AVP Vulnerability Management Program Manager
Listed on 2026-09-15
-
IT/Tech
-
Management
Address
We’re always looking for bright individuals to join our growing organization. As a part of the First Financial Family, we will invest in your development and provide a dynamic work environment where you’re challenged, valued and empowered every day. We strive to be the best destination for the industry’s top talent, creating a diverse, collaborative workplace that celebrates innovation and change.
We are one team, working together to get things done.
Office
Location:
Abilene, Texas, United States
The Assistant Vice President, Vulnerability Management Program Manager leads the ongoing administration, governance, and continuous improvement of First Financial Bank shares' enterprise Vulnerability Management Program. This role ensures vulnerabilities are identified, prioritized, tracked, remediated, validated, reported, and evidenced in accordance with approved standards, risk management expectations, and applicable regulatory requirements. The position provides dedicated program leadership across Information Security, technology operations, application teams, risk management, Internal Audit, third-party providers, and other stakeholders.
The role translates technical exposure into clear business risk, drives remediation accountability, coordinates governance and reporting, and helps maintain a sustainable and demonstrably effective program.
- Lead the day-to-day administration and ongoing maturity of the enterprise Vulnerability Management Program.
- Maintain the program roadmap, governance documentation, operating procedures, standards alignment, and recurring review activities.
- Coordinate the Vulnerability Management Council, including agendas, decisions, action items, escalations, and follow-through.
- Promote consistent execution of program requirements across technology functions, support organizations, and applicable business units.
- Oversee the vulnerability lifecycle from identification and validation through prioritization, remediation, exception management, risk acceptance, and closure.
- Ensure prioritization considers exploitability, asset criticality, business impact, exposure, and other approved risk factors.
- Monitor aging, overdue items, recurring issues, and material exposure; coordinate timely escalation and corrective action.
- Provide oversight of vulnerabilities affecting internally managed, jointly managed, and vendor-managed technology environments.
- Coordinate remediation activity across infrastructure, endpoints, networks, applications, databases, cloud services, and third-party technology providers.
- Partner with accountable technology owners to establish remediation plans, remove execution barriers, and confirm sustainable closure.
- Oversee dedicated vulnerability remediation resources and coordinate supplemental partner support as appropriate.
- Validate that closure and exception records contain sufficient evidence to demonstrate appropriate disposition.
- Produce and maintain recurring program reporting for management and established governance bodies, including performance, risk, trend, maturity, and enhancement information.
- Monitor approved service levels, key performance indicators, key risk indicators, backlog, aging, exceptions, and remediation outcomes.
- Present program status and material issues in clear business terms to executive management, risk committees, Internal Audit, and other stakeholders.
- Maintain consistent definitions, methodologies, and supporting evidence for reported measures.
- Coordinate vulnerability management evidence for…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).