Manager, Cyber Exposure Management
Hoover, AL - USA
Job Summary
Thank you for your interest in a career at Regions. At Regions we believe associates deserve more than just a job. We believe in offering performance-driven individuals a place where they can build a career --- a place to expect more opportunities. If you are focused on results dedicated to quality strength and integrity and possess the drive to succeed then we are your employer of choice.
Regions is dedicated to taking appropriate steps to safeguard and protect private and personally identifiable information you submit. The information that you submit will be collected and reviewed by associates consultants and vendors of Regions in order to evaluate your qualifications and experience for job opportunities and will not be used for marketing purposes sold or shared outside of Regions unless required by law. Such information will be stored in accordance with regulatory requirements and in conjunction with Regions Retention Schedule for a minimum of three years. You may review modify or update your information by visiting and logging into the careers section of the system.
At Regions the Cyber Security Manager is responsible for leading a diverse team of engineers and analysts charged with the daily operations of enforcing monitoring and managing cyber security controls to protect the assets of the bank customers and associates. This role monitors the domains of security controls including but not limited to malware defense network security Internet security security analytics threat intelligence and defense cybercrime data protection vulnerability management and customer authentication.
Primary Responsibilities
- Develops cyber security architecture/designs controls processes standards and strategies to ensure alignment with Information Security standards emerging threats and overall Information Security strategy
- Develops and implements incident response protocols for ongoing threats and attacks
- Communicates status of current threat environment incidents and projected threats to senior management and executives
- Manages the evaluation and testing of hardware firmware and software for possible impact on systems security
- Coordinates with other managers to integrate Information Security project components with other projects including application development network server and mainframe
- Partners across Technology Operations Digital and Data (TODD) to ensure controls are designed implemented and monitored to strengthen risk management compliance and cyber security effectively mitigating risk to levels within the companys risk appetite
- Ensures disciplined change management by evaluating risk and control impacts when designing or implementing changes to processes systems products and/or services
This position is exempt from timekeeping requirements under the Fair Labor Standards Act and is not eligible for overtime pay.
This position is incentive eligible.
Requirements
- Bachelors degree in a related field and six (6) years of related experience
- Or High School Diploma or GED and ten (10) years of related experience
Preferences
- Two (2) years of lead or supervisory/managerial experience
- Experience managing Information Technology and/or Information Security projects
- Experience with security operations and incident response/handling
Skills and Competencies
- Ability to prioritize assignments while working on multiple projects
- Demonstrated ability to effectively engage project teams and leadership within a corporate setting
- Excellent writing and oral communication skills
- Strong ability to predict and plan for unknown threats
- Strong ability to work well with others and place a premium on the groups success
- Strong technical aptitude skills
- Understanding of and ability to interpret applicable rules regulations and industry guidance
Additional Responsibilities & Preferred Qualifications:
- Lead the Exposure Management strategy including Continuous Threat Exposure Management (CTEM) and risk-based prioritization of remediation activities.
- Build an in-house portal to enable technology owners to understand their own individual exposures and understand prioritization requirements.
- Drive automation initiatives to improve vulnerability identification prioritization tracking and reporting efficiencies.
- Providing strategic oversight of attack surface management threat exposure analysis and trigger risk remediation initiatives.
- Integrate threat intelligence and adversary tactics techniques and procedures (TTPs) into exposure prioritization and remediation strategies.
- Develop and implement risk-based methodologies to identify assess prioritize and mitigate cyber exposures across on-premises cloud and hybrid environments.
- Manage exposure management escalations ensuring critical vulnerabilities and high-risk findings are addressed within defined service-level objectives.
- Partner with IT Security Operations Infrastructure Application Development and business stakeholders to drive remediation efforts and reduce organizational risk.
- Hire build mentor and lead a high-performing security team while managing vendor relationships and security technology investments.
Position Type
Full timeCompensation Details
Pay ranges are job specific and are provided as a point-of-market reference for compensation decisions. Other factors which directly impact pay for individual associates include: experience skills knowledge contribution job location and most importantly performance in the job role. As these factors vary by individuals pay will also vary among individual associates within the same job.
The target information listed below is based on the Metropolitan Statistical Area Market Range for where the position is located and level of the position.
Job Range Target:
Minimum:
$140670.75 USDMedian:
$184390.00 USDIncentive Pay Plans:
This role is eligible to participate in the annual discretionary incentive plan. Employees are eligible to receive a discretionary award based on individual business and/or company to participate in the Long Term Incentive Plan.Benefits Information
Regions offers a benefits package that is flexible comprehensive and recognizes that one size does not fit all for benefits-eligible associates. Listed below is a synopsis of the benefits offered by Regions for informational purposes which is not intended to be a complete summary of plan terms and conditions.
Paid Vacation/Sick Time
401K with Company Match
Medical Dental and Vision Benefits
Disability Benefits
Health Savings Account
Flexible Spending Account
Life Insurance
Parental Leave
Employee Assistance Program
Associate Volunteer Program
Please note benefits and plans may be changed amended or terminated with respect to all or any class of associate at any time. To learn more about Regions benefits please click or copy the link below to your browser.
Required Experience:
Manager
About Company
Need a commercial lending partner for affordable housing projects? Call our Real Estate Banking team for help with construction loans and equity financing.