At a Glance
- Tasks: Lead vulnerability management and incident response in a dynamic tech environment.
- Company: Join PJT Partners, a global advisory-focused investment bank with a collaborative culture.
- Benefits: Competitive salary, inclusive workplace, and opportunities for professional growth.
- Other info: Be part of a diverse team that values different perspectives and fosters innovation.
- Why this job: Make a real impact on cybersecurity while working with cutting-edge technology.
- Qualifications: 7-10 years in information security with hands-on vulnerability management experience.
The predicted salary is between 100000 - 150000 € per year.
PJT Partners is a global advisory-focused investment bank. Our team of senior professionals delivers a wide array of strategic advisory, shareholder advisory, restructuring and special situations and private fund advisory and placement services to corporations, financial sponsors, institutional investors and governments around the world. We offer a unique portfolio of advisory services designed to help our clients achieve their strategic objectives.
The Technology department at PJT is responsible for creating and continuously improving a robust and secure technology foundation that supports the firm’s business activities. Underpinning that, the Cybersecurity function ensures that the firm accurately identifies, investigates, and remediates incidents and evaluates applicable controls related to the firm’s technology. As the technology landscape at PJT is undergoing significant change, the Cybersecurity function is also evolving to help enable that change.
We are seeking an experienced, hands-on Cybersecurity Professional to own and drive the firm’s vulnerability management and patching program. This is an execution-focused role — the ideal candidate will be equally comfortable building strategy and rolling up their sleeves to conduct scans, validate remediations, coordinate fixes directly with engineering and infrastructure teams, and provide reporting and metrics on remedial actions and SLA-adherence.
In addition to vulnerability management, this individual will serve as a critical incident response resource, providing coverage during hours when the primary SOC team may not be available. This includes triaging and responding to critical-severity incidents, escalating appropriately, and ensuring continuity of response without gaps.
The candidate should bring a solutions-oriented, investigative mindset, comfort in a fast-paced environment, and the ability to build strong relationships across Technology and relevant business functions.
Responsibilities- Conduct regular vulnerability assessments of all systems, applications, and infrastructure.
- Execute vulnerability scans using tools such as Nessus, Qualys, or Rapid7; perform or coordinate penetration testing and security assessments.
- Analyze vulnerability data and issue actionable remediation, mitigation, or risk-acceptance recommendations calibrated to the firm’s risk profile.
- Drive remediation directly with engineering, infrastructure, and application teams — tracking findings from discovery through to validated closure.
- Validate all remediations to confirm findings are fully resolved.
- Develop and maintain meaningful vulnerability metrics and dashboards for senior leadership, incorporating risk-based scoring, SLA adherence, and trend analysis.
- Work with cross-functional teams to embed vulnerability management considerations into the design, development, and testing of new systems and applications.
- Coordinate with external vendors and partners to optimize detection quality, validate findings, and improve remediation workflows.
- Develop and maintain security policies, procedures, and standards aligned to industry best practices (NIST, CIS, ISO) and PJT policy requirements.
- Support audit evidence collection and manage remediation timelines for compliance-related findings.
- Communicate security risks and program status to management and stakeholders; provide clear, prioritized recommendations.
- Understand and effectively balance risk versus business operability in all remediation decisions.
- Provide leadership and mentorship to junior security team members; manage and direct external teams as needed.
- Support and maintain the vulnerability management platform infrastructure, including scanner and agent configuration, and integration with downstream ticketing and reporting systems.
- In support of the overall PJT security program, assist with project work on security infrastructure, including SIEM, EDR, and related tooling — contributing engineering effort as priorities require.
- Bachelor’s degree in Computer Science, Information Security, or a related field.
- 7–10+ years of experience in information security, with a strong focus on vulnerability management, secure design review, patch operations, and incident response.
- Demonstrated experience running a hands-on vulnerability management program — not solely in an oversight or program management capacity.
- Experience providing incident response coverage, including participation in on-call rotations or extended-hours response.
- Proficiency with vulnerability management platforms such as Nessus, Qualys, or Rapid7; ability to operate these tools directly, not just interpret reports.
- Knowledge of cloud security posture management (CSPM) platforms such as Wiz or Microsoft Defender for Cloud, and exposure management workflows.
- Strong technical skills in vulnerability scanning, patch management, and network security protocols.
- Working knowledge of operating systems (Windows, Linux) and web application security.
- Familiarity with SIEM tools for alert triage and incident investigation.
- Scripting and automation skills in PowerShell or Python; experience with workflow tools such as ServiceNow or JIRA.
- Working knowledge of security frameworks including NIST CSF, CIS Controls, and ISO 27001.
- Understanding of incident response frameworks (e.g., NIST SP 800-61, PICERL) and how vulnerability management integrates into the IR lifecycle.
- Excellent communication and interpersonal skills; able to convey complex security issues to both technical and non-technical audiences.
- Strong leadership and mentorship abilities; demonstrated experience managing cross-functional teams and external consultants.
- Ability to work independently, manage competing priorities, and adapt to rapidly shifting demands.
- Willingness and ability to provide extended-hours incident response coverage as required by the role, including off-hours and weekend on-call responsibilities.
Vulnerability Management and Security Engineering Vice President employer: PJT Partners
PJT Partners is an exceptional employer that prioritises a diverse and inclusive work culture, fostering collaboration among talented professionals in the fast-paced investment banking sector. With a strong commitment to employee growth, we offer ample opportunities for career advancement and skill development, particularly within our evolving Cybersecurity function. Located in a dynamic environment, our team enjoys the unique advantage of working at the forefront of strategic advisory services while contributing to a robust technology foundation that supports our clients' needs.
StudySmarter Expert Advice🤫
We think this is how you could land Vulnerability Management and Security Engineering Vice President
✨Tip Number 1
Network like a pro! Reach out to your connections in the industry, attend relevant events, and don’t be shy about asking for introductions. We all know that sometimes it’s not just what you know, but who you know that can land you that dream job.
✨Tip Number 2
Prepare for interviews by researching PJT Partners thoroughly. Understand their values, recent projects, and the specific challenges they face in cybersecurity. This will help us tailor your responses and show that you’re genuinely interested in being part of the team.
✨Tip Number 3
Practice makes perfect! Conduct mock interviews with friends or mentors to refine your answers and get comfortable discussing your experience. We want you to feel confident when talking about your hands-on vulnerability management skills and incident response experience.
✨Tip Number 4
Don’t forget to follow up after interviews! A simple thank-you email can go a long way in keeping you top of mind. Plus, it shows that you’re proactive and genuinely interested in the role. And remember, apply through our website for the best chance!
We think you need these skills to ace Vulnerability Management and Security Engineering Vice President
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the role of Vulnerability Management and Security Engineering Vice President. Highlight your hands-on experience in vulnerability management and incident response, as well as any relevant technical skills that match the job description.
Craft a Compelling Cover Letter:Your cover letter should tell us why you're the perfect fit for PJT Partners. Share specific examples of your past experiences that align with the responsibilities outlined in the job description, and don’t forget to express your enthusiasm for the role!
Showcase Your Technical Skills:Be sure to include your proficiency with tools like Nessus, Qualys, or Rapid7 in your application. We want to see that you can not only manage vulnerabilities but also understand the technical aspects behind them.
Apply Through Our Website:For the best chance of getting noticed, apply directly through our website. This ensures your application goes straight to the right people and shows us you're serious about joining our team at PJT Partners.
How to prepare for a job interview at PJT Partners
✨Know Your Tools Inside Out
Make sure you’re well-versed in the vulnerability management platforms mentioned in the job description, like Nessus, Qualys, or Rapid7. Be prepared to discuss your hands-on experience with these tools and how you've used them to drive remediation efforts.
✨Showcase Your Incident Response Skills
Since this role involves critical incident response, be ready to share specific examples of how you've triaged and responded to incidents in the past. Highlight your ability to communicate effectively under pressure and how you’ve ensured continuity of response.
✨Demonstrate Your Leadership Abilities
PJT Partners values strong leadership and mentorship skills. Prepare to discuss how you've led cross-functional teams or mentored junior staff in previous roles. Share examples that illustrate your ability to manage competing priorities and adapt to changing demands.
✨Understand the Business Context
Familiarise yourself with PJT Partners' advisory services and how cybersecurity fits into their business model. Being able to articulate how your work in vulnerability management supports the firm's strategic objectives will set you apart from other candidates.