Director Vulnerability Management

Reposted 13 Days Ago
Be an Early Applicant
Coppell, TX
In-Office
Senior level
Financial Services
The Role
The Director of Vulnerability Management leads the enterprise VM program, ensuring compliance, strategy implementation, and remediation across various platforms. This role involves collaboration, tool integration, risk assessment, and producing executive metrics.
Summary Generated by Built In
Exceed the expectations of our residential mortgage borrowers & business partners through superior service, simple processes, and effective communications.
We deliver on this mission by empowering our employees by encouraging and recognizing superior performance and innovative solutions, by promoting teamwork and divisional cooperation.
 

POSITION SUMMARY

The Director Vulnerability Management (VM) owns the enterprise VM program across endpoints, servers, network devices, cloud platforms, containers, and applications. This role sets strategy and governance; drives risk-based prioritization; enforces remediation SLAs and exception handling; leads tool adoption and integration; and produces executive-ready metrics for internal governance and external obligations. Success requires deep collaboration with Infrastructure, End-User Computing, Network, Cloud/SRE, Application Engineering, Security Operations, and GRC, as well as selected service providers. The program operates under the Company’s Patch & Vulnerability Management Standard and supports regulatory, audit, and customer requirements.

DESCRIPTION

Duties and Responsibilities

  • Program Strategy & Governance
  • Define and continuously mature a risk-driven VM strategy, roadmap, and RACI.
  • Establish policy-aligned remediation SLAs, exception criteria, escalation paths, and evidence requirements.
  • Ensure customer/contract obligations related to scanning cadence and patch timelines are operationalized where applicable.
    • Operations, Coverage & Tooling
  • Lead enterprise scanning and assessment coverage across on-prem, cloud, containers, and applications using core platforms (e.g., Qualys VMDR/TotalAppSec, Veracode, Microsoft Defender for Endpoint).
  • Expand and maintain authenticated/agent-based coverage; manage discovery for shadow/EOL assets.
  • Oversee web app/API scanning in partnership with AppSec; ensure rescans validate remediation.
  • Lead enterprise hardening efforts across systems, software, networks, cloud applications, and cloud environments.
    • Integration & Automation
  • Drive CMDB and ITSM integrations to automate ownership mapping, ticket creation, routing, and SLA tracking.
  • Improve data quality (asset/owner criticality) to enable risk-based prioritization and reporting.
    • Remediation Enablement & Outcomes
  • Partner with Infra, Desktop, Cloud, and App Owners to remove blockers (e.g., maintenance windows, change control constraints, EOL/EOS platforms).
  • Track and resolve exceptions with compensating controls; publish actionable playbooks/runbooks.
    • Zero-Day / Major Event Response
  • Orchestrate assessment, prioritization, patch/mitigation guidance, rescans, stakeholder communications, and executive updates for critical vulnerabilities.
    • Metrics, Reporting & Audit Readiness
  • Produce executive-ready dashboards (coverage, SLA attainment, risk burn-down, exception inventory, business impact).
  • Maintain audit artifacts and evidence for internal/external assessments; support GLBA and customer reviews.
    • Performs related duties as assigned by management.

Qualifications and Education Requirements

  • Bachelor’s degree in Information Security, Information Systems, Computer Science, or equivalent experience.
  • 10+ years in Information Security with 5+ years leading Vulnerability Management for a multi-platform enterprise (hybrid cloud). Demonstrated results improving enterprise VM metrics and SLA performance.
  • Technical: Depth with Qualys (VMDR, WAS/TotalAppSec), Veracode, Microsoft Defender for Endpoint; familiarity with network device scanning, container registries, and cloud workload coverage.
  • Frameworks/Regulatory: Working knowledge of NIST CSF/ISO 27001; audit evidence management (e.g., GLBA); experience satisfying customer security requirements.
  • Preferred Certifications: CISSP, CISM, CCSP, or comparable.

Skills, Abilities, and Knowledge

  • Leadership & Influence: Leads cross-functional remediation at enterprise scale; strong executive presence and communication.
  • Risk-Based Decisioning: Translates technical findings to business risk; prioritizes by asset criticality and exposure.
  • Tooling Expertise: Hands-on with Qualys (VMDR and WAS/TotalAppSec), Veracode, Microsoft Defender for Endpoint; data/automation integrations with CMDB/ITSM.
  • Process Design: Scalable workflows, exception governance, and evidence management aligned to standards and audits.
  • Partnering & Change Management: Drives outcomes with Infra/App/Cloud teams and third parties; removes operational friction.
  • Communication: Converts complex risk and technical data into concise, outcome-oriented narratives for executives and non-security stakeholders.

Additional Information:

While this description is intended to be an accurate reflection of the position’s requirements, it in no way implies/states that these are the only job responsibilities. Management reserves the right to modify, add or remove duties and request other duties, as necessary.

 

All employees are required to have smart phones that meet Company security standards with the ability to install apps such as Okta Verify and Microsoft Authenticator. Employment will be contingent on this requirement.

Company Benefits:

Newrez is a great place to work but we are only as strong as our greatest asset, our employees, so we believe in rewarding them!

  • Medical, dental, and vision insurance

  • Health Savings Account with employer contribution

  • 401(k) Retirement plan with employer match

  • Paid Maternity Leave/Parental Bonding Leave

  • Pet insurance

  • Adoption Assistance

  • Tuition reimbursement

  • Employee Loan Program

  • The Newrez Employee Emergency and Disaster Fund is a new program to support our team members

Newrez NOW:

  • Our Corporate Social Responsibility program, Newrez NOW, empowers employees to become leaders in their communities through a robust program that includes volunteering, philanthropy, nonprofit grants, and more

  • 1 Volunteer Time Off (VTO) day, company-paid volunteer day where all eligible employees may participate in a volunteer event with a nonprofit of their choice

  • Employee Matching Gifts Program: We will match monetary employee donations to eligible non-profit organizations, dollar-for-dollar, up to $1,000 per employee

  • Newrez Grants Program: Newrez hosts a giving portal where we provide employees an abundance of resources to search for an opportunity to donate their time or monetary contributions

Equal Employment Opportunity 
We're proud to be an equal opportunity employer- and celebrate our employees' differences, including race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, and Veteran status. Different makes us better.

CA Privacy Policy

CA Notice at Collection

Top Skills

Microsoft Defender For Endpoint
Qualys Vmdr
Veracode
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Fort Washington, PA
1,575 Employees

What We Do

Newrez LLC (Newrez) is a leading nationwide mortgage lender and servicer. As a lender, Newrez focuses on offering a breadth of industry-leading products, supported by a loan process that blends both human interaction and the benefits of technology into an unparalleled customer experience. Founded in 2008 and licensed to lend in 50 states, Newrez is headquartered in Fort Washington, Pennsylvania and operates multiple lending channels, including Correspondent Lending, Wholesale, Direct-to-Consumer, Retail, and a network of joint venture partners. Newrez’s servicing business consists of its performing loan servicing division, Newrez Servicing, and its special servicing division, Shellpoint Mortgage Servicing. Newrez also has several affiliates that perform various services in the mortgage and real estate industries. These include Avenue 365 Lender Services, LLC, a title agency, and E Street Appraisal Management LLC, an appraisal management company. Newrez is member of the New Residential Investment Corp. family. More information is available at www.newrez.com.


© 2022 Newrez LLC {f/k/a New Penn Financial, LLC}. All Rights Reserved. {Doing business as Newrez Mortgage in the states of Arkansas and Texas}. {Website approval pending with the New York Department of Financial Services.} This communication does not constitute a commitment to lend or the guarantee of a specified interest rate. All loan programs and availability of cash proceeds are subject to credit, underwriting and property approval. Programs, rates, terms and conditions are subject to change without notice. Other restrictions apply. Newrez LLC, 1100 Virginia Drive, Suite 125, Fort Washington, PA 19034. Corp NMLS#: 3013 (www.nmlsconsumeraccess.org). Additional licenses available at www.newrez.com. Equal Housing Opportunity.

Similar Jobs

Wells Fargo Logo Wells Fargo

Personal Banker at Rosenburg

Fintech • Financial Services
Hybrid
Rosenberg, TX, USA
213000 Employees
Hybrid
Texarkana, TX, USA
213000 Employees
Hybrid
Bryan, TX, USA
213000 Employees
Hybrid
Midland, TX, USA
213000 Employees

Similar Companies Hiring

Yooz Thumbnail
Software • Machine Learning • Fintech • Financial Services • Cloud • Automation • Artificial Intelligence
Aimargues, FR
470 Employees
Amplify Platform Thumbnail
Fintech • Financial Services • Consulting • Cloud • Business Intelligence • Big Data Analytics
Scottsdale, AZ
62 Employees
Rain Thumbnail
Web3 • Payments • Infrastructure as a Service (IaaS) • Fintech • Financial Services • Cryptocurrency • Blockchain
New York, NY
40 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account