Skip to content

Open nowPosted 8 days ago

Senior Vulnerability & Security Engineer

bbh28 open roles

Pay
$140,000 – $190,000 a year
Where
Jersey City
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Vulnerability & Security Engineerbbh · Jersey City
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on bbh's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. bbh postings stay open a median of 1 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 8 days ago

bbh median: 1 days open

The posting

At BBH, Partnership is more than a form of ownership—it’s our approach to business and relationships. We know that supporting your professional and personal goals is the best way to help our clients and advance our business. We take that responsibility seriously. With a 200-year legacy and a shared passion for what’s next, this is the right place to build a fulfilling career.

Reporting to the Head of Vulnerability Management within the Cybersecurity team, we are seeking a Senior Vulnerability & Security Engineer to lead the advancement of the organization's vulnerability management and security configuration programs.

This is a technical cybersecurity role responsible for identifying, assessing, prioritizing, and managing security exposures across the enterprise. The successful candidate will combine strong engineering expertise with risk-based analysis to evaluate vulnerabilities and security configuration weaknesses, determine their business impact, and drive effective remediation and mitigation strategies.

As a key subject matter expert, this individual will partner closely with infrastructure, cloud, application development, engineering, and security teams to improve the organization's security posture. The role requires the ability to translate complex technical findings into clear business risk insights and actionable recommendations for technical and non-technical stakeholders.

In addition, this role will be responsible for engineering and continuous enhancement of the enterprise security configuration capabilities, including the development of security baselines, compliance monitoring, automated assessment capabilities, and remediation processes. The role will ensure configuration management practices are integrated with broader vulnerability management processes to provide a holistic view of cyber risk.

Key Responsibilities

Vulnerability Assessment & Risk Analysis

  • Analyze vulnerabilities identified through enterprise vulnerability scanning, endpoint detection and response (EDR) platforms, application security testing, penetration testing, and threat intelligence sources.
  • Conduct technical analysis of CVEs, vendor advisories, and threat intelligence to assess affected technologies, exploitability, attack vectors, business impact, and available mitigation options.
  • Evaluate vulnerabilities using both technical and business context to differentiate between vulnerabilities that represent material business risk and those that can be effectively managed through compensating controls.
  • Provide risk-based recommendations to support remediation planning, exception management, and cybersecurity governance processes.

Vulnerability Remediation & Mitigation

  • Partner with infrastructure, cloud, application, platform, and engineering teams to develop effective remediation strategies.
  • Assess the effectiveness of proposed mitigations and determine whether residual risk remains acceptable.
  • Identify alternative remediation approaches when immediate patching or correction is not feasible.
  • Review, assess, and provide recommendations regarding vulnerability exceptions requests.

Vulnerability & Security Configuration Engineering

  • Design, implement, and continuously improve capabilities supporting the enterprise vulnerability and security configuration management programs.
  • Develop and maintain secure configuration baselines aligned with organizational standards and industry frameworks.
  • Engineer automated solutions to assess, monitor, measure, and report on configuration compliance across enterprise environments.
  • Integrate configuration assessment findings with vulnerability management workflows to improve risk visibility and prioritization.
  • Evaluate emerging technologies, tools, and methodologies to enhance vulnerability and configuration management capabilities.
  • Serve as the technical escalation point and subject matter expert for vulnerability and configuration management issues.
  • Provide technical leadership, mentorship, and guidance to cybersecurity team members.
  • Maintain awareness of emerging threats, vulnerabilities, exploitation techniques, and industry best practices.

Required Qualifications

  • 7+ years of cybersecurity experience, preferably within financial services or another highly regulated industry.
  • Strong technical knowledge of enterprise infrastructure, operating systems, networking, databases, applications, and cloud platforms.
  • Demonstrated experience analyzing vulnerabilities, assessing risk, and developing remediation strategies.
  • Experience engineering and operating enterprise vulnerability management and security configuration management programs.
  • Experience with vulnerability exception processes, compensating controls, risk acceptance methodologies, and remediation governance.
  • Strong understanding of cybersecurity frameworks, regulations, and industry practices, including NIST, ISO 27001, OWASP, NYDFS Part 500, DORA, CIS and STIG.
  • Experience interpreting cybersecurity control requirements and evaluating compliance with organizational standards.
  • Strong analytical, problem-solving, stakeholder management, communication, and influencing skills.
  • Ability to communicate complex technical issues effectively to both technical and business audiences.

Preferred Qualifications

  • CISSP or equivalent
  • Experience in automation and scripting (PowerShell, Python, or similar) to improve vulnerability and configuration management processes.
  • Advanced PowerPoint and Excel skills, including development of executive-level risk reporting, dashboards, metrics, and presentations.

Salary Range

MA: $140,000 - $190,000 + annual target bonus

NJ: $150,000 - $195,000 + annual target bonus

BBH and its affiliates' compensation program includes base salary, discretionary bonuses, and profit-sharing. The anticipated base salary range(s) shown above are only for the indicated location(s) and may differ in other locations due to cost of living and labor considerations. Base salaries may vary based on factors such as skill, experience and qualification for the role. BBH's total rewards package recognizes your contributions with more than just a paycheck—providing you with benefits that enhance your experience at BBH from long-term savings, healthcare, and income protection to professional development opportunities and time off, our programs support your overall well-being.

We value diverse experiences. We value diverse experiences and transferrable skillsets. If your career hasn’t followed a traditional path, includes alternative experiences, or doesn’t meet every qualification or skill listed in the job description, please do go ahead and apply.

About BBH:

Brown Brothers Harriman (BBH) is a premier global financial services firm, known for premium service, specialist expertise, technology solutions and partnership approach to client management. Across Investor Services and Capital Partners, we work with an enviable roster of sophisticated clients who make BBH their first call when they are tackling their hardest challenges. Delivering for our clients and each other energizes us.

We believe that how we do our work is just as important as what we do. We are relentless problem solvers who know our best ideas come from collective debate and development—so we are never possessive about our ideas. Every day we come together as a diverse community of smart and caring people to deliver exceptional service and expert advice—creating success that lasts. No matter where you sit in the organization, everyone is empowered to contribute their ideas. BBHers can pick up the phone and call any colleague, and they are happy to help. Expanding your impact beyond your daily role is part of how we operate as trusted partners to one another.

We believe stability is a competitive advantage, but being stable means having the knowledge, skill, and discipline to evolve, often—pushing the boundaries of innovation. As a private partnership, every investment we make is in the relationships, technologies, products and development we believe are in the long-term interests of our clients and our people. Our long-tenured leaders are experts in their areas and are actively involved in the day-to day business, taking the time to provide guidance and mentoring to build the next generation of BBHers. Because we know, our success begins with yours.

Go to BBH.com to learn more about our rewards and benefits, philanthropy, approach to sustainability or how we support you to thrive personally, physically and financially.

We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, national origin, age, genetic information, creed, marital status, sexual orientation, gender identity, disability status, protected veteran status, or any other protected status under federal, state or local law.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against bbh's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on bbh's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    bbh's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.