Insight Global logo

Exposure Management Lead (Vulnerabilities)

Insight Global

Cincinnati, OHContractSeen 1 day agoSeen in employer's feed 1 day ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
No compensation found
Location
Cincinnati, OH
Schedule
Contract
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

The employer seeks an on‑site Exposure Management Lead for a contract role at a large bank in Cincinnati, Ohio, responsible for coordinating urgent cybersecurity exposure events, assessing enterprise exposure, tracking remediation, and ensuring thorough documentation and resolution.

Skills & qualifications

RequiredNice to have

Skills

CybersecurityVulnerability ManagementSecurity OperationsIncident Response CoordinationTechnology RiskCloud SecurityThreat IntelligenceEnterprise Security ToolsTicketing PlatformsFinance/Banking Regulated Industry KnowledgeSecurity+CySA+CISSPCISMGCIHOrganizational SkillsFacilitation SkillsCommunication SkillsAbility to Operate in Fast‑Paced Situations

Qualifications

5-10+ Years Cybersecurity Experience

Full job description

Job Description

An employer is looking for an Exposure Management Lead for an on-site, contract opportunity in the Cincinnati, Ohio area.

The client is a large bank and the Lead, Exposure Management serves as an operational coordinator for urgent cybersecurity exposure events. This role is responsible for leading day-to-day response activities, assessing enterprise exposure, coordinating stakeholders, tracking remediation progress, and driving issues to resolution.

The Lead is expected to independently manage active exposure events while partnering closely with the Principal to ensure timely assessment, communication, escalation, and closure. This role work closely with other Leads to provide continuity, backup coverage, and support for simultaneous events.

Success is measured by the ability to coordinate exposure events efficiently, maintain accurate situational awareness, drive timely remediation activities, communicate effectively with stakeholders, and ensure events are resolved with clear accountability and documentation.

Key Responsibilities:

Exposure Response Coordination

  • Lead coordination of active exposure events from initial intake through closure.

  • Assess enterprise exposure and coordinate validation activities across technology teams.

  • Facilitate response meetings and working sessions.

  • Drive timely engagement of stakeholders, subject matter experts, and decision makers.

  • Ensure response activities remain organized, documented, and focused on risk reduction. Remediation & Mitigation Tracking

  • Track remediation and mitigation activities across multiple teams.

  • Maintain ownership assignments, target dates, action items, and status updates.

  • Identify and escalate blockers, dependencies, and unresolved issues.

  • Verify that remediation activities are completed and appropriately documented.

  • Support transition of open issues to longer-term governance processes when necessary. Documentation & Reporting

  • Maintain the authoritative record for active response activities.

  • Document decisions, timelines, exposure assessments, status updates, and closure evidence.

  • Prepare concise updates for leadership and stakeholders.

  • Ensure response documentation supports audit, regulatory, and governance requirements. Escalation & Handoff Management

  • Identify situations requiring escalation to leadership, Incident Response, Risk Management, or other stakeholders.

  • Support structured handoffs between teams and processes.

  • Ensure continuity of ownership and accountability throughout the response lifecycle. Continuous Improvement

  • Participate in post-event reviews and lessons-learned sessions.

  • Identify opportunities to improve coordination, communication, and response effectiveness.

  • Contribute to updates of playbooks, procedures, templates, and response standards.

Skills and Requirements

  • 5-10+ years’ experience in cybersecurity, vulnerability management, security operations, incident response coordination, technology risk, or related fields.
  • Strong experience in vulnerability management: understanding what emerging vulnerabilities are applicable, validating if they’re relevant for the company, understanding exposure/impact, working with platform owners and teams on remediation and response efforts
  • Strong organizational, facilitation, and communication skills.
  • Ability to operate effectively in fast-paced, high-visibility situations.
  • Experience tracking issues, managing action plans, and driving accountability.
  • Experience supporting vulnerability response, zero-day response, cloud security, or threat intelligence activities.
  • Familiarity with enterprise security tools, ticketing platforms, and technology operations.
  • Experience working within Finance/Banking or another regulated industry environment.
  • Security certifications such as Security+, CySA+, CISSP, CISM, GCIH, or equivalent.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal employment opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment without regard to race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to [email protected].

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.