivated cybersecurity professional to join our Integrated Exposure Operations (IXO) team. This role plays a critical part in reducing organizational cyber risk through vulnerability management, security validation, penetration testing governance, and remediation orchestration across a complex global technology environment.
The Role
As a Cyber Security Penetration Testing Lead (Program Management), you will be responsible for coordinating and governing key exposure management and security validation activities across the enterprise. You will work closely with application owners, infrastructure teams, risk management functions, security engineering teams, and executive stakeholders to ensure security findings are effectively prioritized, remediated, and validated.
You will lead the operational management of penetration testing and security validation programs, ensuring assessments are planned, executed, tracked, and closed in accordance with enterprise security requirements. You will help drive risk-based decision making by ensuring vulnerabilities and exposures are translated into actionable remediation plans and measurable risk reduction outcomes.
Success in this role requires strong stakeholder management, cybersecurity knowledge, program governance, and the ability to translate technical findings into meaningful business risk conversations.
Responsibilities- Coordinate and govern enterprise penetration testing, security validation, and related activities from onboarding through remediation and closure.
- Drive vulnerability and exposure management processes, ensuring findings are prioritized using risk-based methodologies and tracked to resolution.
- Partner with solution owners, engineering teams, Cyber Operations, and remediation teams to accelerate risk reduction activities.
- Facilitate security findings reviews, remediation workshops, risk acceptance discussions, and retest readiness assessments.
- Track and report remediation progress, risk treatment plans, service metrics, and key performance indicators to technical and executive stakeholders.
- Manage exception requests, compensating controls, executive approvals, and risk documentation in accordance with established governance processes.
- Support cyber risk management activities by ensuring evidence is collected and maintained to satisfy audit, compliance, and risk closure requirements.
- Contribute to the evolution of vulnerability management, exposure management, and security validation capabilities through process improvement and operational innovation.
- Support strategic cybersecurity initiatives designed to improve organizational visibility, risk prioritization, and overall security posture.
- Develop trusted relationships across technical, operational, and leadership teams, acting as a central point of coordination for security validation and remediation activities.
- Experience in vulnerability management, exposure management, cyber risk management, or security operations.
- Strong understanding of penetration testing, security assessments, Purple Team exercises, and security validation methodologies.
- Experience coordinating remediation activities across multiple stakeholders and technology teams.
- Strong analytical, communication, and stakeholder management skills.
- Experience presenting cybersecurity risks and remediation status to senior leadership.
- Understanding of cybersecurity frameworks, risk management processes, and governance controls.
- Experience working within large, complex enterprise environments.
- Knowledge of Risk-Based Vulnerability Management (RBVM) platforms and methodologies.
- Experience with attack surface management, exposure assessment, and continuous controls validation.
- Familiarity with enterprise risk management and audit processes.
- Relevant industry certifications such as CISSP, CISM, CRISC, Security+, GSEC, or equivalent.
- Experience supporting large-scale cybersecurity transformation or operational improvement initiatives.
This is not a traditional incident response or SOC role. Instead, you will help shape how Kyndryl identifies, prioritizes, validates, and reduces cyber risk across the enterprise.
Who You Are
You're an experienced cybersecurity professional with a strong understanding of vulnerability management, security validation, cyber risk reduction, and enterprise security governance. You are passionate about reducing organizational risk through effective prioritization, remediation, and operational excellence.
You combine technical credibility with strong stakeholder management skills and can confidently work across engineering teams, security functions, risk management, and senior leadership to drive measurable security outcomes. You are outcome-focused, collaborative, and comfortable operating in complex global environments where influence, coordination, and execution are as important as technical expertise.
Most importantly, you have a growth mindset, are committed to continuous learning, and enjoy solving complex cybersecurity challenges while helping others succeed.
Required Skills and Experience- 7+ years' experience in cybersecurity, vulnerability management, exposure management, security operations, cyber risk management, or related disciplines.
- Strong understanding of Vulnerability Management (VM), Risk-Based Vulnerability Management (RBVM), exposure management, and remediation governance.
- Experience coordinating penetration testing, security assessments, or other security validation activities.
- Ability to evaluate and prioritize vulnerabilities and security findings based on risk, exploitability, business impact, and threat intelligence.
- Experience partnering with application owners, infrastructure teams, Cyber Operations, and remediation stakeholders to drive risk reduction outcomes.
- Knowledge of cyber risk management frameworks, governance processes, and security control validation methodologies.
- Experience managing remediation programs, tracking corrective actions, facilitating retests, and supporting risk closure activities.
- Strong analytical and problem-solving skills with the ability to translate technical findings into business risk.
- Excellent written and verbal communication skills, including experience presenting cybersecurity risks, trends, and recommendations to senior stakeholders.
- Experience working within large, complex enterprise environments with multiple stakeholders and competing priorities.
- Demonstrated ability to lead cross-functional initiatives and drive process improvements that improve security outcomes.
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related discipline.
- Experience with exposure management, attack surface management, continuous security validation, or cyber risk quantification platforms.
- Experience with security validation tooling, vulnerability platforms, and remediation orchestration technologies.
- Familiarity with enterprise risk management, audit, regulatory, and compliance requirements.
- Experience supporting executive reporting, operational metrics, and cybersecurity governance forums.
- Knowledge of cloud security platforms and modern application security practices.
- Experience working with vulnerability scanners, penetration testing providers, and security assessment teams.
- Industry certifications such as CISSP, CISM, CRISC, Security+, GSEC, CGRC, or equivalent.
- Experience supporting cybersecurity transformation programs or operational maturity initiatives.
Being You
The “Kyn” in Kyndryl means kinship, which represents the strong bonds we have with each other, our customers and our communities. We focus on ensuring all Kyndryls feel included and we welcome people of all cultures, backgrounds, and experiences. Even if you don’t meet every requirement, we encourage you to apply. We believe in growth, and we’re excited to see what you can bring. At Kyndryl, employee feedback has told us that our number one driver of employee engagement is belonging. That sense of belonging — being a valued, respected, trusted member of the team — is fundamental to our culture and fueling great experiences for our customers. This dedication to welcoming everyone into our company means that Kyndryl gives you the ability to thrive and contribute to our culture of empathy and shared success. That’s The Kyndryl Way.
What You Can Expect
Your career with us isn’t just a job—it’s an adventure with purpose. We offer a dynamic, hybrid-friendly culture that supports your well-being and empowers you to grow. Our Be Well programs are thoughtfully designed to support your financial, mental, physical, and social health—because we know that when you feel your best, you do your best.
From your very first day, you’ll dive into impactful work that powers the systems our customers rely on every day. You won’t just contribute—you’ll make a difference, tackling meaningful projects that sharpen your skills and fuel your growth.
We’re here to champion your journey. With powerful tools to chart your career path, personalized development goals aligned with your ambitions, and continuous feedback to keep you inspired and on track, you’ll have everything you need to thrive and evolve. You’ll develop in-demand skills to grow your career and achieve your ambitions with access to cutting-edge learning opportunities—from certifications with Microsoft, Google, and Amazon to coaching and hands-on experiences. And through it all, you’ll be part of a culture that values empathy, restless learning, and a devotion to shared success.
We want you to thrive here—and we’re committed to helping you do just that. Ready to make an impact? Join us and help shape what’s next.
Get Referred!
If you know someone that works at Kyndryl, when asked ‘How Did You Hear About Us’ during the application process, select ‘Employee Referral’ and enter your contact's Kyndryl email address.
Skills Required
- 7+ years of experience in cybersecurity, vulnerability management, exposure management, security operations, cyber risk management, or related disciplines
- Strong understanding of vulnerability management, risk-based vulnerability management, exposure management, and remediation governance
- Experience coordinating penetration testing, security assessments, or other security validation activities
- Ability to evaluate and prioritize vulnerabilities and security findings based on risk, exploitability, business impact, and threat intelligence
- Experience partnering with application owners, infrastructure teams, Cyber Operations, and remediation stakeholders
- Knowledge of cyber risk management frameworks, governance processes, and security control validation methodologies
- Experience managing remediation programs, tracking corrective actions, facilitating retests, and supporting risk closure activities
- Strong analytical and problem-solving skills, including the ability to translate technical findings into business risk
- Excellent written and verbal communication skills, including presenting cybersecurity risks, trends, and recommendations to senior stakeholders
- Experience working within large, complex enterprise environments with multiple stakeholders and competing priorities
- Demonstrated ability to lead cross-functional initiatives and drive security process improvements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related discipline
- Experience with exposure management, attack surface management, continuous security validation, or cyber risk quantification platforms
- Experience with security validation tooling, vulnerability platforms, and remediation orchestration technologies
- Familiarity with enterprise risk management, audit, regulatory, and compliance requirements
- Experience supporting executive reporting, operational metrics, and cybersecurity governance forums
- Knowledge of cloud security platforms and modern application security practices
- Experience working with vulnerability scanners, penetration testing providers, and security assessment teams
- Industry certification such as CISSP, CISM, CRISC, Security+, GSEC, CGRC, or equivalent
- Experience supporting cybersecurity transformation programs or operational maturity initiatives
Kyndryl Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Kyndryl and has not been reviewed or approved by Kyndryl.
-
Fair & Transparent Compensation — Pay is considered good in some roles, with mentions of “good pay,” “great pay and benefits,” and an “acceptable salary range” paired with bonuses. Certain senior or consulting tracks are described as market-competitive.
-
Leave & Time Off Breadth — Vacation, paid time off, holidays, and a dedicated volunteer day are highlighted as positives. Parental leave exists companywide alongside sick leave and disability coverage.
-
Wellbeing & Lifestyle Benefits — Remote and hybrid flexibility is emphasized, including 100% remote roles and a formal flexible workplace policy. Well‑being resources such as the Be Well program and an EAP are available.
Kyndryl Insights
What We Do
We have the world’s best talent that design, run, and manage the most advanced and reliable technology infrastructure each day. Together, we think holistically about the health of these vital technology ecosystems. We are a focused, independent company that builds on our foundation of excellence by creating systems in new ways. Bringing in the right partners, investing in our business, and working side-by-side with our customers to unlock potential. We're raising the bar. Our experience speaks for itself: We have 90,000 highly skilled employees around the world serving 75 of the Fortune 100. But our purpose is what drives us: Advancing the vital systems that power human progress. Because when a digital ecosystem is healthy, it can more readily adapt and support continuous growth and that opens up a world of possibility for everyone.









