Hiring.Camp

AVP Vulnerability Management Program Manager

Ffin

·

Yesterday

Location
Operations Center, United States of America
Type
Full-time
Department
Management
Seniority
Manager
Education
Master
Source
Workday

Description

Address

We’re always looking for bright individuals to join our growing organization. As a part of the First Financial Family, we will invest in your development and provide a dynamic work environment where you’re challenged, valued and empowered every day. We strive to be the best destination for the industry’s top talent, creating a diverse, collaborative workplace that celebrates innovation and change. We are one team, working together to get things done.

Job Description:

Office Location:

Abilene, Texas, United States

ROLE SUMMARY

The Assistant Vice President, Vulnerability Management Program Manager leads the ongoing administration, governance, and continuous improvement of First Financial Bankshares' enterprise Vulnerability Management Program. This role ensures vulnerabilities are identified, prioritized, tracked, remediated, validated, reported, and evidenced in accordance with approved standards, risk management expectations, and applicable regulatory requirements.

The position provides dedicated program leadership across Information Security, technology operations, application teams, risk management, Internal Audit, third-party providers, and other stakeholders. The role translates technical exposure into clear business risk, drives remediation accountability, coordinates governance and reporting, and helps maintain a sustainable and demonstrably effective program.

KEY RESPONSIBILITIES

Program Leadership & Governance

  • Lead the day-to-day administration and ongoing maturity of the enterprise Vulnerability Management Program.
  • Maintain the program roadmap, governance documentation, operating procedures, standards alignment, and recurring review activities.
  • Coordinate the Vulnerability Management Council, including agendas, decisions, action items, escalations, and follow-through.
  • Promote consistent execution of program requirements across technology functions, support organizations, and applicable business units.

Risk-Based Vulnerability Oversight

  • Oversee the vulnerability lifecycle from identification and validation through prioritization, remediation, exception management, risk acceptance, and closure.
  • Ensure prioritization considers exploitability, asset criticality, business impact, exposure, and other approved risk factors.
  • Monitor aging, overdue items, recurring issues, and material exposure; coordinate timely escalation and corrective action.
  • Provide oversight of vulnerabilities affecting internally managed, jointly managed, and vendor-managed technology environments.

Remediation Coordination & Accountability

  • Coordinate remediation activity across infrastructure, endpoints, networks, applications, databases, cloud services, and third-party technology providers.
  • Partner with accountable technology owners to establish remediation plans, remove execution barriers, and confirm sustainable closure.
  • Oversee dedicated vulnerability remediation resources and coordinate supplemental partner support as appropriate.
  • Validate that closure and exception records contain sufficient evidence to demonstrate appropriate disposition.

Performance Reporting & Executive Communication

  • Produce and maintain recurring program reporting for management and established governance bodies, including performance, risk, trend, maturity, and enhancement information.
  • Monitor approved service levels, key performance indicators, key risk indicators, backlog, aging, exceptions, and remediation outcomes.
  • Present program status and material issues in clear business terms to executive management, risk committees, Internal Audit, and other stakeholders.
  • Maintain consistent definitions, methodologies, and supporting evidence for reported measures.

Audit, Regulatory & Evidence Readiness

  • Coordinate vulnerability management evidence for Internal Audit, independent reviews, and regulatory examinations.
  • Maintain organized, complete, and repeatable evidence of program operation, governance decisions, remediation activity, reporting, exceptions, and management oversight.
  • Support responses to audit and regulatory requests and track related commitments through resolution.
  • Identify control or evidence gaps and coordinate timely corrective action.

Program Improvement & Capability Development

  • Assess program effectiveness and recommend improvements to processes, governance, reporting, technology enablement, automation, and resource alignment.
  • Monitor relevant threat, vulnerability, regulatory, and industry developments and evaluate their implications for the program.
  • Promote integration of vulnerability management practices into technology operations, change management, asset management, configuration management, and third-party oversight.
  • Support training, awareness, and role clarity for stakeholders with vulnerability management responsibilities.

Leadership & Collaboration

  • Provide direction, coaching, and performance support for assigned team members and program resources.
  • Build productive relationships across cybersecurity, technology, risk, audit, compliance, and business functions.
  • Influence outcomes without relying solely on direct authority and foster shared accountability for risk reduction.
  • Perform other duties and responsibilities as assigned.

MINIMUM QUALIFICATIONS

  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Business Administration, Risk Management, or a related field, or an equivalent combination of education and relevant experience.
  • Seven or more years of progressive experience in cybersecurity, information security, technology risk, technology operations, or a related discipline.
  • Three or more years of experience leading vulnerability management, cyber risk, security operations, governance, or comparable enterprise programs.
  • Demonstrated experience coordinating cross-functional remediation or risk-reduction initiatives in a complex technology environment.
  • Working knowledge of vulnerability assessment, risk-based prioritization, remediation governance, exception management, validation, metrics, and evidence practices.
  • Experience communicating technical risk, program performance, and decisions to management and non-technical stakeholders.
  • Strong written communication, facilitation, organization, analytical judgment, and stakeholder management skills.

PREFERED QUALIFICATIONS

  • MBA or advanced technical degree (Computer Science, Cybersecurity, Information Systems)
  • Experience in banking, financial services, or another highly regulated industry.
  • Experience supporting Internal Audit, independent assessments, or regulatory examinations.
  • Experience building, formalizing, or maturing an enterprise vulnerability management or cyber risk program.
  • Knowledge of recognized cybersecurity and control frameworks, including NIST Cybersecurity Framework, NIST Special Publication 800-53, CIS Controls, and FFIEC cybersecurity guidance.
  • Professional certification such as CISSP, CISM, CRISC, CGRC, GIAC, PMP, or a comparable credential.
  • Experience with enterprise vulnerability assessment, workflow, reporting, data visualization, or security automation platforms.

WORK ENVIRONMENT AND EXPECTATIONS

Onsite presence is required in accordance with company expectations for the position.  Hybrid work arrangement will be considered based on the candidate’s qualifications.

May require occasional work outside normal business hours to support urgent vulnerability response, material escalations, examinations, or business needs.

Must maintain the confidentiality and integrity of sensitive security, risk, audit, regulatory, employee, customer, and company information.

Commitment to a professional workplace that supports collaboration, respect, equal opportunity, and inclusion.

The above statements reflect the general details considered necessary to decide the principal functions of the job identified and shall not be construed as a detailed description of all work requirements that may be

inherent in the job.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor’s legal duty to furnish information. 41 CFR 60-1.35(c)

Skills

CybersecurityRisk ManagementComplianceChange ManagementPMPCISSP
AVP Vulnerability Management Program Manager at Ffin | Hiring.Camp