Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

SVP, Vulnerability Management & Cloud Security Posture Platform Engineering

BNY

SVP, Vulnerability Management & Cloud Security Posture Platform Engineering

We're seeking a team member for the role of SVP, Vulnerability Management & Cloud Security Posture Platform Engineering to join our Cybersecurity Engineering Tools & Platforms team. This role is located in New York, NY; Pittsburgh, PA; or Washington, DC.

This is a high-impact, deeply technical individual contributor role focused on both running and engineering enterprise cybersecurity platforms that support vulnerability management, asset discovery, network and infrastructure scanning, cloud security posture management, cloud-native risk visibility, reporting, and remediation enablement.

This role fits in the intersection of hands-on platform operations, deployment and execution, troubleshooting, automation engineering, service ownership, and technical leadership.

In this role, you'll make an impact in the following ways:

  • Own engineering and operational accountability for enterprise vulnerability management and cloud security posture management tooling.
  • Run critical cybersecurity platforms day to day, including platform health, configuration, access, integrations, upgrades, onboarding, troubleshooting, vendor support, and production stability.
  • Engineer platform improvements that increase reliability, scalability, coverage, automation, performance, data quality, and operational resilience.
  • Manage platform configuration, tenant administration, access models, scanner and agent lifecycle, cloud connectors, onboarding standards, and service health.
  • Support scanning across servers, endpoints, databases, network devices, appliances, cloud assets, containers, external-facing assets, and other enterprise technologies.
  • Partner with network and infrastructure teams on scanner placement, network zones, routing, firewall rules, segmentation, latency, reachability, authenticated scanning, and scan troubleshooting.
  • Drive asset discovery, inventory reconciliation, coverage reporting, ownership validation, and integration with CMDB and authoritative asset sources.
  • Build and maintain automation, APIs, configuration management, dashboards, reporting workflows, and data pipeline integrations, including integrations that ingest asset, ownership, cloud, and configuration data from enterprise systems and publish vulnerability and posture data to downstream remediation, reporting, and risk platforms.
  • Partner with vulnerability management teams to enable prioritization, remediation tracking, SLA governance, exception workflows, and major vulnerability response.
  • Own platform monitoring, health checks, operational dashboards, incident response, vendor escalations, disaster recovery readiness, and business continuity procedures.
  • Support SSO, RBAC, privileged access, service accounts, API tokens, access recertification, segregation of duties, audit evidence, and regulatory reporting.
  • Troubleshoot complex issues across tools, agents, scanners, APIs, cloud connectors, networks, identity systems, data pipelines, vendor platforms, and downstream reporting consumers.
  • Create dynamic engineering solutions using languages such as Python, Go, Java, or similar.
  • Mentor engineers, improve runbooks and documentation, and raise the technical bar through hands-on platform expertise.

To be successful in this role, you bring:

  • Hands-on experience running and engineering enterprise cybersecurity platforms, especially vulnerability management, scanning, asset discovery, cloud security posture, or cloud-native application protection platforms in large financial institutions.
  • Strong operational discipline, including production support, incident response, change management, service health monitoring, vendor escalation, and lifecycle management.
  • Strong engineering mindset, including automation, API integration, configuration management, repeatable deployment patterns, data quality improvement, and toil reduction.
  • Strong understanding of vulnerability management operating models, including remediation tracking, SLA governance, exceptions, ownership validation, and major vulnerability response.
  • Strong networking knowledge, including TCP/IP, routing, DNS, firewalls, proxies, load balancers, network segmentation, NAT, packet flows, latency, and reachability troubleshooting.
  • Experience scanning and assessing diverse enterprise technologies, including servers, endpoints, network devices, databases, appliances, cloud assets, containers, and externally exposed systems.
  • Knowledge of scanner architecture, agent health, network zones, scan routes, authenticated scanning, credential management, and scan troubleshooting.
  • Experience with cloud environments, including AWS, Azure, and GCP, cloud connectors, IAM, APIs, and security control frameworks.
  • Experience integrating cybersecurity platforms with CMDB, ticketing systems, reporting platforms, data pipelines, cloud platforms, vulnerability management systems, and enterprise dashboards.
  • Strong understanding of access management, including SSO, MFA, RBAC, privileged access, service accounts, API tokens, and recertification.
  • Programming and automation skills using Python, Go, Java, or similar.
  • Ability to debug complex issues across platforms, agents, scanners, cloud connectors, APIs, data pipelines, identity systems, networks, firewalls, routing paths, and vendor services.
  • Experience supporting audit, regulatory reporting, evidence retention, operational controls, and production change management.
  • A mindset focused on automation, scalability, governance, resilience, and reducing operational friction.
  • Experience with Kubernetes and container vulnerability management, including cluster visibility, container image assessment, runtime context, registry integrations, cloud-native asset inventory, and remediation workflows.

Preferred:

  • Experience with the following tooling preferred: Qualys, Wiz.io, Lumeta, or similar vulnerability management, asset discovery, network visibility, and cloud security posture platforms.
  • Experience operating or engineering cybersecurity platforms in FedRAMP-authorized or FedRAMP-aligned cloud environments.
  • Familiarity with FedRAMP control expectations, evidence collection, vulnerability scanning requirements, continuous monitoring, access governance, and cloud security operations.

Success Profile

  • Becomes a senior technical authority for both operating and engineering vulnerability management and cloud security posture tooling.
  • Bachelor's degree in computer science or a related discipline, or equivalent work experience required, advanced degree preferred.
  • 10-12 years of experience in information security or related technology experience required, experience in the securities or financial services industry is a plus.
  • Keeps critical cybersecurity platforms stable, healthy, upgraded, monitored, documented, and supportable.
  • Improves platform reliability, scan health, agent health, connector health, data quality, and operational visibility.
  • Expands coverage across infrastructure, applications, business units, cloud accounts, containers, network devices, appliances, and external-facing assets.
  • Enables reliable reporting, remediation tracking, SLA governance, audit evidence, and regulatory support.
  • Reduces manual effort through automation, repeatable onboarding, self-service intake, standardized runbooks, and engineered controls.
  • Strengthens access governance, platform controls, service ownership discipline, and production resilience.

This role is for someone who wants to run, own, and engineer the platforms that define cyber risk visibility across the enterprise. Day-to-day platform execution and long-term engineering decisions will directly impact security posture, vulnerability response, regulatory confidence, and operational resilience across BNY.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the SVP, Vulnerability Management & Cloud Security Posture Platform Engineering in New York, NY vacancy
  •  ...We're seeking a team member for the role of SVP, Vulnerability Management & Cloud Security Posture Platform Engineering to join our Cybersecurity Engineering Tools & Platforms team. This role is located in New York, NY; Pittsburgh, PA; or Washington, DC . This is... 
    Cloud
    Work experience placement

    BNY Mellon

    New York, NY
    18 hours ago
  • BNY Mellon is seeking an SVP for Vulnerability Management & Cloud Security Posture Engineering to lead efforts in enhancing cybersecurity platforms in New York City. This individual will engineer and operate enterprise platforms ensuring vulnerability management and cloud... 
    Cloud

    BNY Mellon

    New York, NY
    2 days ago
  • $195k - $240k

    Bloomberg L.P. is seeking a Senior Cloud Security and Vulnerability Analyst in New York. This role focuses on ensuring the public cloud IT infrastructure...  ...vulnerabilities and collaborating with security engineering teams. Candidates should have 10+ years of relevant experience... 
    Cloud

    Bloomberg L.P.

    New York, NY
    2 days ago
  • $150k - $175k

     ...alternative investment managers, including...  ...a robust and secure technology foundation...  ...the firm's vulnerability management and patching...  ...directly with engineering and...  ...vulnerability management platform infrastructure,...  ...Knowledge of cloud security posture management (CSPM... 
    Cloud
    Shift work

    PJT Partners

    New York, NY
    2 days ago
  • $50 per hour

     ...Our client is seeking a Security Engineer . This individual will play...  ...and remediating security vulnerabilities across cloud and on-premise...  ...Responsibilities and Duties Manage and improve the...  ...Vulnerability Management platforms such as Rapid7, Qualys, or... 
    Cloud

    The Right Click, Inc.

    New York, NY
    18 hours ago
  • $124.9k - $228.9k

     ...leading independent platform for digital...  ...Our Software Engineers are end-to-end owners...  ...thousands of servers in cloud and physical data...  ...The Platform Security team builds foundational...  ...Secrets and certificate management Security health...  ...about security posture, model... 
    Cloud
    Full time
    Temporary work
    Local area
    Worldwide

    The Trade Desk

    New York, NY
    3 days ago
  • $165k - $242k

     ...Security Engineering Manager, Platform Security Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA...  ...Francisco, CA CoreWeave is The Essential Cloud for AI™. Built for pioneers by...  ...strategy and execution for cloud security posture, workload isolation, platform... 
    Cloud

    CoreWeave

    New York, NY
    18 hours ago
  • $188k - $275k

     ...Staff Security Engineer, Vulnerability Management Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators... 
    Cloud
    Permanent employment
    Temporary work
    Casual work
    Work at office
    Flexible hours

    CoreWeave

    New York, NY
    5 days ago
  •  ...Senior Cloud Security Engineer At BNY, our culture allows us to run our...  ...security controls across cloud platforms and cloud-native services...  ...technical leadership, posture management, and close partnership...  ...security, API security, vulnerability management, and cloud-native... 
    Cloud
    Worldwide

    BNY

    New York, NY
    a month ago
  •  ...Vulnerability Operations Engineer Cloud Engineering/DevOps This Vulnerability Operations...  ...vulnerability management across infrastructure, applications...  ...Rapid7, Nexpose, or similar platforms. Analyze and...  ...analysis to identify recurring security gaps and systemic control... 
    Cloud
    Contract work

    Delphi-US, LLC - Peacemakers in the Talent War

    New York, NY
    18 hours ago
  •  ...Application Security Engineer | Location: New York, NY...  ...identify and remediate vulnerabilities, mature DevSecOps...  ...mobile, and API-based platforms. Conduct secure...  .... Implement and manage application security...  ...Collaborate with cloud and infrastructure teams... 
    Cloud
    Contract work

    Delphi-US

    New York, NY
    4 days ago
  • $83k - $209k

     ...Cloud Security Engineer At BNY, our culture allows us to run our company...  ...across infrastructure, platform, and application...  ...maturity of Cloud Security Posture Management (CSPM) capabilities to identify...  ...security, API security, or vulnerability management is a plus. ~... 
    Cloud
    Temporary work
    Worldwide
    Flexible hours

    BNY Mellon

    New York, NY
    3 days ago
  • Hightouch is the modern AI platform for marketing and growth...  ...and rapid adoption of cloud data warehouses like...  ...is our first dedicated security hire, and it's a rare chance...  ...'s application security posture end‑to‑end. We have strong engineering fundamentals and a solid... 
    Cloud
    Shift work

    Hightouch

    New York, NY
    1 day ago
  •  ...VRNS) is a leader in data security, fighting a different...  ...cybersecurity companies. Our cloud-native Data Security Platform continuously discovers...  ...including data security posture management (DSPM), data...  ...innovative Inside Sales Engineer to join our team. The ideal... 
    Cloud
    Remote work
    Worldwide

    Varonis

    New York, NY
    1 day ago
  • $300k - $330k

     ...revolutionizing the way large networks are managed. The Forward Enterprise platform delivers a vendor‑agnostic “...  ...of network devices, whether cloud, hybrid cloud, or on‑prem. It serves...  ...network operators to instantly verify security posture, accelerate troubleshooting, avoid... 
    Cloud
    Full time
    Work experience placement
    Remote work

    Forward Networks, Inc.

    New York, NY
    1 day ago
  • Tricon Solutions is seeking a Platform DevSecOps Engineer in Fort Lee, NJ. This...  ...and ensuring application security across environments....  ...experience in AWS and Google Cloud Platform, as well as a strong...  ...that include vulnerability management and participation in a 24... 
    Cloud

    Tricon Solutions

    Fort Lee, NJ
    18 hours ago
  •  ...and rapid paced team. You'll secure, scale, and operate the...  ...modeling and compliance program management to CI/CD, observability,...  ...Responsibilities Own our cloud security posture across AWS (ECS Fargate,...  ...remediation guidance for engineering teams Build observability... 
    Cloud
    Local area

    Polimorphic

    New York, NY
    4 days ago
  •  ...implementation of Application Security controls across CI/...  .... Define and manage tiered security...  ...ownership across engineering teams. 2. Vulnerability & Threat Management...  ...threat classes including cloud-native risks, APIs,...  ...on security posture and trends. Manage... 
    Cloud

    2T Consulting

    Jersey City, NJ
    4 days ago
  •  ...hands‑on Head of Security to own and build our security posture end-to-end. This is...  ...a policy-only or management-only position. You...  ...Infrastructure (cloud + networking) Establish...  ...or supervise deep vulnerability research Define...  ...Background Strong engineering background (you’ve... 
    Cloud
    Contract work

    Framework Ventures

    New York, NY
    1 day ago
  • $2,500 per month

     ...Implement a Zero-Trust Security Architecture Sep 2...  ...a diverse set of cloud-based applications...  ...: Our security posture is based on the...  ...making us highly vulnerable to insider threats...  ...makes it difficult to manage and secure our...  ...Access Management platforms (Okta, Auth0, etc.... 
    Cloud
    Freelance

    Featmate

    New York, NY
    1 day ago
  • A leading staffing agency is seeking a GCP Platform Administrator to manage and optimize their Google Cloud Platform infrastructure. This remote, full-time role focuses on ensuring performance, security, and scalability of cloud solutions. Ideal candidates will possess... 
    Cloud
    Remote job
    Full time

    Pinnacle Talent Placement

    New York, NY
    1 day ago
  •  ...the highest levels of security, safety, and...  ...for a Customer Success Manager with extensive experience...  ...River Studio Developer, Cloud Platform, Linux, etc. In...  ...internal resources (from Engineering, Product Management,...  ...access control, and vulnerability management in embedded... 
    Cloud

    Aptiv PLC

    New York, NY
    1 day ago
  •  ...We are hiring a Security Engineering Lead to own security...  ...Credential safety: secrets management, key rotation, least...  ...IAM patterns across cloud and internal tooling....  ...and device security posture for laptops and operational...  ...environments. Vulnerability management and... 
    Cloud

    Mecka AI

    New York, NY
    3 days ago
  • $70k - $120k

     ...is driven by risk management, threat-informed defense...  .... The Analyst, Vulnerability Management - Cloud supports JetBlue's...  ..., and future cloud platforms as adopted. The Analyst...  ..., Cloud Engineering, DevOps, Infrastructure...  ...management, cloud security, CSPM/CNAPP, container... 
    Cloud
    Temporary work
    Work experience placement
    Work at office
    Immediate start
    Flexible hours
    Night shift

    JetBlue

    Long Island City, NY
    4 days ago
  • $115k - $125k

     ...cybersecurity and compliance services firm is seeking a Continuous Monitoring Engineer. This fully remote role emphasizes vulnerability management, compliance monitoring, and cloud security across major platforms like AWS, Azure, and GCP. Successful candidates will manage... 
    Cloud
    Remote job

    Piper Companies

    New York, NY
    1 day ago
  •  ...Application Security Lead Our client is...  ...to firm's Asset Management and Financial Advisory...  ...AWS/Azure/GCP cloud architecture – experience...  ...security and vulnerability analyses,...  ...with the solution engineering and security architecture...  ...the security posture of the current... 
    Cloud

    ERS Search

    New York, NY
    18 hours ago
  • $110k - $140k

     ...the largest Federal managed cloud, building and operating secure cloud and AI...  ...The Devops Security Engineer is a hands-on DevSecOps...  ...security posture and deployment readiness...  ...workflows against platform security requirements...  ..., including vulnerability tracking, POA&M updates... 
    Cloud
    Full time
    Contract work
    Immediate start
    Remote work

    Knox Systems

    New York, NY
    1 day ago
  • $200k - $250k

     ...Engineering • New York, New York • In...  ...is the marketing platform for the AI era....  ...they rely on are secure, compliant, and...  ...Profound's security posture across our...  ...access control, vulnerability management, compliance, and...  ...security services and cloud security... 
    Cloud
    Work at office
    Shift work

    Profound

    New York, NY
    1 day ago
  • Socotra, Inc. is seeking a Cloud Security Engineer to develop automated security solutions for cloud environments....  ...engineering guardrails and improving security posture through proactive solutions across multi-cloud platforms. The ideal candidate will possess a degree in... 
    Cloud

    Socotra, Inc.

    New York, NY
    18 hours ago
  •  ...skilled Senior IAM Engineer to...  ...identity and access management infrastructure...  ...intersection of security, scale, and...  ...cutting‑edge cloud‑native authentication platforms. This role offers...  ...Improve Security Posture: You will...  ...identifying systemic vulnerabilities, proposing... 
    Cloud
    Permanent employment

    Estreetsecurity

    New York, NY
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to SVP, Vulnerability Management & Cloud Security Posture Platform Engineering. Be the first to apply!