×
Register Here to Apply for Jobs or Post Jobs. X

Threat & Exposure Management Lead

Job in 411001, Pune, Maharashtra, India
Listing for: Mizuho
Full Time position
Listed on 2026-09-03
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Security Management & Operations
Job Description & How to Apply Below
Why Mizuho

At Mizuho, we provide the stability of an international industry leader with the career trajectory of a growing business. Our steady, strategic growth gives our people at all levels rewarding degrees of responsibility and richer work experience than a boutique firm or an established giant could offer alone

It’s the local expertise of our employees that makes our global network so powerful. By collaborating with colleagues and clients who have the same ambition and drive, you can amplify your sphere of influence and base of knowledge as part of one of the largest and growing banks in the world.

Role Overview :

Mizuho EMEA is building a strategic cybersecurity capability hub in Pune and expanding its Threat & Exposure Management capability to proactively identify, assess, prioritize, and reduce cyber risk across infrastructure, cloud platforms, applications, containers, APIs, and third-party technologies.

The Threat & Exposure Management Lead will be responsible for leading the enterprise vulnerability management program, driving threat-informed risk prioritization, attack surface visibility, remediation governance, and cyber risk reporting. The role will partner closely with Infrastructure, Cloud, Application Development, Dev Sec Ops , Security Operations, Architecture, and Risk teams to strengthen the organization's overall security posture and reduce enterprise cyber risk.

Key Responsibilities:

Threat & Exposure Management
Lead the enterprise Threat & Exposure Management program across infrastructure, cloud platforms, applications, containers, APIs, and third-party technologies.
Establish and mature vulnerability management standards, governance processes, remediation workflows, reporting, and operating procedures.
Drive risk-based prioritization using exploitability, threat intelligence, exposure, business criticality, and cyber risk.
Oversee External Attack Surface Management activities to identify exposed assets, security weaknesses, and emerging threats.
Govern remediation activities, SLA adherence, validation testing, exception management, and risk acceptance processes.
Deliver meaningful cyber risk reporting, executive metrics, and vulnerability reduction outcomes.
Establish common vulnerability management processes, reporting standards, and governance frameworks that support consistency across global regions.

Threat Intelligence & Risk Prioritization
Integrate threat intelligence, active exploitation trends, ransomware activity, and known exploited vulnerabilities into remediation priorities.
Lead rapid risk assessments for critical vulnerabilities, zero-day threats, and major security advisories.
Translate technical findings into actionable business risk insights that support leadership decision-making.

Security Testing & Exposure Reduction
Oversee application security testing, API security assessments, software composition analysis, and software supply chain security risk management.
Partner with engineering and Dev Sec Ops  teams to identify and reduce cloud, container, and application security exposures.
Coordinate penetration testing, Breach & Attack Simulation (BAS), Red Team, and Purple Team engagements to validate control effectiveness and remediation outcomes.
Ensure security findings are prioritized, tracked, validated, and remediated through established governance processes.
Support secure configuration and hardening initiatives aligned with CIS Benchmarks and industry security standards.

Leadership & Governance
Lead and develop a high-performing Threat & Exposure Management team.
Partner with Infrastructure, Cloud, Security Operations, Architecture, Dev Sec Ops , and Risk teams to reduce cyber risk.
Support audit, regulatory, compliance, and control assurance activities.
Present cyber risk, vulnerability posture, exposure trends, and remediation performance to senior management and governance forums.

Required Skills & Technical Expertise
Threat & Exposure Management
Vulnerability Management
Attack Surface Management
Threat Intelligence Integration
Risk-Based Prioritization & Remediation Governance
Security Metrics, Reporting & Executive Communication
Application Security & API Security
Cloud & Container Security
Software Supply Chain Security
Security Validation, BAS & Penetration Testing
Secure Configuration & CIS Benchmark Practices
Leadership, Stakeholder Management & Team Development

Essential Experience &

Qualifications:

12+ years of cybersecurity experience within enterprise or regulated environments.
5+ years leading Vulnerability Management, Threat Management, Exposure Management, Security Operations, Cyber Risk, Dev Sec Ops , or related security functions.
Proven experience managing enterprise-scale vulnerability, exposure management, and remediation programs.
Strong understanding of infrastructure, cloud, application, container, and software supply chain risk.
Experience developing governance frameworks, executive reporting, and cyber risk metrics.
Ability to translate technical findings into business risk and…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary