Principal of Vulnerability Management Oversight
$154k - $193kEarly Warning Services
Principal Of Vulnerability Management Oversight
At Early Warning, we've powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle®, Paze℠, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.
Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment.
Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.
Overall Purpose:
The Principal of Vulnerability Management Oversight is responsible for ensuring the enterprise Vulnerability Management (VM) program is effective, risk-aligned, and defensible—through independent challenge, governance, and validation.
This role provides independent risk-based governance within a Three Lines of Defense (3LOD) model, ensuring VM practices across the organization are effective, measurable, and aligned to risk appetite and regulatory expectations. The position partners closely with engineering, infrastructure, and application teams, acting as a credible challenger—not an operator. This role will support the Cybersecurity and Technology Risk Management team within the Second Line of Defense (2LOD) and report directly to the 2LOD VP of Information Security Risk.
Essential Functions:
- Provide independent challenge and oversight of vulnerability identification, prioritization, and remediation practices across enterprise environments.
- Define and maintain VM policies, standards, and risk-based remediation SLAs.
- Perform control validation and effectiveness testing of VM processes, tooling, and data quality.
- Assess and challenge risk acceptance decisions, compensating controls, and remediation timelines.
- Deliver risk-based reporting and insights on vulnerability exposure, trends, and systemic gaps.
- Provide oversight of VM tooling (e.g., Tenable, Qualys, Rapid7) to ensure coverage, configuration, and data integrity.
- Partner with First Line teams, Risk, Compliance, and Audit to ensure alignment with internal policies and regulatory expectations.
- Support regulatory exams and internal audits as the VM Second Line SME.
Minimum Qualifications:
- 15+ years of IT experience with 8+ years in Information Security
- Deep expertise in enterprise Vulnerability Management and risk-based prioritization.
- Experience operating in a Three Lines of Defense model and/or regulated environment (financial services preferred).
- Strong understanding of infrastructure, cloud, networking, and common vulnerability classes.
- Ability to translate technical findings into business risk and executive-level insights
- Experience in fintech or highly regulated industries
- Familiarity with CVSS, EPSS, threat intelligence, and KEV-based prioritization.
- Background in risk management, audit, or control validation.
- Background and drug screen.
The above job description is not intended to be an all-inclusive list of duties and standards of the position. Incumbents will follow instructions and perform other related duties as assigned by their supervisor.
Physical Requirements
Working conditions consist of a normal office environment. Work is primarily sedentary and requires extensive use of a computer and involves sitting for periods of approximately four hours. Work may require occasional standing, walking, kneeling and reaching. Must be able to lift 10 pounds occasionally and/or negligible amount of force frequently. Requires visual acuity and dexterity to view, prepare, and manipulate documents and office equipment including personal computers. Requires the ability to communicate with internal and/or external customers.
Employee must be able to perform essential functions and physical requirements of position with or without reasonable accommodation.
The base pay scale for this position in: Phoenix, AZ/ Chicago, IL / Washington, DC in USD per year is: $154,000 - $193,000. New York, NY/ San Francisco, CA in USD per year is: $186,000 - $232,000. Additionally, candidates are eligible for a discretionary incentive plan and benefits.
This pay scale is subject to change and is not necessarily reflective of actual compensation that may be earned, nor a promise of any specific pay for any specific candidate, which is always dependent on legitimate factors considered at the time of job offer. Early Warning Services takes into consideration a variety of factors when determining a competitive salary offer, including, but not limited to, the job scope, market rates and geographic location of a position, candidate's education, experience, training, and specialized skills or certification(s) in relation to the job requirements and compared with internal equity (peers). The business actively supports and reviews wage equity to ensure that pay decisions are not based on gender, race, national origin, or any other protected classes.
Some of the Ways We Prioritize Your Health and Happiness
- Healthcare Coverage – Competitive medical (PPO/HDHP), dental, and vision plans as well as company contributions to your Health Savings Account (HSA) or pre-tax savings through flexible spending accounts (FSA) for commuting, health & dependent care expenses.
- 401(k) Retirement Plan – Featuring a 100% Company Safe Harbor Match on your first 6% deferral immediately upon eligibility.
- Paid Time Off – Flexible Time Off for Exempt (salaried) employees, as well as generous PTO for Non-Exempt (hourly) employees, plus 11 paid company holidays and a paid volunteer day.
- 12 weeks of Paid Parental Leave
- Maven Family Planning – provides support through your Parenting journey including egg freezing, fertility, adoption, surrogacy, pregnancy, postpartum, early pediatrics, and returning to work.
And SO much more! We continue to enhance our program, so be sure to check our Benefits page here for the latest. Our team can share more during the interview process!
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Early Warning Services, LLC ("Early Warning") considers for employment, hires, retains and promotes qualified candidates on the basis of ability, potential, and valid qualifications without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote equal employment opportunity and affirmative action, in accordance with all applicable federal, state, and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our employees.
$125k - $280.5k
...Job Description: Job Title: Control Oversight Corporate Title: Vice President - Director Location: New York, NY ALL... ...efficiency, sustainability and transparency of Market Conduct controls management. Residing within the Front Office, reporting up into the Head...SuggestedWork at officeRemote workWork from home$200.3k - $293.81k
...Services organization is creating a Principal Product Manager, Applied AI & Agentic Solutions role... ...under defined guardrails and human oversight. Relevant examples may include analyst... ...tointegratedthreat intelligence and vulnerability data into products, services, and...PrincipalWork at officeRemote workFlexible hours- First Horizon Bank is seeking a Business Risk Oversight Officer to provide independent oversight and strategic risk guidance within their... ...ideal candidate will possess over 7 years in operational risk management, strong project management skills, and a deep understanding of...Suggested
$147.5k - $211k
...Lead the enterprise operating model for vulnerability and patch remediation across... ...acceptance. Endpoint Patching SRE Oversight Lead the endpoint patching reliability... ...through approved tools such as Qualys Patch Management, Tanium, AWS Systems Manager Patch Manager...SuggestedLocal area3 days per week$140k - $205k
...firm that conducts its business through three principal business segments - Institutional Securities, Wealth Management, and Investment Management. Morgan Stanley provides... ...related financial crimes risks Providing oversight to planning, implementation, and testing...SuggestedTemporary work- TryApplyNow is seeking a Senior Principal Scientist for Tech Ops in Pennsylvania to lead... ...manufacturing along with strong skills in project management and cross-functional collaboration.... ...in process improvements, scientific oversight, and mentoring of junior staff,...Principal
- ...leading environmental consulting firm is seeking a Senior or Principal Environmental Project Manager to lead natural resource projects in Oklahoma or... ...role involves client relationship management and project oversight, focusing on compliance with environmental regulations....PrincipalRemote jobFull time
- ...President to join our Securities Finance Principal Trading team. This role is located in... ...senior execution leadership, business oversight, cross-functional coordination, and support... ..., disciplined execution, stakeholder management, and the ability to operate effectively...PrincipalWork experience placement
$204k - $288k
...professional services firm in New York is seeking a Principal to lead valuation consulting engagements and manage a dynamic team. The ideal candidate will have 8-1... .... Responsibilities include client interaction, oversight of valuation processes, and team development....Principal$150k - $200k
...looking for a Vice President in New York to join the Principal Finance group. This role involves managing the full lifecycle of private credit transactions,... ...in transaction management and operational oversight is required. #J-18808-Ljbffr InforCapital, partnershipPrincipal- First Horizon Bank is seeking a Business Risk Oversight Officer to provide independent oversight and ensure operational risks are proactively identified and managed. The ideal candidate will have over 7 years of experience in risk management within the banking sector,...
- A regional educational service center in Ohio is seeking an Opportunity School Principal. The role involves leadership, oversight, and daily management of an alternative education program for students facing behavioral challenges. Candidates must possess a Bachelor’s degree...Principal
- ...solutions. The CCB Payment Network Office is the central hub for managing and strengthening relationships with major card and account-... ...address payment network opportunities and challenges. As an Oversight & Compliance Lead on the Card Payment Networks Team, you will...Contract workWork at officeWork visa
$185k - $245k
Bloomberg L.P. in New York is seeking an Information Security Risk Oversight Lead to translate cybersecurity risk into executive insight and... ...will ensure risks are effectively identified, measured, and managed, and present findings to leadership. Required qualifications...- Principal, Fund Liquidity Management Lead page is loaded## Principal, Fund Liquidity Management Leadlocations: New York, New Yorktime type: Full timeposted... ...front-office resource for fund-level financing oversight, liquidity management, and facility strategy across GCC...PrincipalImmediate start
$170k - $240k
...engineering and design consultancy, is seeking an Associate Principal level Mechanical or Electrical Engineer to join its... ...staff Contribute to commercial strategy, risk management, and project performance oversight Desired Background Established client relationships and...PrincipalFlexible hours$115.44k - $186.16k
...mission to build a more resilient and scalable compliance risk management function. As part of our team, you'll play a key role in... ...throughout the organization. The Senior Compliance Business Oversight Manager - Consumer Banking will provide compliance oversight,...Work experience placementWork at officeLocal areaWork from homeFlexible hours- * Lead the design and development of comprehensive risk management frameworks that govern international technical architecture and... ...design-level risk assessments, including identifying threats and vulnerabilities within complex network or cloud infrastructures* At least 5...PrincipalFull timePart time
- ...Marketing Advisory team and the EDD will work closely with the Managing Partner, the head of strategy, technology and operations. They... ...the NY hub. Possibly across other markets. Project Oversight • End-to-End Design: Oversee the design and delivery of...PrincipalWork experience placement
- ...President, Senior Compliance Officer, Monitoring & Compliance Oversight About the Company Leading global financial institution with... ...and documentation. The role also involves the development of management reporting, the identification of control gaps, and the support...
$190k - $240k
...Senior Rail and Transit Principal Technical Manager – Architecture page is loaded## Senior Rail and Transit Principal Technical Manager – Architecturelocations... ...and other digital formats( for the purpose of providing oversight).## **About you*** Bachelor’s degree required. Master’s...PrincipalTemporary workWork at officeLocal areaRemote workFlexible hours- JPMorgan Chase & Co. is seeking an Oversight & Compliance Lead for the Card Payment Networks Team in New York. This role involves managing controls and processes between Chase and major card networks, ensuring compliance and operational quality. Candidates should have 8...
$140k - $185k
...seeking a Fund Governance Specialist. In this role, you will support the governance framework for investment funds, ensuring proper oversight and compliance with fiduciary and regulatory standards. Candidates should possess a Bachelor’s degree and demonstrate strong...- DESCRIPTION We are looking for a talented Principal Technical Engineer - Identity & Access Management to join our team specializing in Systems/Information Technology... ...penetration testing will help identify vulnerabilities proactively, enabling the organization to fortify...PrincipalFor contractorsWork experience placementRelocation package
$82.94k - $182.55k
Position Summary Planned, monitors, and manages internal projects from initiation through completion. Secures required resources and uses... ..., working with operations to mitigate audit risk, and oversight of root cause and corrective action planning. Analyze business...Hourly payFull timeTemporary workWork experience placementLocal area- ...Vice President, Regulatory Oversight Management At BNY, our culture allows us to run our company better and enables employees' growth and success. As a leading global financial services company at the heart of the global financial system, we influence nearly 20% of...Work experience placementWorldwideFlexible hours
$180k - $250k
...Principal– Property & Casualty Actuarial Consulting Location: Dallas, Houston, Charlotte... ...other organizations with all aspects of managing property and casualty insurance... ...Provide strategic guidance and technical oversight across engagements which may include: loss...PrincipalMinimum wage$116.5k - $173.25k
...connect with their customers, process exchanges and returns, and manage risk. We enable consumers to engage in cross-border shopping... ...Summary Reporting to the Director, Product & Operational Risk Oversight, the Manager, Product Lifecycle Risk Oversight is a second‑line...Local areaFlexible hours$150k - $200k
...caliber professional to lead the strategic oversight, governance, and optimization of our... ..., regulatory strategy, and capital management. You will be responsible for building robust... ...capital allocation strategy. Other Principal Investment Portfolio owners across the...PrincipalWork experience placementLocal areaWork from homeFlexible hours$170k - $240k
About the Position The Principal, Discipline Lead is a senior technical leadership position... ...identification, and effective QA/QC oversight. You define and achieve discipline priorities... ...coordination, QA/QC practices, risk management, and delivery requirements....PrincipalFull timeTemporary workFor contractorsWork at officeImmediate startRemote workVisa sponsorshipFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal of Vulnerability Management Oversight. Be the first to apply!
- principal architect New York, NY
- principal New York, NY
- principal solutions consultant New York, NY
- principal solution architect New York, NY
- senior principal scientist New York, NY
- associate principal New York, NY
- principal consultant New York, NY
- senior principal cloud computing engineer New York, NY
- epic principal trainer New York, NY
- principal designer New York, NY

