Skip to main contentA logo with &quat;the muse&quat; in dark blue text.

Director, Vulnerability Management & Cloud Monitoring

AT Prudential Financial
Prudential Financial

Director, Vulnerability Management & Cloud Monitoring

Newark, NJ

Job Classification:
Technology - Information Security

Are you interested in building capabilities that enable the organization with innovation, speed, agility, scalability and efficiency? The Global Technology team takes great pride in our culture where digital transformation is built into our DNA! When you join our organization at Prudential, you'll unlock an exciting and impactful career - all while growing your skills and advancing your profession at one of the world's leading financial services institutions.

Your Team & Role

As a Director, Vulnerability Management & Cloud Continuous Monitoring on the Attack Surface Management Team, you will partner with other security professionals across the Information Security Office, the Chief Technology Office, and other groups in Prudential to lead Prudential's Vulnerability Management and Cloud security efforts across the global enterprise.

Want more jobs like this?

Get Management jobs in Newark, NJ delivered to your inbox every week.

By signing up, you agree to our Terms of Service & Privacy Policy.


You will lead the programs to detect and respond to vulnerabilities across the multiple technology stacks (infrastructure, network, open source, 3rd party software, endpoints, cloud, container). You will partner with Application Security and Configuration Compliance leaders to identify "secure by design" opportunities to enhance baseline capabilities and establish preventive controls. In addition, you will continuously evolve and grow the strategic direction of the program and contribute to security standards, enablement of new capabilities (container vulnerability management, SBOM implementation, endpoint vulnerability management, serverless computing) and identification of attack surface reduction opportunities.

You will work on significant and unique issues where analysis of context-based risk, unique business environments or vulnerability exploitability requires an evaluation of variables to drive time-sensitive risk reduction efforts. In your efforts, you will continuously look at opportunities to automate and strengthen controls.

In addition to your deep domain experience, you will bring excellent engineering, problem solving, collaboration and stakeholder management skills in developing capabilities. An agile and continuous improvement/learning mindset is needed to mature the team and transform the function.

Here is What You Can Expect on a Typical Day Primary leader for all vulnerability management initiatives, including but not limited to:

  • Management of requirements for scanning policies, coverage and lifecycle management processes for vulnerabilities and misconfigurations (Qualys, Wiz). This includes configuration-based assessments where automated detections are not available.
  • Responsible for assuring completeness of external scanning environments, the assessments related to DMZ processes and approvals.
  • Identification and monitoring of high-risk software, services and ports.
  • Responsible for continuously monitoring threat intelligence and industry sources (NVD, EPSS, CISA, core vendors) for emerging risk and proactive response.
  • Responsible for continuous monitoring of attack surface and ensuring remediation governance via escalation to business and risk advisors.
  • Development and oversight for vulnerability management related tools, configuration policies, documentation and standard operating procedures and processes to ensure consistency in vulnerability management operations.
  • Oversee the development of automation workflows in collaboration with the ASM Orchestration team.
  • Own and manage the emergent vulnerability response playbook and risk assessment and triage processes.
  • Partner with CTO organization to establish security standards, design requirements and build the roadmap to implement cloud security controls to ensure the secure deployment of cloud-based resources.
  • Operationalize new processes for cloud and container continuous monitoring.
  • Manage KRIs to monitor the risk and health of the VM program.
  • Provide mentorship, training, and guidance for team members, including periodic reviews and individual development plans.
  • Support managers and Prudential leadership on new initiatives and opportunities to grow our security practices.
  • Ensures proper communication of the program's results, opportunities, and deficiencies, as needed, to Prudential upper management.
  • Align findings for a centralized reporting capability for the enterprise.
  • Perform security assessments and other duties as assigned.
  • Manage the day-to-day Operations teamwork, while guiding and transferring knowledge to more junior team members. Guides teams through project work, team goals, and align resources to meet deadlines.
  • Function as the escalation point for all Security Operations daily operational work as well as project work from more junior staff on the team
  • Leverage Security Operations and tool/process specific knowledge to resolve complex technical/process/people problems the team faces.
  • Leverage organizational and industry knowledge to bridge gaps between the Security Operations teams and internal IT/business teams to ensure the team has the information and resources they need to meet team goals.
  • Partner with leadership to set direction for the future of the VM and Cloud Security monitoring program, while ensuring an accurate understanding and in-depth knowledge of daily operations to provide team recommendations.
  • Bring a deep understanding of relevant and emerging technologies, give technical direction to team members, and embed learning and innovation in the day-to-day Maintain a broad knowledge of innovative security principles and theory.
  • Tracking, rating and ranking of highly critical vulnerabilities along with all coordination with business unit owners to ensure required adherence to SLAs.
  • Responsible for review and approval of remediation deferment requests, escalation where appropriate

The Skills & Expertise You Bring

  • Bachelor of Computer Science or Engineering or experience in related fields
  • Demonstrated leadership and effectively leverage diverse ideas, experiences, thoughts and perspectives to the benefit of the organization.
  • Knowledge of security concepts tools and processes that are needed for making sound decisions and assessment of risk in the context of the company's business.
  • Continually advance skills and knowledge on an on-going basis through self-initiative and tackling challenges and act as a mentor for the team to upskill.
  • Excellent problem solving, communication and collaboration skills.

Significant experience and/or deep expertise with several of the following:

  • Hands on experience with VM tools and tools used to determine risk and triage response activities.
  • Advanced experience in the Information Security industry
  • Experience using industry-standard vulnerability scanning and security tools (Qualys, Tenable, Wiz, NMAP, Cloud Native - AWS, Azure)
  • Experience with standard frameworks, such as OWASP, MITRE ATT&CK, and NIST.
  • In-Depth knowledge of threat intelligence frameworks & methodology that will help aid the response process.
  • Proficient in scripting languages such as Python, PowerShell
  • Familiarity with defensive and monitoring technologies such intrusion prevention/detection systems (IPS/IDS), Web Application Firewalls (WAFs) security information and event management systems (SIEMs), firewalls, endpoint protection (EPP) and endpoint detection/response (EDR) tools, as well as user and entity behavior analytics (UEBA).

Preferred qualifications:

  • CISSP
  • Cloud (AWS, Azure, GCP, etc.) Certs
  • Other Security Certifications beyond intro level

You'll Love Working Here Because You Can

Join a team and culture where your voice matters; where every day, your work transforms our experiences to make lives better. As you put your skills to use, we'll help you make an even bigger impact with learning experiences that can grow your technical AND leadership capabilities. You'll be surprised by what this rock-solid organization has in store for you.

What we offer you:

  • Market competitive base salaries, with a yearly bonus potential at every level
  • Medical, dental, vision, life insurance, disability insurance, Paid Time Off (PTO), and leave of absences, such as parental and military leave
  • Retirement plans:
  • 401(k) plan with company match (up to 4%)
  • Company-funded pension plan
  • Wellness Programs to help you achieve your wellbeing goals, including up to $1,600 a year for reimbursement of items purchased to support personal wellbeing needs
  • Work/Life Resources to help support topics such as parenting, housing, senior care, finances, pets, legal matters, education, emotional and mental health, and career development.
  • Tuition Assistance to help finance traditional college enrollment toward obtaining an approved degree, many accredited certificate programs, and industry designations.
  • Employee Stock Purchase Plan: Shares can be purchased at 85% of the lower of two prices (Beginning or End of the purchase period), after one year of service.

To find out more about our Total Reward package, see our Total Rewards Brochure. Some of the above benefits may not apply to part-time employees scheduled to work less than 20 hours per week.

Note: Prudential is required by state specific laws to include the salary range for this role when hiring a resident in applicable locations. The salary range for this role is from $160,700.00 to $217,300.00. Specific pricing for the role may vary within the above range based on many factors including geographic location, candidate experience, and skills. Roles may also be eligible for additional compensation and/or benefits. Eligibility to participate in a discretionary annual incentive program is subject to the rules governing the program, whereby an award, if any, depends on various factors including, without limitation, individual and organizational performance. In addition, employees are eligible for standard benefits package including paid time off, medical, dental and retirement.

Prudential Financial, Inc. of the United States is not affiliated with Prudential plc. which is headquartered in the United Kingdom.

Prudential is a multinational financial services leader with operations in the United States, Asia, Europe, and Latin America. Leveraging its heritage of life insurance and asset management expertise, Prudential is focused on helping individual and institutional customers grow and protect their wealth. The company's well-known Rock symbol is an icon of strength, stability, expertise and innovation that has stood the test of time. Prudential's businesses offer a variety of products and services, including life insurance, annuities, retirement-related services, mutual funds, asset management, and real estate services.

We recognize that our strength and success are directly linked to the quality and skills of our diverse associates. We are proud to be a place where talented people who want to make a difference can grow as professionals, leaders, and as individuals. Visit www.prudential.com to learn more about our values, our history and our brand.

Prudential is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, ancestry, sex, sexual orientation, gender identity, national origin, genetics, disability, marital status, age, veteran status, domestic partner status , medical condition or any other characteristic protected by law.

The Prudential Insurance Company of America, Newark, NJ and its affiliates.

Note that this posting is intended for individual applicants. Search firms or agencies should email Staffing at staffingagencies@prudential.com for more information about doing business with Prudential.

PEOPLE WITH DISABILITIES:
If you need an accommodation to complete the application process, which may include an assessment, please email accommodations.hw@prudential.com.

Please note that the above email is solely for individuals with disabilities requesting an accommodation. If you are experiencing a technical issue with your application or an assessment, please email careers.technicalsupport@prudential.com to request assistance.

Client-provided location(s): Newark, NJ, USA
Job ID: Prudential-R-118147
Employment Type: Full Time

Perks and Benefits

  • Health and Wellness

    • Dental Insurance
    • Vision Insurance
    • Life Insurance
    • Short-Term Disability
    • Long-Term Disability
    • FSA
    • FSA With Employer Contribution
    • HSA
    • HSA With Employer Contribution
    • Health Insurance
  • Parental Benefits

    • Adoption Leave
    • Birth Parent or Maternity Leave
    • Adoption Assistance Program
    • Family Support Resources
  • Vacation and Time Off

    • Paid Holidays
    • Personal/Sick Days
  • Financial and Retirement

    • 401(K)
    • 401(K) With Company Matching
    • Pension
    • Stock Purchase Program