- Location
- North Dallas Campus, United States of America
- Type
- Full-time
- Department
- Security
- Seniority
- Manager
- Experience
- 10+ years
- Education
- Bachelor
- Source
- Workday
Description
Texas Capital is built to help businesses and their leaders. Our depth of knowledge and expertise allows us to bring the best of the big firms at a scale that works for our clients, with highly experienced bankers who truly invest in people’s success — today and tomorrow.
While we are rooted in core financial products, we are differentiated by our approach. Our bankers are seasoned financial experts who possess deep experience across a multitude of industries. Equally important, they bring commitment — investing the time and resources to understand our clients’ immediate needs, identify market opportunities and meet long-term objectives. At Texas Capital, we do more than build business success. We build long-lasting relationships.
Texas Capital provides a variety of benefits to colleagues, including health insurance coverage, wellness program, fertility and family building aids, life and disability insurance, retirement savings plans with a generous 401K match, paid leave programs, paid holidays, and paid time off (PTO).
Headquartered in Dallas with offices in Austin, Fort Worth, Houston, Richardson, Plano and San Antonio, Texas Capital was recently named Best Regional Bank in 2024 by Bankrate and was named to The Dallas Morning News’ Dallas-Fort Worth metroplex Top Workplaces 2023 and GoBankingRate’s 2023 list of Best Regional Banks. For more information about joining our team, please visit us at www.texascapitalbank.com.
Responsibilities
• Lead the identification, assessment, prioritization, and management of vulnerabilities across on-premises and cloud-based infrastructure, networks, applications, databases, and technology platforms
• Proactively identify security weaknesses and reduce organizational risk.
• Collaborate with cross-functional technology, infrastructure, cloud, and application teams to remediate vulnerabilities and configuration weaknesses, ensuring timely risk reduction and compliance with established remediation requirements.
• Analyze findings and provide detailed reports daily, weekly and monthly with actionable recommendations for improving security posture
• Stay updated on the latest cybersecurity threats, trends, and technologies to ensure cutting-edge testing strategies
• Assist in developing security
Qualifications
• Bachelor's degree in Information Security, Information Technology, Computer Science, Engineering, or related field.
• Minimum 10 years of experience in an appropriate domain.
• Strong expertise in enterprise Vulnerability Management programs, including network-based, agent-based, cloud-native, application, container, and infrastructure vulnerability assessment technologies.
• Experience integrating vulnerability management practices into enterprise governance, risk management, and compliance (GRC), and operational risk programs.
• Deep understanding of vulnerability scoring methodologies and frameworks, including but not limited to: CVSS, EPSS (Exploit Prediction Scoring System), OWASP Top 10, SANS/CWE Top 25, KEV (Known Exploited Vulnerabilities) and Threat intelligence-driven risk prioritization models
• Strong knowledge of attack methodologies, adversary tactics, techniques, and procedures (TTPs), and the MITRE ATT&CK Framework.
• Strong understanding operating systems Windows, Linux databases, network architectures, cloud platforms, virtualization technologies, APIs, containers, and emerging technologies.
• Strong understanding of cloud security risks and vulnerability management across AWS, Microsoft Azure, Google Cloud Platform, and SaaS environments.
• Highly experienced programming and scripting capabilities using Python, PowerShell, Bash, Ruby, or similar languages to automate assessment, reporting, and remediation processes.
• Deep understanding of technology risk management, control frameworks, and regulatory expectations applicable to banks, financial institutions, and fintech organizations.
• Demonstrated experience collaborating with financial regulators, examiners, internal audit, external audit, and independent assessors during cybersecurity examinations and reviews.
• Demonstrated experience developing defensible documentation, evidence packages, and executive-level reporting supporting regulatory and audit requirements.
• Proven ability to present vulnerability management program maturity, risk metrics, remediation strategies, compensating controls, and risk acceptance processes to regulators and executive leadership.
• Experience establishing, risk exception frameworks, service level agreements (SLAs), and key risk indicators (KRIs).
• Ability to assess emerging threats, exploit trends, and business impacts to prioritize remediation efforts based on risk.
• Exceptional verbal, written, and presentation skills with the ability to communicate technical concepts to executive management, board-level audiences, auditors, regulators, and technical teams.
• Advanced analytical, critical-thinking, and problem-solving skills with the ability to translate complex technical risks into business-focused recommendations.
Preferred
• 5 years of progressive leadership experience in information security, vulnerability management, or technology risk manager is preferred.
• 3 years of experience managing a program, enterprise-wide security initiatives within highly regulated industries or financial services preferred.
• Relevant certifications preferred, including CISSP, CISM, CRISC, GIAC, OSCP, Security+, PCI Professional (PCIP), or equivalent.
The duties listed above are the essential functions, or fundamental duties within the job classification. The essential functions of individual positions within the classification may differ. Texas Capital Bank may assign reasonably related additional duties to individual employees consistent with standard departmental policy.Texas Capital is an Equal Opportunity Employer.