Head of Vulnerability & Business Information Risk Management

MassMutual
East Rutherford, New Jersey, United States
Full-time

Overview : We are seeking a highly skilled and strategic leader to join our organization as the Head of Vulnerability & Business Information Risk Management.

In this role, you will be responsible for overseeing and enhancing our vulnerability management program and application security practices.

You will lead a team of experts to identify, assess, prioritize, and mitigate vulnerabilities across our systems and applications, ensuring the integrity and security of our technology infrastructure.

Key ResponsibilitiesLeadership and Strategy : Develop and execute a comprehensive vulnerability management strategy aligned with organizational goals and industry best practices.

Provide strategic direction and vision for application security initiatives, integrating security into the software development lifecycle (SDLC).

BISO and Enterprise Advisory Services : Working closely with business leaders, technology leaders, and privacy professionals to assure the organization meets current standards, complies with regulatory requirements, and addresses the future direction of the business.

Team Management : Lead and mentor a team of vulnerability management and application security professionals, fostering a culture of excellence, innovation, and collaboration.

Define roles, responsibilities, and career development paths within the team to promote growth and maximize performance.Vulnerability Assessment and Remediation : Oversee the identification, assessment, and prioritization of vulnerabilities across infrastructure, networks, and applications.

Implement effective remediation strategies and controls to mitigate identified vulnerabilities promptly.Application Security Governance : Establish and enforce application security policies, standards, and guidelines to ensure compliance with regulatory requirements and industry standards (e.

g., OWASP).Conduct regular security assessments and audits of applications to identify security gaps and recommend solutions.

Work with developers and architects to ensure security is appropriately built in the development cycle. Coordinate the performance of internal and external network and systems vulnerability assessments and penetration tests.

Collaboration and Communication : Collaborate with cross-functional teams including IT operations, development, architecture, and risk management to integrate security into the overall IT strategy.

Communicate security risks and recommendations to senior leadership and stakeholders, advocating for necessary investments and resources.

Incident Response and Continuous Improvement : Develop and maintain incident response plans and procedures related to vulnerabilities and application security incidents.

Drive continuous improvement initiatives to enhance the effectiveness and efficiency of vulnerability management and application security processes.

Required Skills and Qualifications : Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field;

advanced degree preferred.Proven experience (8+ years) in vulnerability management, application security, or related cybersecurity roles, with at least 5 years in a leadership capacity.

Deep technical expertise in vulnerability assessment tools, application security testing methodologies, and threat modeling.

Strong understanding of regulatory requirements, compliance frameworks (e.g., PCI-DSS, GDPR), and industry standards (e.g.

NIST, ISO 27001).Demonstrated ability to develop and execute strategic initiatives, manage budgets, and drive organizational change.

Excellent communication skills, with the ability to articulate complex technical concepts to non-technical stakeholders and influence decision-making at all levels.

Preferred Qualifications : Industry certifications such as CISSP, CISM, CEH, or GIAC certifications (e.g., GPEN, GWAPT).

Experience with cloud security architecture and technologies (e.g., AWS, Azure, GCP).Knowledge of DevSecOps principles and practices, including automation of security testing and monitoring.

LI-MC1MassMutual is an Equal Employment Opportunity employer Minority / Female / Sexual Orientation / Gender Identity / Individual with Disability / Protected Veteran.

We welcome all persons to apply. Note : Veterans are welcome to apply, regardless of their discharge status.If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need.

9 hours ago
Related jobs
MassMutual
Carlstadt, New Jersey

Overview:We are seeking a highly skilled and strategic leader to join our organization as the Head of Vulnerability & Business Information Risk Management. Team Management:Lead and mentor a team of vulnerability management and application security professionals, fostering a culture of excellence, in...

Promoted
VirtualVocations
Paterson, New Jersey

A company is looking for a Head of Account Management - Americas. ...

MassMutual
Guttenberg, New Jersey

In this critical role, you will be responsible for overseeing and enhancing our third-party cyber risk management program, governance, security awareness and training, and ensuring the security of our business information assets. You will lead efforts to assess, mitigate, and monitor risks associate...

HR Advantage, LLC
Summit, New Jersey

Through leadership of the staffing function, the Office Coordinator is responsible for optimizing the deployment of consulting resources to meet the business needs of the office, system and region, while ensuring that each consulting staff member in the office gets the right set of development oppor...

MassMutual
North Arlington, New Jersey

In this critical role, you will be responsible for overseeing and enhancing our third-party cyber risk management program, governance, security awareness and training, and ensuring the security of our business information assets. You will lead efforts to assess, mitigate, and monitor risks associate...

0000050007 Royal Bank of Canada
Jersey City, New Jersey

Broader audit coverage of Risk Governance & Oversight; Risk Identification, Assessment & Measurement; Risk Appetite; Issues Management; Risk Data Aggregation & Reporting; and the firm’s efforts to integrate Risk within Business Processes. The Internal Audit (IA) Manager - Risk Management will provid...

Ralph Lauren
Nutley, New Jersey

The Portfolio Managerwill bring a mixture of business process / solutions understanding,project management competence and experience within RL to the team. Ensure that processes exist for the reporting of the project activities, budget, risks, issues and that this is coordinated across the teams and...

Broadridge
Newark, New Jersey

Recommend and implement a major transformation effort in the areas of third-party supplier relationship and risk management, with a particular focus on enhanced governance and operating model between SSG and Broadridge's businesses and key suppliers, skills upgrading, process efficiencies, and enhan...

Prudential Ins Co of America
Newark, New Jersey

As a member of the Emerging Markets team, the Manager, Strategic Initiatives will support effective management of the regional business, including providing analysis and insights to the operations and business of the Joint Venture and strategic investments, support oversight of the entities business...

Prudential Ins Co of America
Newark, New Jersey

As a member of a first-line operational risk management team within a business unit, the Manager of Operational Risk Management will be responsible for providing direction to the business unit in developing and maintaining an effective and efficient risk management program. Proactively partners with...