> Markdown version of [/jobs/ext/2869475-cyber-security-vulnerability-manager](https://www.wearedevelopers.com/jobs/ext/2869475-cyber-security-vulnerability-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Vulnerability Manager - **Company:** Texas Capital Bank - **Location:** Richardson, TX, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Bash Shell, Software as a Service, Cloud Computing, Cloud Computing Security, Cloud Engineering, CompTIA Security+, Cyber Security, Databases, Linux, Python (Programming Language), Network Architecture, Open Web Application Security, Windows PowerShell, Ruby, Systems Integration, Strategies of Testing, Virtualization Technology, Software Vulnerability Management, Google Cloud, Cloud Platform System, Mitre Att&ck, Cyber Threat Analysis, Information Technology, Vulnerability Analysis - **Published:** September 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=b7b21de32bc88148 ## About the Role * Bachelor's degree in Information Security, Information Technology, Computer Science, Engineering, or related field. * Minimum 10 years of experience in an appropriate domain. * Strong expertise in enterprise Vulnerability Management programs, including network-based, agent-based, cloud-native, application, container, and infrastructure vulnerability assessment technologies. * Experience integrating vulnerability management practices into enterprise governance, risk management, and compliance (GRC), and operational risk programs. * Deep understanding of vulnerability scoring methodologies and frameworks, including but not limited to: CVSS, EPSS (Exploit Prediction Scoring System), OWASP Top 10, SANS/CWE Top 25, KEV (Known Exploited Vulnerabilities) and Threat intelligence-driven risk prioritization models * Strong knowledge of attack methodologies, adversary tactics, techniques, and procedures (TTPs), and the MITRE ATT&CK Framework. * Strong understanding operating systems Windows, Linux databases, network architectures, cloud platforms, virtualization technologies, APIs, containers, and emerging technologies. * Strong understanding of cloud security risks and vulnerability management across AWS, Microsoft Azure, Google Cloud Platform, and SaaS environments. * Highly experienced programming and scripting capabilities using Python, PowerShell, Bash, Ruby, or similar languages to automate assessment, reporting, and remediation processes. * Deep understanding of technology risk management, control frameworks, and regulatory expectations applicable to banks, financial institutions, and fintech organizations. * Demonstrated experience collaborating with financial regulators, examiners, internal audit, external audit, and independent assessors during cybersecurity examinations and reviews. * Demonstrated experience developing defensible documentation, evidence packages, and executive-level reporting supporting regulatory and audit requirements. * Proven ability to present vulnerability management program maturity, risk metrics, remediation strategies, compensating controls, and risk acceptance processes to regulators and executive leadership. * Experience establishing, risk exception frameworks, service level agreements (SLAs), and key risk indicators (KRIs). * Ability to assess emerging threats, exploit trends, and business impacts to prioritize remediation efforts based on risk. * Exceptional verbal, written, and presentation skills with the ability to communicate technical concepts to executive management, board-level audiences, auditors, regulators, and technical teams. * Advanced analytical, critical-thinking, and problem-solving skills with the ability to translate complex technical risks into business-focused recommendations. Preferred * 5 years of progressive leadership experience in information security, vulnerability management, or technology risk manager is preferred. * 3 years of experience managing a program, enterprise-wide security initiatives within highly regulated industries or financial services preferred. * Relevant certifications preferred, including CISSP, CISM, CRISC, GIAC, OSCP, Security+, PCI Professional (PCIP), or equivalent. ## Description * Lead the identification, assessment, prioritization, and management of vulnerabilities across on-premises and cloud-based infrastructure, networks, applications, databases, and technology platforms * Proactively identify security weaknesses and reduce organizational risk. * Collaborate with cross-functional technology, infrastructure, cloud, and application teams to remediate vulnerabilities and configuration weaknesses, ensuring timely risk reduction and compliance with established remediation requirements. * Analyze findings and provide detailed reports daily, weekly and monthly with actionable recommendations for improving security posture * Stay updated on the latest cybersecurity threats, trends, and technologies to ensure cutting-edge testing strategies * Assist in developing security ## Related Videos - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Coroutine explained yet again 60 years later](https://www.wearedevelopers.com/videos/690-coroutine-explained-yet-again-60-years-later) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)