This job has expired

This job posting is no longer active and is not accepting applications. Explore similar roles below!

Fifth Third Bank
Posted 1mo ago

Lead Information Security Engineer - Vulnerability Management

Fifth Third Bank
Ohio, United States
$82k-$173k/yrRemoteFull Time
Responsibilities
  • remediating vulnerabilities
  • analyzing data
  • mentoring engineers
Requirements
  • 6+ years hands-on vulnerability management experience
  • Strong security architecture and networking knowledge
  • CVE triage and remediation expertise
  • Scripting and data analysis skills
  • Bachelor\u0002s or equivalent
  • Relevant security certifications preferred
Technical tools mentioned
Power AutomatePower BIServiceNowBrinqaExcelPythonPowerShellSQL

Job description

Make banking a Fifth Third better®
We connect great people to great opportunities. Are you ready to take the next step? Discover a career in banking at Fifth Third Bank.

The Lead Information Security Engineer on the Enterprise Vulnerability Management (EVM) Remediation team will support the continuous vulnerability remediation process and reduce the Fifth Third Bank’s attack surface across infrastructure, endpoints, and applications on prem and in cloud environments.

The ideal candidate excels at deep investigative analysis into complex problems to identify risks and gaps before they can be exploited. They bring strong expertise across the full Vulnerability Management Lifecycle, including asset discovery, internal and external scanning, contextual and risk-based analysis, CVE triage, reporting, and remediation.

The position requires a solid foundation in vulnerability management, with demonstrated broad prior experience in foundational roles such as help desk, system administration, networking, SOC operations, & software engineering.

The successful candidate will play a key role in maintaining a strong security posture through close collaboration with infrastructure, development, product, and other teams across Fifth Third Bank to embed security from design through deployment and into ongoing operations.

ESSENTIAL DUTIES AND RESPONSIBILITIES:

Vulnerability Mgt – Remediation – 60%

  • Serve as the primary escalation point and subject matter expert for the most complex and high‑risk remediation issues across infrastructure, cloud, containers, applications, and code.
  • Provide advanced technical guidance on remediation paths, exploitability assessment, scanning output interpretation, and multi‑layered False Positive evaluations.
  • Stay up to date on the latest vulnerabilities, exploitation techniques, and exploits.
  • Independently own intake, investigation, escalation, and mitigation reviews for high-impact items such as critical vulnerabilities, emerging threats, and executive escalations.
  • Drive and own sophisticated remediation planning that includes dependency mapping, coordinated timelines, and long-term fixes.
  • Perform analytical reviews of large datasets to identify meaningful trends and shape targeted remediation campaigns for the highest areas of risk.
  • Conduct proactive follow-up on stalled plans and escalate appropriately when remediation does not progress.
  • Deliver expert-level communication to technical and non-technical stakeholders to ensure clarity of risk, urgency, and remediation requirements.
  • Oversee False Positive determinations, Exception requests, and Risk Acceptance submissions to ensure accuracy, thoroughness, and adherence to governance standards.
  • Partner with teams across Information Security and application teams across the Bank to ensure complex issues are addressed correctly and efficiently.

Metrics, Reporting & Dashboards – 25%

  • Report and track vulnerability metrics, KPIs, and KRIs with proactive escalations to maintain risk within acceptable appetite.
  • Create impactful presentations to deliver key metrics and data to senior leadership.
  • Conceptualize, design, and update dashboards and workflows utilizing scripting, Power Automate, PowerBI, ServiceNOW, Brinqa, and/or other tools/processes as appropriate.
  • Utilize macros, scripting, formulas, and optimizations for workflows in Excel.

Process Improvement & Documentation – 15%

  • Work within Agile framework to deliver incremental value.
  • Proactively identify opportunities for, and volunteer to, improve EVM processes and demonstrate measurable impact towards reducing inefficiencies.
  • Build and maintain standards, playbooks, and repeatable processes to improve the efficiency and maturity of the vulnerability management program
  • Mentor junior and mid‑level engineers through hands-on support, structured coaching, and direct involvement in complex cases.
  • Contribute to the evolution of the Program and contribute to additional duties and projects as appropriate.

MINIMUM KNOWLEDGE, SKILLS AND ABILITIES REQUIRED:

  • At least 6 years of related and recent hands-on experience in Vulnerability Management.
  • Strong attention to detail, and advanced understanding of security architecture, networking, operating systems, identity, and cloud services.
  •  Demonstrated experience in risk articulation, and remediation strategies across common technology stacks.
  • Demonstrated experience triaging and prioritizing complex findings from scanning tools and translating technical findings into actionable remediation guidance
  • Strong written and verbal communication skills, including the ability to communicate effectively with senior leaders and with deeply technical teams.
  • Proven analytical and problem-solving skills, including the ability to interpret large datasets and identify meaningful trends.
  • Experience collaborating across multiple teams and influencing outcomes without direct authority.
  • Bachelor’s degree in computer science/information systems or equivalent combination of education and experience.
  • Certifications such as Security+, CISSP, CISM, GIAC, or cloud certifications (AWS preferred).

PREFERRED KNOWLEDGE, SKILLS AND ABILITIES:

  • Experience supporting at least one of the following: cloud security, container security, application security, or code scanning programs.
  • Experience with threat intelligence inputs and applying exploitability context to remediation prioritization.
  • Working knowledge of scripting (for example Python, PowerShell, SQL) to support data analysis and workflow automation.
  • Experience building in, and maintaining enterprise workflow and reporting platforms such as ServiceNow, Power BI, and Power Automate.
  • Demonstrated experience in sysadmin, networking, or SOC roles.
  • Experience embedding security controls into CI/CD pipelines and DevSecOps workflows.
  • Hands-on experience implementing cybersecurity frameworks such as NIST CSF, NIST 800-53, CIS Controls, ISO 27001, and PCI DSS, including practical work aligning controls, assessing gaps, and guiding teams through remediation and compliance activities.

#LI-CB2

Please note that this position is not available for immigration sponsorship.

Lead Information Security Engineer - Vulnerability Management

Total Base Pay Range 82,100.00 - 172,500.00 USD Annual

At Fifth Third, we understand the importance of recognizing our employees for the role they play in improving the lives of our customers, communities and each other. Our Total Rewards include comprehensive benefits and differentiated compensation offerings to give each employee the opportunity to be their best every day.

The base salary for this position is reflective of the range of salary levels for all roles within this pay grade across the U.S. Individual salaries within this range will vary based on factors such as role, relevant skillset, relevant experience, education and geographic location. In addition to the base salary, this role is eligible to participate in an incentive compensation plan, with any such payment based upon company, line of business and/or individual performance.

Our extensive benefits programs are designed to support the individual needs of our employees and their families, encompassing physical, financial, emotional and social well-being. You can learn more about those programs on our 53.com Careers page at: https://www.53.com/content/fifth-third/en/careers/benefits.html or by consulting with your talent acquisition partner. 

LOCATION -- Virtual, Ohio 00000

Attention search firms and staffing agencies: do not submit unsolicited resumes for this posting.  Fifth Third does not accept resumes from any agency that does not have an active agreement with Fifth Third.  Any unsolicited resumes – no matter how they are submitted – will be considered the property of Fifth Third and Fifth Third will not be responsible for any associated fee.

Fifth Third Bank, National Association is proud to have an engaged and inclusive culture and to promote and ensure equal employment opportunity in all employment decisions regardless of race, color, gender, national origin, religion, age, disability, sexual orientation, gender identity, military status, veteran status or any other legally protected status.

About Fifth Third Bank

Provides retail, commercial, and wealth management financial services.

Similar jobs

Information Security Engineer roles in Ohio
3w
Save
Mark Applied
Hide
Lead Information Security Engineer - Cryptographic Products and Services
Irving or Columbus or Charlotte
$119k-$187k/yr HybridFull Time
Wells Fargo
Wells FargoNYSE: WFC: Global provider of banking, investment, and mortgage financial services.
5+ YOE5+ years information security engineering experience; intermediate-advanced scripting (Bash, PowerShell, Python, Ansible, VBScript, JavaScript, UI path); Linux/Windows server experience; cryptography, HSMs, automation, CI/CD, and auditing experience preferred.
Bash, PowerShell, Python, Ansible, VBScript, JavaScript, UI path, Linux, Windows, Puppet, Chef, CI/CD, Hardware Security Modules (HSMs)
1mo
Save
Mark Applied
Hide
Information Security Engineer
Cleveland or United States
$95k-$115k/yr HybridFull Time
Dealer Tire
Dealer Tire: Distributes tires and automotive parts to car dealerships and manufacturers.
3+ YOEBachelor's or equivalent 3+ years in information security, scripting with Powershell/Bash, vendor risk assessment, AI/LLM security knowledge, security monitoring, and incident response.
Powershell, Bash, OWASP Top 10 for LLM and Agentic Applications, MITRE ATLAS, NIST AI Risk Management Framework, MCP, IaaS
1mo
Save
Mark Applied
Hide
Information Security Engineer
North Carolina or Georgia or Texas or New Jersey or Pennsylvania or Illinois or District of Columbia or Maryland or Ohio or Florida or South Carolina or Colorado or Indiana or Washington or Nevada or California or Massachusetts
RemoteFull Time
Exostar
Exostar: Cloud platforms for secure collaboration in regulated industries.
7+ YOE7+ years in information security with security operations, incident response, Azure/Microsoft 365 experience, SIEM/EDR familiarity, scripting (Python/KQL/SPL), strong communication and ability to obtain Trusted Role.
EDR, AV, DLP, Tenable, Splunk, Sentinel, Defender, Proofpoint, IDS, Firewalls, SIEM, vulnerability scanners, Splunk Query Language, KQL, Python, PERL, Ruby, Bash, SQL, Azure, Microsoft 365, AAD
3mo
Save
Mark Applied
Hide
Information Security Engineer
Englewood or Boston or Los Angeles or New Kensington or Rochester or Rock Hill or Denver or Framingham or Merrimack or Kalamazoo or Cleveland
RemoteFull Time
Re:Build Manufacturing
Re:Build Manufacturing: Provides advanced engineering and US-based contract manufacturing services.
5+ YOE5+ years security experience; strong Microsoft 365 Security, Azure Sentinel; IT security governance; manufacturing/defense exposure preferred.
Microsoft 365 Security and Compliance, Azure, Microsoft Sentinel, Microsoft Purview
4mo
Save
Mark Applied
Hide
Information Security Engineer
Westfield Center, Ohio, United States
HybridFull Time
Westfield
Westfield: Provides property, casualty, and specialty insurance and surety solutions.
5+ YOE0-5 years in Information Security; Bachelor's in CS/IT or related field or equivalent experience.
Encryption Techniques, Firewall Management, Identity Management, Incident Response, Information Security, Network Security, Security Assessments, Security Engineering, Security Monitoring, Threat Intelligence, Vulnerability Management
3d
Save
Mark Applied
Hide
Information System Security Engineer
Dayton, Ohio, United States
OnsiteFull Time
University of Dayton: Catholic research university providing undergraduate and graduate higher education.
5+ YOEBachelor's degree in cybersecurity, computer science, IT, or related field; Security+ and DoD IAM II certification; 5+ years cybersecurity and 7+ years IT experience; Secret clearance eligibility and U.S. citizenship required.
eMASS, NIST RMF, Microsoft Azure, Amazon Web Services, Google Cloud, Secure Development Operations Systems, NIST SP 800-53
2w
Save
Mark Applied
Hide
Information Systems Security Engineer
Wright-Patterson Air Force Base, Ohio, United States
$99k-$225k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
7+ YOE7+ years implementing NIST RMF, TS/SCI clearance, experience with RMF artifacts and vulnerability mitigation, SEIM tools, network/device support, and interfacing with stakeholders.
Palo Alto, data transport, Cisco, Splunk, Elastic, SEIM, eMASS, AWS, Azure
2w
Save
Mark Applied
Hide
Information Systems Security Engineer
Wright Patterson AFB, Ohio, United States
$99k-$225k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
7+ YOE7+ years implementing NIST RMF, TS/SCI clearance required, DoD 8570 IAM Level II, HS diploma/GED, 3+ years ISSO/ISSM leadership, RMF artifact experience, SEIM (Splunk/Elastic), Cisco/Palo Alto experience.
NIST Risk Management Framework (RMF), Palo Alto, Cisco, Splunk, Elastic, SEIM, eMASS, AWS, Azure
This job has expired