미주 지역의 취약점 및 구성 관리 프로그램을 총괄하며, 보안 위협 대응과 패치 전략을 수립해요. 영어로 원활한 의사소통이 가능해야 하며, 경영진에게 보안 지표를 보고하고 개선안을 제시하는 역할을 수행해요. Cyber Threat Defense 팀 소속으로 디렉터에게 보고하며, 미주 및 글로벌 유관 부서와 긴밀히 협업해야 해요. 보안 프레임워크 및 금융 규제에 대한 지식은 우대하며, 실무 경험이 필수적인 리드급 직무예요.
Banking operations processing
Permanent contract
Montreal, Quebec, Canada
Hybrid
Reference 25000Q4P
Start date Immediately
Publication date 2026/05/06
The Vulnerability Management Lead is responsible for the AMER region’s vulnerability management and configuration management program. The position requires excellent communication skills (written and verbal) and a strong ability to influence others. The ideal candidate will be able to demonstrate practical and in-depth knowledge of running an effective vulnerability & / or configuration management program including dynamically responding to emerging threats in the financial services industry.
The role also calls for strong technical analysis and process improvement skills and the ability to present to senior management on the state of, and proposals to improve, the program.
Working knowledge of cybersecurity and risk assessment frameworks (e.g., NIST) and regulations applicable to the financial services industry (e.g., NYDFS 500, FINRA, SEC) is preferred.
The Vulnerability Management Lead is a member of the Cyber Threat Defense (CTD) team within the AMER Data and Cyber Security (ISR) department and reports to the Director of CTD. This position requires strong collaboration across GBSU and GTS departments in the Americas and globally with SG CERT, ISR and GTS teams.
ESSENTIAL JOB FUNCTIONS
Vulnerability & Configuration Management
Lead the AMER vulnerability & configuration management programs – Act as the main point of contact and expert in Vulnerability Management and configuration management; including overseeing the risk of zero-day vulnerabilities, oversee patching/remediation and risk acceptance of vulnerabilities where appropriate.
Oversee the discovery, evaluation, and implementation of vulnerability scanning, patch and configuration review, penetration testing.
Present operating and steering committees for projects to senior management on a quarterly basis.
Develop and oversee annual roadmaps of initiatives to align with overall InfoSec and business objectives/strategy.
Develop and manage detailed vulnerability reviews and assessments, and patching and configuration reviews: (1) Assess potential damage of security flaws and assist in the implementation of corrective actions; (2) Identify, document, and report security issues and concerns to management; and (3) Monitor corrective actions and recommending cost-effective preventive measures to preclude recurrences.
Review and sign-off on all recommendations on possible improvements resulting from the work performed as part of projects.
Draft and publish communications for management as new threats emerge.
Improve the reporting framework that will provide regular metrics and statistics about our business and IT environment; analyze trends in security events, activities, etc. to better understand risks, insufficiencies in our solutions, staffing shortages, etc.; report security metrics and statistics to the CISO and other key stakeholders such as the COO, CIO, and CTO.
Ability to communicate in English, both orally and in writing, is a requirement as the person in this position will need to collaborate regularly with colleagues and partners in the United States.
Competitive compensation & benefits offering, including but not limited to:
Fully sponsored virtual healthcare assistance and Employee Assistance Program to you and your immediate family Various Employee Resource Groups (ERG) to engage with such as Pride and Allies, American Women Network, Black Leadership Network, One planet, etc.
Societe Generale is committed to offering an inclusive recruitment experience to all candidates. If you require any reasonable accommodations during the recruitment process, please do not hesitate to let our Recruiters know.
At Societe Generale, we live by our 4 core values of commitment, responsibility, team spirit and innovation. We are engaged and demonstrate consideration for others. We act ethically and with courage. We focus our talent and energy on collective success. We experiment and propose new ideas. This way, we maximize our ability to serve client needs and anticipate market changes. Societe Generale is committed to strengthening bonds with colleagues, communities, and the world in which we live, because relationships are at the heart of how we operate. For more information about our Culture and Conduct initiatives, please visit this link (https://americas.societegenerale.com/en/careers/get-know-culture/)
Our Diversity & Inclusion Mission: Recruit, develop, advance, and retain a diverse workforce that is united in our efforts to enhance our competitive position and deliver innovative solutions to our clients. Our Diversity & Inclusion Vision:
For more information about our D&I initiatives, please visit this link
Societe Generale is an equal opportunity employer and we are proud to make diversity a strength for our company. We are committed to recognizing and promoting the talents and achievements of our employees and staff, regardless of race, religion, color, national origin, sex, disability, age, gender, sexual orientation, and any other characteristic or status protected under applicable law. We strive to write our postings as inclusively as possible. If, however, one gender is used alone in this display, it designates persons of all gender identities.
Share
Information Security Officer
Permanent contract
Montreal, Quebec, Canada
Hybrid
Responsibilities Profile required Why join us Business insight Diversity and Inclusion
Titre
Similar jobs
Titre
Jobs & contracts