About this role
Who We Are
At Kyndryl, we run and reimagine the mission-critical technology systems that drive advantage for the world’s leading businesses. We are at the heart of progress; with proven expertise and a continuous flow of AI-powered insight, enabling smarter decisions, faster innovation, and a lasting competitive edge. For our people—Kyndryls—that means doing purposeful work that powers human progress. Join us and experience a flexible, supportive environment where your well-being is prioritized and your potential can thrive.
The Role
Who We Are
Kyndryl's Chief Information Security Office (CISO) is responsible for protecting the enterprise through effective cyber risk management, security governance, exposure reduction, and security validation. As cyber threats continue to evolve, our focus is not only on identifying vulnerabilities, but on ensuring risks are understood, prioritized, remediated, and validated through measurable outcomes.
We are seeking a highly motivated cybersecurity professional to join our Integrated Exposure Operations (IXO) team. This role plays a critical part in reducing organizational cyber risk through vulnerability management, security validation, penetration testing governance, and remediation orchestration across a complex global technology environment.
The Role
As a Cyber Security Penetration Testing Lead (Program Management), you will be responsible for coordinating and governing key exposure management and security validation activities across the enterprise. You will work closely with application owners, infrastructure teams, risk management functions, security engineering teams, and executive stakeholders to ensure security findings are effectively prioritized, remediated, and validated.
You will lead the operational management of penetration testing and security validation programs, ensuring assessments are planned, executed, tracked, and closed in accordance with enterprise security requirements. You will help drive risk-based decision making by ensuring vulnerabilities and exposures are translated into actionable remediation plans and measurable risk reduction outcomes.
Success in this role requires strong stakeholder management, cybersecurity knowledge, program governance, and the ability to translate technical findings into meaningful business risk conversations.
###
Responsibilities
- Coordinate and govern enterprise penetration testing, security validation, and related activities from onboarding through remediation and closure.
- Drive vulnerability and exposure management processes, ensuring findings are prioritized using risk-based methodologies and tracked to resolution.
- Partner with solution owners, engineering teams, Cyber Operations, and remediation teams to accelerate risk reduction activities.
- Facilitate security findings reviews, remediation workshops, risk acceptance discussions, and retest readiness assessments.
- Track and report remediation progress, risk treatment plans, service metrics, and key performance indicators to technical and executive stakeholders.
- Manage exception requests, compensating controls, executive approvals, and risk documentation in accordance with established governance processes.
- Support cyber risk management activities by ensuring evidence is collected and maintained to satisfy audit, compliance, and risk closure requirements.
- Contribute to the evolution of vulnerability management, exposure management, and security validation capabilities through process improvement and operational innovation.
- Support strategic cybersecurity initiatives designed to improve organizational visibility, risk prioritization, and overall security posture.
- Develop trusted relationships across technical, operational, and leadership teams, acting as a central point of coordination for security validation and remediation activities.
###
Required Skills & Experience
- Experience in vulnerability management, exposure management, cyber risk management, or security operations.
- Strong understanding of penetration testing, security assessments, Purple Team exercises, and security validation methodologies.
- Experience coordinating remediation activities across multiple stakeholders and technology teams.
- Strong analytical, communication, and stakeholder management skills.
- Experience presenting cybersecurity risks and remediation status to senior leadership.
- Understanding of cybersecurity frameworks, risk management processes, and governance controls.
- Experience working within large, complex enterprise environments.
###
Preferred Skills
- Knowledge of Risk-Based Vulnerability Management (RBVM) platforms and methodologies.
- Experience with attack surface management, exposure assessment, and continuous controls validation.
- Familiarity with enterprise risk management and audit processes.
- Relevant industry certifications such as CISSP, CISM, CRISC, Security+, GSEC, or equivalent.
- Experience supporting large-scale cybersecurity transformation or operational improvement initiatives.
###
Why Join Us?
This is not a traditional incident response or SOC role. Instead, you will help shape how Kyndryl identifies, prioritizes, validates, and reduces cyber risk across the enterprise.
Who You Are
Who You Are
You're an experienced cybersecurity professional with a strong understanding of vulnerability management, security validation, cyber risk reduction, and enterprise security governance. You are passionate about reducing organizational risk through effective prioritization, remediation, and operational excellence.
You combine technical credibility with strong stakeholder management skills and can confidently work across engineering teams, security functions, risk management, and senior leadership to drive measurable security outcomes. You are outcome-focused, collaborative, and comfortable operating in complex global environments where influence, coordination, and execution are as important as technical expertise.
Most importantly, you have a growth mindset, are committed to continuous learning, and enjoy solving complex cybersecurity challenges while helping others succeed.
Required Skills and Experience
- 7+ years' experience in cybersecurity, vulnerability management, exposure management, security operations, cyber risk management, or related disciplines.
- Strong understanding of Vulnerability Management (VM), Risk-Based Vulnerability Management (RBVM), exposure management, and remediation governance.
- Experience coordinating penetration testing, security assessments, or other security validation activities.
- Ability to evaluate and prioritize vulnerabilities and security findings based on risk, exploitability, business impact, and threat intelligence.
- Experience partnering with application owners, infrastructure teams, Cyber Operations, and remediation stakeholders to drive risk reduction outcomes.
- Knowledge of cyber risk management frameworks, governance processes, and security control validation methodologies.
- Experience managing remediation programs, tracking corrective actions, facilitating retests, and supporting risk closure activities.
- Strong analytical and problem-solving skills with the ability to translate technical findings into business risk.
- Excellent written and verbal communication skills, including experience presenting cybersecurity risks, trends, and recommendations to senior stakeholders.
- Experience working within large, complex enterprise environments with multiple stakeholders and competing priorities.
- Demonstrated ability to lead cross-functional initiatives and drive process improvements that improve security outcomes.
##
Preferred Skills and Experience
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related discipline.
- Experience with exposure management, attack surface management, continuous security validation, or cyber risk quantification platforms.
- Experience with security validation tooling, vulnerability platforms, and remediation orchestration technologies.
- Familiarity with enterprise risk management, audit, regulatory, and compliance requirements.
- Experience supporting executive reporting, operational metrics, and cybersecurity governance forums.
- Knowledge of cloud security platforms and modern application security practices.
- Experience working with vulnerability scanners, penetration testing providers, and security assessment teams.
- Industry certifications such as CISSP, CISM, CRISC, Security+, GSEC, CGRC, or equivalent.
- Experience supporting cybersecurity transformation programs or operational maturity initiatives.
Being You
The “Kyn” in Kyndryl means kinship, which represents the strong bonds we have with each other, our customers and our communities. We focus on ensuring all Kyndryls feel included and we welcome people of all cultures, backgrounds, and experiences. Even if you don’t meet every requirement, we encourage you to apply. We believe in growth, and we’re excited to see what you can bring. At Kyndryl, employee feedback has told us that our number one driver of employee engagement is belonging. That sense of belonging — being a valued, respected, trusted member of the team — is fundamental to our culture and fueling great experiences for our customers. This dedication to welcoming everyone into our company means that Kyndryl gives you the ability to thrive and contribute to our culture of empathy and shared success. That’s The Kyndryl Way.
What You Can Expect
Your career with us isn’t just a job—it’s an adventure with purpose. We offer a dynamic, hybrid-friendly culture that supports your well-being and empowers you to grow. Our Be Well programs are thoughtfully designed to support your financial, mental, physical, and social health—because we know that when you feel your best, you do your best.
From your very first day, you’ll dive into impactful work that powers the systems our customers rely on every day. You won’t just contribute—you’ll make a difference, tackling meaningful projects that sharpen your skills and fuel your growth.
We’re here to champion your journey. With powerful tools to chart your career path, personalized development goals aligned with your ambitions, and continuous feedback to keep you inspired and on track, you’ll have everything you need to thrive and evolve. You’ll develop in-demand skills to grow your career and achieve your ambitions with access to cutting-edge learning opportunities—from certifications with Microsoft, Google, and Amazon to coaching and hands-on experiences. And through it all, you’ll be part of a culture that values empathy, restless learning, and a devotion to shared success.
We want you to thrive here—and we’re committed to helping you do just that. Ready to make an impact? Join us and help shape what’s next.
Get Referred!
If you know someone that works at Kyndryl, when asked ‘How Did You Hear About Us’ during the application process, select ‘Employee Referral’ and enter your contact's Kyndryl email address.