Attack Surface Reduction Lead Associate Director
New Today
Are you ready to make an impact at DTCC?
Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We're committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve.
Pay and Benefits: Competitive compensation, including base pay and annual incentive
Comprehensive health and life insurance and well-being benefits, based on location
Pension / Retirement benefits
Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).
The Impact you will have in this role :
IT Cyber Security & Resiliency (CSR) sets strategic direction for IT Risk and Information Security, maintains corporate security policies and control standards, and serves as the primary interface for regulatory and client reviews. CSR also oversees threat intelligence and incident response coordination across the enterprise.
The Threat & Vulnerability team proactively identifies and mitigates security threats through continuous monitoring, assessment, and development of robust security measures to safeguard DTCC’s infrastructure.
The Attack Surface Reduction Lead Associate Director will drive the strategic reduction of externally exposed assets and findings, aligning with the Edge Zero initiative. This role requires a strong communicator and partner who can navigate the complexity of perimeter technologies and defensive controls to reduce risk across the enterprise.
Your Primary Responsibilities : Lead the identification and reduction of externally exposed assets and vulnerabilities across DTCC’s perimeter.
Foster trust-based relationships with stakeholders who own perimeter and edge assets to align on responsibilities, risks, and remediation actions.
Shape priorities and influence planning across teams to embed risk reduction into decision-making processes.
Demonstrate technical curiosity by developing deep understanding of perimeter technologies and defensive controls.
Manage vulnerability management projects, including scheduling, resource allocation, and reporting.
Create and present meaningful metrics and reports to senior management on attack surface reduction effectiveness.
Ensure adherence to relevant compliance standards and internal policies.
Lead and coordinate responses to security incidents related to external threats and vulnerabilities.
Develop and maintain policies, procedures, job aids, and documentation.
**NOTE: The Primary Responsibilities of this role are not limited to the details above. **
Qualifications: Minimum of 8 years of related experience in cybersecurity, threat and vulnerability management, or technology risk.
Bachelor’s degree preferred or equivalent experience.
Talents Needed for Success: Proven ability to influence cross-functional teams and drive strategic initiatives.
Strong understanding of perimeter security technologies and external threat landscapes.
Experience with vulnerability management tools, metrics, and reporting.
The salary range is indicative for roles at the same level within DTCC across all US locations. Actual salary is determined based on the role, location, individual experience, skills, and other considerations.
- Location:
- Tampa
- Job Type:
- FullTime