15+ years of IT experience with 8+ years in Information Security
Deep expertise in enterprise Vulnerability Management and risk-based prioritization.
Experience operating in a Three Lines of Defense model and/or regulated environment (financial services preferred).
Strong understanding of infrastructure, cloud, networking, and common vulnerability classes.
Ability to translate technical findings into business risk and executive-level insights
Experience in fintech or highly regulated industries
Familiarity with CVSS, EPSS, threat intelligence, and KEV-based prioritization.
Background in risk management, audit, or control validation.
Background and drug screen.
The above job description is not intended to be an all-inclusive list of duties and standards of the position. Incumbents will follow instructions and perform other related duties as assigned by their supervisor.
Physical Requirements
Employee must be able to perform essential functions and physical requirements of position with or without reasonable accommodation.
The base pay scale for this position in:
Phoenix, AZ/ Chicago, IL / Washington, DC in USD per year is: $154,000 - $193,000.
New York, NY/ San Francisco, CA in USD per year is: $186,000 - $232,000.
Additionally, candidates are eligible for a discretionary incentive plan and benefits.
Benefits
Equity / stock options
Additional Information
At Early Warning, we've powered and protected the U.S. financial system for over thirty years with cutting-edge solutions like Zelle®, Paze℠, and so much more. As a trusted name in payments, we partner with thousands of institutions to increase access to financial services and protect transactions for hundreds of millions of consumers and small businesses.
Positions located in Scottsdale, San Francisco, Chicago, or New York follow a hybrid work model to allow for a more collaborative working environment.
Candidates responding to this posting must independently possess the eligibility to work in the United States, for any employer, at the date of hire. This position is ineligible for employment Visa sponsorship.
Overall Purpose:
The Principal of Vulnerability Management Oversight is responsible for ensuring the enterprise Vulnerability Management (VM) program is effective, risk-aligned, and defensible-through independent challenge, governance, and validation.
This role provides independent risk-based governance within a Three Lines of Defense (3LOD) model, ensuring VM practices across the organization are effective, measurable, and aligned to risk appetite and regulatory expectations. The position partners closely with engineering, infrastructure, and application teams, acting as a credible challenger-not an operator. This role will support the Cybersecurity and Technology Risk Management team within the Second Line of Defense (2LOD) and report directly to the 2LOD VP of Information Security Risk.
Essential Functions:
Provide independent challenge and oversight of vulnerability identification, prioritization, and remediation practices across enterprise environments.
Define and maintain VM policies, standards, and risk-based remediation SLAs.
Perform control validation and effectiveness testing of VM processes, tooling, and data quality.
Assess and challenge risk acceptance decisions, compensating controls, and remediation timelines.
Deliver risk-based reporting and insights on vulnerability exposure, trends, and systemic gaps.
Provide oversight of VM tooling (e.g., Tenable, Qualys, Rapid7) to ensure coverage, configuration, and data integrity.
Partner with First Line teams, Risk, Compliance, and Audit to ensure alignment with internal policies and regulatory expectations.
Support regulatory exams and internal audits as the VM Second Line SME.