Head of Exposure Management
Rolls-Royce
- Location
- Working from home, US
- Work model
- On-Site
- Level
- Staff
- Posted
- Sep 4, 2026
Skills
About this role
Job Description
Job Title: Head of Exposure Management Working Pattern: Fulltime Working Location: Indianapolis, IN or Remote Relocation assistance will be provided if applicable. Why Rolls-Royce? At Rolls-Royce we are proud to be a business that has truly helped to shape the modern world and are committed to always being a force for progress; powering, protecting and connecting people everywhere. By joining Rolls-Royce, you’ll have the opportunity to create world-class power and propulsion solutions, pushing your problem-solving and ingenuity, to deliver real impact that puts safety first. You’ll be given responsibility and the opportunity to grow in our high-performance culture. This is Infinite Potential . And it’s your chance to really shine and contribute to one of the world’s most recognized brands and a beacon for engineering excellence.
Position
Summary The Exposure Management Lead is responsible for leading and maturing the organization’s Vulnerability Management Program to identify, assess, prioritize, and reduce cybersecurity risk across enterprise technology environments. This role provides strategic oversight of vulnerability management processes, technologies, reporting, and remediation activities while partnering closely with infrastructure, application, cloud, security, and business teams. The Exposure Management Lead serves as the subject matter expert for vulnerability risk management and is accountable for ensuring vulnerabilities are identified, assessed, prioritized, tracked, and remediated in accordance with organizational policies and risk tolerance.
What you will be doing
Develop, implement, and maintain the enterprise Exposure Management Program. Establish Exposure management policies, standards, procedures, and service level objectives. Oversee enterprise vulnerability scanning activities across on-premises, cloud, endpoint, network, and application environments. Ensure Exposure assessment coverage across all managed assets. Evaluate newly disclosed vulnerabilities and assess organizational exposure. Lead Exposure triage and prioritization efforts. Develop executive-level reporting and dashboards that communicate organizational risk exposure. Present vulnerability trends, remediation performance, and risk metrics to security leadership and business stakeholders. Partners with Threat Intelligence and Security Operations teams to prioritize vulnerabilities actively targeted by threat actors.
Basic Requirements
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field with 5+ years of experience in Exposure Management, Security Operations, Security Engineering, Risk Management or related cybersecurity disciplines Master's degree in Cybersecurity, Computer Science, Information Technology, or related field with 3+ years of experience in Exposure Management, Security Operations, Security Engineering, Risk Management or related cybersecurity disciplines JD/PhD Must be a U.S. Citizen or Permanent Resident to be considered for this role Preferred Requirements: Experience managing vulnerabilities across cloud, container, and hybrid environments. Familiarity with threat intelligence integration and exploitation analysis. Experience with security automation and workflow orchestration. Knowledge of vulnerability remediation processes within large enterprise environments. Experience supporting regulatory, compliance, and audit requirements. Our vision is to ensure that the quality and dynamism that shaped our history continues into our future. It’s a bold pursuit, and we never stop striving to go further, faster, and better. We lead progress, creating the technologies that move us forward. If you’re driven to grow, to learn, and to make a lasting difference, this is where you belong. Rolls-Royce is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to any protected characteristics. We are