At Finastra, we’re a global leader in financial services software, dedicated to expanding access to financial services and shaping what’s next for the industry. Our technology powers mission‑critical solutions across Lending, Payments and Universal Banking, supporting over 7,000 customers, including 80% of the world’s top 50 banks, in more than 110 countries.
Position Overview
We are seeking an experienced and strategic Director of Vulnerability Management to lead the organization's efforts to identify, prioritize, remediate, and govern cybersecurity vulnerabilities across infrastructure, cloud environments, applications, and internally developed products.
This leader will be responsible for advancing a mature, risk-based vulnerability management program while partnering closely with Engineering, Product, Architecture, Infrastructure, DevOps, and Security Operations teams to embed security throughout the software development lifecycle. The successful candidate will combine strong technical expertise, program leadership, and stakeholder management skills to reduce enterprise risk and enable secure business growth.
Key Responsibilities
Enterprise Vulnerability Management
Own and mature the enterprise vulnerability management program across infrastructure, endpoints, cloud platforms, applications, containers, and third-party technologies.
Establish risk-based prioritization methodologies that consider exploitability, business criticality, threat intelligence, and asset exposure.
Define and maintain vulnerability management standards, operational procedures, remediation SLAs, exception processes, and governance frameworks.
Drive accountability for remediation efforts and ensure timely resolution of critical and high-risk vulnerabilities.
Lead executive reporting and board-level metrics related to vulnerability exposure, remediation performance, and cyber risk reduction.
Coordinate enterprise response efforts for critical vulnerabilities, zero-day threats, and actively exploited security issues.
Program Governance & Risk Management
Collaborate with Risk, Compliance, Audit, Privacy, and Legal teams to ensure alignment with regulatory and industry requirements.
Manage vulnerability exception processes and risk acceptance frameworks.
Support regulatory examinations, customer security assessments, internal audits, and external audits.
Develop and maintain meaningful KPIs and KRIs that demonstrate program effectiveness and risk reduction.
Leadership & Organizational Development
Build, lead, and mentor a high-performing team of vulnerability management professionals.
Foster strong partnerships across Engineering, Infrastructure, Operations, and business leadership teams.
Establish a culture of accountability, collaboration, innovation, and continuous improvement.
Provide strategic guidance and subject matter expertise to executive leadership on emerging threats, vulnerability trends, and secure product development practices.
Required Qualifications
Education
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related discipline.
Equivalent combination of education and relevant experience will be considered.
Experience
Progressive cybersecurity experience, including vulnerability management, application security, product security, or related security disciplines.
Leadership experience managing security teams, programs, or enterprise initiatives.
Demonstrated success leading vulnerability management programs in large-scale enterprise environments.
Experience partnering with software engineering organizations and implementing secure development practices.
Strong background in cyber risk management, governance, and executive communications.
Technical Expertise
Deep understanding of vulnerability management frameworks, CVSS, exploitability analysis, threat intelligence integration, and remediation prioritization.
Strong knowledge of secure software development practices and application security principles.
Experience with vulnerability management and application security platforms such as Tenable, Qualys, Rapid7, Wiz, Prisma Cloud, Microsoft Defender, GitHub Advanced Security, CodeQL, Veracode, Checkmarx, or similar solutions.
Familiarity with cloud environments, containers, Kubernetes, CI/CD pipelines, APIs, and modern software architectures.
Ability to communicate technical risks effectively to both technical and non-technical audiences.
Certifications (Preferred)
CISSP
CISM
Relevant cloud security certifications
Preferred Qualifications
Experience leading Product Security or DevSecOps transformation initiatives.
Experience implementing secure-by-design principles within enterprise software development environments.
Familiarity with software supply chain security and emerging secure software development regulations.
Experience supporting highly regulated industries, including financial services, healthcare, insurance, or critical infrastructure sectors.
Experience leveraging automation and AI-driven security capabilities to improve vulnerability management and security operations.
Leadership Competencies
The ideal candidate will demonstrate:
Strategic thinking and business acumen.
Strong executive presence and communication skills.
Ability to influence without direct authority.
Data-driven decision-making and risk prioritization.
Effective stakeholder management across technical and business functions.
A commitment to talent development, inclusiveness, and continuous improvement.
Success Measures
Success in this role will be measured through:
Reduction of enterprise vulnerability exposure and risk.
Improvement in remediation performance and SLA compliance.
Increased adoption of secure development practices across engineering teams.
Enhanced visibility and reporting of cyber risk to executive leadership.
Successful integration of security into product and technology delivery processes.
Positive audit, regulatory, and customer security assessment outcomes.
We are proud to offer a range of incentives to our employees worldwide. These benefits are available to everyone, regardless of grade, and reflect the values we stand for:
Flexibility: Enjoy unlimited vacation, subject to local regulations and business priorities. Benefit from hybrid working arrangements and inclusive policies such as paid time off for voting, bereavement, and sick leave.
Well‑being: Access confidential one‑to‑one support through our Employee Assistance Program, connect with our network of Wellbeing Champions and Gather Groups, and take part in monthly events and initiatives designed to help you thrive—inside and outside of work.
Health & Financial Security: Medical, life and disability insurance, retirement plans, lifestyle, and other benefits.*
Sustainability: Paid time off for volunteering and donation‑matching opportunities to support causes that matter to you.
Inclusion: Get involved in our inclusion communities, such as Count Me In, Culture@Finastra, Proud@Finastra, Disabilities@Finastra, and Women@Finastra—open to everyone who wants to participate and contribute.
Career Development: Access online learning and accredited courses through our Skills & Career Navigator tool.
Recognition: Take part in our global recognition program, Finastra Celebrates, and share your voice through regular employee surveys that help shape our culture and ways of working.
*Specific benefits may vary by location.
At Finastra, each individual is unique—bringing their own ideas, perspectives, cultural backgrounds, and experiences. We learn from one another, value what makes us different, and create an environment where everyone feels included, supported, and able to be their authentic selves.
Be unique. Be exceptional. Help us make a difference at Finastra.
Applicants for this position need to be located in posted location or their immediate surrounding areas. Due to the requirements of this position, this job posting is not available for, and Finastra will not be considering any applicants who currently reside in New York City or California.
Skills Required
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related discipline, or equivalent education and experience
- Progressive cybersecurity experience in vulnerability management, application security, product security, or related disciplines
- Leadership experience managing security teams, programs, or enterprise initiatives
- Demonstrated success leading vulnerability management programs in large-scale enterprise environments
- Experience partnering with software engineering organizations and implementing secure development practices
- Strong background in cyber risk management, governance, and executive communications
- Deep understanding of vulnerability management frameworks, CVSS, exploitability analysis, threat intelligence integration, and remediation prioritization
- Strong knowledge of secure software development practices and application security principles
- Experience with vulnerability management or application security platforms such as Tenable, Qualys, Rapid7, Wiz, Prisma Cloud, Microsoft Defender, GitHub Advanced Security, CodeQL, Veracode, Checkmarx, or similar
- Familiarity with cloud environments, containers, Kubernetes, CI/CD pipelines, APIs, and modern software architectures
- Ability to communicate technical risks to technical and non-technical audiences
- CISSP certification
- CISM certification
- Relevant cloud security certification
- Experience leading Product Security or DevSecOps transformation initiatives
- Experience implementing secure-by-design principles in enterprise software development environments
- Familiarity with software supply chain security and emerging secure software development regulations
- Experience supporting highly regulated industries
- Experience using automation and AI-driven security capabilities to improve vulnerability management and security operations
Finastra Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Finastra and has not been reviewed or approved by Finastra.
-
Leave & Time Off Breadth — Leave is positioned as flexible/“unlimited” in many roles, which can support work-life balance when team norms allow it. Hybrid/flexible working is also framed as a core part of the overall rewards experience.
-
Parental & Family Support — Parental leave is described as relatively generous in the US, with multiple references to roughly three months (or around 12 weeks) fully paid and equal leave for mothers and fathers. This is repeatedly highlighted as a meaningful component of the benefits package.
-
Wellbeing & Lifestyle Benefits — Wellbeing support is emphasized through offerings like an Employee Assistance Program and TaskHuman coaching, alongside volunteering time off and employee networks. These programs broaden total rewards beyond cash compensation.
Finastra Insights
What We Do
At Finastra our purpose is to unlock the power of finance for everyone & redefine finance for good. We’re the orchestrator of open finance; building and delivering innovative, next-generation technology on our open Fusion software architecture and cloud ecosystem. We’re one of the world’s largest FinTechs, working with over 9,000 customers including 90 of the top 100 banks globally. We’re creating a pioneering open platform that’s disrupting the financial industry, changing how financial software is developed and used. We believe in collaboration for innovation, to unlock the potential of people, businesses and communities. We have an unmatched portfolio of financial software and deliver mission critical solutions for financial institutions of all sizes, on premises or in the cloud. Our open architecture and platform approach embrace a wide ecosystem of partners and co innovators. Together we're leading the way in which applications are written, deployed and consumed in the world of financial services. Our people mission is to be the most loved and inclusive fintech company in the world; a mission we take seriously. DE&I factors into everything we do and every decision we make as a business. When you join Finastra, you open up a world of possibilities. With us, you can supercharge financial institutions, big tech and fintech while also building a more inclusive finance industry. We believe our people thrive when given the opportunity to be their authentic selves and we trust our people to work how, when and where they want; this is OPENworking. Our 2+ policy provides the perfect mix of focused work at home, coupled with the meaningful connection that comes from in person collaboration, coaching and community. We're rolling out a new programme where our people take as much leave as they need; we do not count vacation days and we trust our people to work in a way that suits them, when it suits them. Come join the future of Fintech, and make your world. OPEN.









