Vulnerability and Exposure Management Program Manager
$170.26k - $200.3kU.S. Bank
At U.S. Bank, we're on a journey to do our best. Helping the customers and businesses we serve to make better and smarter financial decisions and enabling the communities we support to grow and succeed. We believe it takes all of us to bring our shared ambition to life, and each person is unique in their potential. A career with U.S. Bank gives you a wide, ever-growing range of opportunities to discover what makes you thrive at every stage of your career. Try new things, learn new skills and discover what you excel at-all from Day One.
Job Description
Location Expectation
This role requires working from a U.S. Bank location three (3) or more days per week.
Role Overview
The Vulnerability and Exposure Management Program Manager is accountable for the enterprise vulnerability management strategy and operating model-expanding beyond traditional vulnerability management to build and lead a largely newly established continuous exposure management capability.
This is a strategic, enterprise-scale leadership role responsible for transforming an evolving program, addressing effectiveness gaps, and improving stakeholder confidence while reducing risk and enabling business and technology development.
The role partners across technology and business leadership to embed vulnerability and exposure reduction practices across cloud, data, digital, and AI initiatives. It includes ownership of internal and external exposure management capabilities, including attack surface visibility, attack path mitigation, and risk-based prioritization to reduce real-world exploitability.
The leader will operate within a highly regulated environment and must demonstrate strong executive presence and negotiation skills , with the ability to influence senior stakeholders and lead through a multi-layer organization at enterprise scale.
Key Responsibilities
Define and execute the enterprise vulnerability and exposure management strategy and multi-year roadmap, including transforming program effectiveness and stakeholder outcomes .
Build, scale, and lead a largely new exposure management capability , expanding beyond current-state maturity into a comprehensive, enterprise-wide program.
Establish and operate a scalable model across infrastructure, applications, cloud, containers, third-party technology, and external attack surface, including governance, decision rights, and escalation paths.
Drive risk-based prioritization and remediation by integrating severity, exploitability, threat intelligence, asset criticality, and business context; lead zero-day response and decision-making.
Set and enforce remediation SLAs aligned to a faster, AI-influenced threat environment , with strong governance for exceptions and compensating controls.
Partner across CIO/CTO organizations, security, engineering, and business lines to embed vulnerability reduction into delivery practices (e.g., CI/CD), platform guardrails, and operational processes.
Modernize tooling, processes, and automation (including AI) to improve speed, accuracy, and efficiency of detection and remediation.
Deliver executive reporting and insights (KPIs/KRIs), translating technical risk into clear business impact, trends, and actions.
Leverage large-scale data analysis (millions of vulnerabilities) to identify themes, root causes, and opportunities for targeted risk reduction.
Ensure regulatory and audit readiness through strong documentation, controls, and issue management practices.
Lead and develop a multi-layer organization (25-35+ employees) , including 5-8 direct reports who are people leaders , focusing on strategy and outcomes rather than hands-on technical execution.
Manage budget, vendors, and strategic partnerships, including evaluation and implementation of capabilities to improve coverage and remediation effectiveness.
Establish and enhance External Attack Surface Management (EASM) and enterprise asset intelligence, identifying unmanaged or unknown assets and bringing them into governance.
Incorporate adversary-informed perspectives into prioritization, aligning efforts with real-world threat behavior and attack paths.
Evolve the program toward a continuous, global operating model to support enterprise-scale responsiveness.
Basic Qualifications
Bachelor's degree in information security, Computer Science, Information Technology, or a related field; advanced degree preferred
Professional certifications such as CISSP, CISM, CISA, or equivalent strongly preferred
10+ years of progressive experience in information security, technology risk, or security operations, including ownership of enterprise-scale programs in large, complex organizations
5+ years of people leadership experience, including leading managers and multi-layer teams (leader of leaders)
Demonstrated ability to influence senior executives, drive cross-functional alignment, and deliver results in complex, evolving environments
Experience operating in highly regulated industries (e.g., banking, insurance, healthcare)
Preferred Skills / Experience
Exceptional executive communication and stakeholder management skills, including regulator- and audit-facing interactions
Strong negotiation skills to drive alignment, resolve conflict, and deliver outcomes with senior leaders
Experience leading vulnerability management and/or exposure management programs at enterprise scale
Expertise in risk-based prioritization, vulnerability lifecycle management, and exposure reduction strategies
Deep understanding of attack surface management, EASM, and asset discovery across internal and external environments
Strong data and analytics capability, including experience working with large datasets and translating insights into action
Metrics-driven leadership (KPIs/KRIs, SLA performance, MTTR, risk posture) with a focus on measurable outcomes
Experience modernizing security programs through automation, tooling, and AI-enabled capabilities
Proven ability to operate at enterprise scale , balancing risk reduction with business enablement in a regulated environment
If there's anything we can do to accommodate a disability during any portion of the application or hiring process, please refer to our disability accommodations for applicants ( .
Benefits:
Our approach to benefits and total rewards considers our team members' whole selves and what may be needed to thrive in and outside work. That's why our benefits are designed to help you and your family boost your health, protect your financial security and give you peace of mind. Our benefits include the following:
Healthcare (medical, dental, vision)
Basic term and optional term life insurance
Short-term and long-term disability
Pregnancy disability and parental leave
401(k) and employer-funded retirement plan
Paid vacation (from two to five weeks depending on salary grade and tenure)
Up to 11 paid holiday opportunities
Adoption assistance
Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise provided by law
Review our full benefits available by employment status here ( .
U.S. Bank is an equal opportunity employer. We consider all qualified applicants without regard to race, religion, color, sex, national origin, age, sexual orientation, gender identity, disability or veteran status, and other factors protected under applicable law.
E-Verify
U.S. Bank participates in the U.S. Department of Homeland Security E-Verify program in all facilities located in the United States and certain U.S. territories. The E-Verify program is an Internet-based employment eligibility verification system operated by the U.S. Citizenship and Immigration Services. Learn more about the E-Verify program ( .
The salary range reflects figures based on the primary location, which is listed first. The actual range for the role may differ based on the location of the role. In addition to salary, U.S. Bank offers a comprehensive benefits package, including incentive and recognition programs, equity stock purchase 401(k) contribution and pension (all benefits are subject to eligibility requirements). Pay Range: $170,255.00 - $200,300.00
U.S. Bank will consider qualified applicants with arrest or conviction records for employment. U.S. Bank conducts background checks consistent with applicable local laws, including the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act as well as the San Francisco Fair Chance Ordinance. U.S. Bank is subject to, and conducts background checks consistent with the requirements of Section 19 of the Federal Deposit Insurance Act (FDIA). In addition, certain positions may also be subject to the requirements of FINRA, NMLS registration, Reg Z, Reg G, OFAC, the NFA, the FCPA, the Bank Secrecy Act, the SAFE Act, and/or federal guidelines applicable to an agreement, such as those related to ethics, safety, or operational procedures.
Applicants must be able to comply with U.S. Bank policies and procedures including the Code of Ethics and Business Conduct and related workplace conduct and safety policies.
Posting may be closed earlier due to high volume of applicants.
$108k - $148k
...About this role: Gartner is looking for a well-rounded IT Program Manager who can provide project and program leadership for technology... ...Encouragement to be innovative and challenge status quo • Exposure to industry leading training and development • Performance...SuggestedFor contractorsApprenticeshipImmediate startWork from homeWorldwideFlexible hours- ...Data & Analytics Integration Program Manager Owns the Data & Analytics integration workstream for acquired companies, cutting horizontally... ...Nice to have: Prior M&A / acquisition integration exposure (not required) Experience evaluating tooling options and discussing...SuggestedRemote work
- ...are seeking a dynamic and highly skilled hands-on Technical Program Manager (TPM) to lead factory-side execution across manufacturing process... ...with software-only TPM experience or limited factory-floor exposure will not be a fit for this position. Key Responsibilities...Suggested
- ...Job Title:Technical Program Manager-Senior Location:Irving,Tx Duration:8 months The position is for a delivery focusedTechnical... ...regulatory timelines Development Value: Significant Senior management exposure opportunity to work with experienced professionals located...SuggestedWorldwide
- ...Substation Program Manager - Strategic Growth & Delivery Together, we own our company, our future, and our shared success. As an employee... ...(electric currents, working on scaffolding and high places, exposure to chemicals), atmospheric conditions (fumes, odors, dusts,...SuggestedContract workWork experience placementWork at officeFlexible hours
$102k - $117k
...sounds and insights through some of the best programming and technology in the world. Our... ...seeking an Associate Technical Program Manager (TPM) to help drive cross-functional software... ...work in the U.S. Nice to Have * Exposure to consumer-facing products such as mobile...Temporary workLocal area$102k - $142.8k
...bonus eligibility ~ Comprehensive benefits package ~ Paid time off ~401k & company match Position Summary: The program manager is responsible for the management of significant and operational, multi-disciplinary projects that require a broad knowledge of...- ...execution. We combine deep technical and management expertise to solve complex challenges,... ...in the United States. We are seeking a Program Manager with deep expertise in Mergers and... ...This role provides significant growth and exposure across multiple M&A initiatives within a...Full timeContract workRemote work
$58 - $62 per hour
...Senior Program Manager Legacy Modernization Senior Program Manager with deep experience running enterprise-scale transformation programs... ...-modern or mainframe modernization initiatives ~ Hands-on exposure to mainframe environments; COBOL migration is a strong plus...Hourly pay- ...and help us build the future. What You'll Do The Sr. Program Manager will lead cross-functional initiatives from planning through... ...fast-paced, evolving environments with shifting priorities Exposure to managing multiple concurrent projects within a portfolio or...For contractorsShift work
- ...delivery of large-scale product development programs while proactively identifying new... ...business opportunities. Client Relationship Management - Proven experience in building strong... ...Technical Understanding - Adequate exposure to web technology architecture, cloud platforms...
- ...Job Description The Program Manager is responsible for overseeing end-to-end service delivery performance, customer communication, and operational coordination across onsite and depot service programs. This role ensures consistent execution, high-quality service,...
- ...Skill Set: Project Management,Risk Management,CONTROL Location: Dallas Job Description... ...in project management and 3+ years in program management. Proficient in written and verbal... ...customer and organizations management. Exposure US lending/credit domain. Salesforce...
- ...mechanical, process engineering, pipeline design, and integrity management works together to deliver integrated, high-impact solutions.... ...Survey / Geospatial teams in Dallas, or San, Antonio, Texas. As a Program Manager, you will provide overall leadership for our survey...Work at office
- ...Cabin / Interior Program Manager The Cabin / Interior Program Manager is responsible for managing aircraft cabin interior completion and... ...hours to meet program milestones and delivery schedules. Exposure to aircraft maintenance environments including noise, equipment...Contract workWork at office
- ...Program Manager - EPMO (contract) Agility 360 is looking for a qualified and highly energetic candidate to fill the position of Program Manager (EPMO). The Program Manager within the Enterprise Project Management Office (EPMO) partners with business lines to define...Hourly payContract workLocal areaRemote work
- ...Non-It Program Manager The main function of a non-IT program manager is to plan, direct, or coordinate activities in such fields as engineering, research and development, financial systems and product roll-out, etc or any other non-IT based project. Job Responsibilities...
$112.4k - $149.8k
...lists. First American will always strive to be a great place to work, for all. For more information, please visit What We DoThe Program Manager, AI Adoption & Enablement will lead employee adoption, engagement, and operational enablement efforts related to AI...Local areaRemote work- ...SailPoint Program Manager Location TX/NJ/NC Contract Relevant Experience Years 15+ years of experience with IAM projects with 8+ years managing multi-workstream projects in IAM domain in large enterprise environments Tools • SailPoint IIQ (Must have...Contract work
- ...about driving innovation and making a difference. Your role and responsibilities About the Role As a Staff GTM Operations Manager, you are a master of execution and oversight. You don’t just follow processes—you build, monitor, and refine them to ensure global...Contract work
$127.2k - $185k
...and Sustainability (Ops GEMS) organization is seeking a detail-oriented, analytical, innovative, hands-on, and customer-obsessed Program Manager (PM) capable of providing program management support in a fast paced and highly ambiguous environment. The Ops GEMS...Full timeTemporary workSeasonal workWorldwideFlexible hours- ...Position Description & Qualifications Program Manager F-35 Enterprise IT Services Crystal City/Arlington, Virginia Are you looking for an IT oriented Program Manager position that supports corporate mission daily and shares our culture based on a set of four...Full timeContract workPart timeWork experience placementFor subcontractorWork at officeLocal areaRemote workFlexible hours3 days per week
$70k - $104k
...Role Overview : As the Meetings Program Manager supporting the Strategic Partnerships team, you will play a pivotal role in driving the success of Gartner Conferences by orchestrating meeting programs that facilitate meaningful engagement between internal business...Worldwide$115.6k - $160k
...Amazon's Selling Partner API (SP-API) team is seeking an experienced Senior Program Manager to lead the Program Management Office (PMO) within our Solutions Architecture (SA) practice. This role will support cross-functional initiatives and requires expertise in program...Work at officeFlexible hours$130k - $160k
...Operational Technology Program Manager At Jacobs, we're challenging today to reinvent tomorrow by solving the world's most critical problems... ...prioritization decisions based on financial health, risk exposure, and revenue impact Provide leadership with consolidated...Contract workRemote work- ...A leading business and technology services company seeks an experienced Program Manager EQMS to lead the execution of key projects and initiatives. This role is crucial for governing and facilitating an Enterprise Quality Management System standardization process and requires...Remote work
- ...Consulting services in the US. We are actively seeking Technology Program Manager for one of our direct client in Dallas,TX. Please share your... ...Segmentation, Data Protection, Identity Access Management, Threat and Vulnerability Management. Thanks & Regards, Naveen
- ...IT Specialty - Program Manager (Healthcare Program Manager) Remote Involves overseeing multiple programs and coordinating with senior leaders and delivery team members. The successful candidate will have a strong leadership presence and demonstrated ability...Remote workFlexible hours
$100k - $120k
...About the job Technical Program Manager - Manufacturing Operations We are partnering with a fast-growing manufacturing organization... ..., vision inspection, or poka-yoke solutions is a plus Exposure to tooling validation, supplier coordination, process qualification...Full timeOverseas- ...Community Impact Program Manager ( Resident Professional Program) Location: Corporate Office (Irving, TX) - Monday through Thursday in person. Remote Fridays. Reports To: Vice President, Strategic Initiatives Classification: Full-Time, Exempt Travel: Up to 30%...Full timeFor contractorsWork at officeLocal areaRemote workMonday to Thursday
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability and Exposure Management Program Manager. Be the first to apply!
- national program manager Irving, TX
- program manager government Irving, TX
- nutrition program coordinator Irving, TX
- program coordinator remote Irving, TX
- localization program manager Irving, TX
- remote program manager Irving, TX
- amazon program manager Irving, TX
- head of program management Irving, TX
- program director Irving, TX
- IT program manager Irving, TX

