Technical Patching Lead, VP - Middleware Web Services
State StreetAbout the role
Who We are Looking For:
This role will be a member of the Enterprise Patch Vulnerability Management Team.
We are seeking a highly skilled and experienced individual to join our team as a Middleware Vulnerability Lead. In this role, you will be responsible for overseeing the identification, assessment, and remediation of vulnerabilities within our organization's Middleware & Messaging systems. Your expertise will be critical to ensure the security and integrity of our middleware platforms.
What you will be responsible for:
The right person for this role will have strong program management experience, strong communication skills, the ability to deliver multiple high priority projects simultaneously, the ability to drive negotiations across teams with competing priorities and be an advocate for risk management.
Job Responsibilities:
Lead the Middleware vulnerability management program, focusing on identifying, assessing, and remediating vulnerabilities across various middleware and messaging platforms, including but not limited to WebSphere, Jboss, Tomcat, WebLogic, IBM HTTP Server, MQ Series, Kafka, Managed File Transfer.
Analyze vulnerability scan results and prioritize vulnerabilities based on severity, potential impact, and risk to the organization's data assets.
Collaborate with middleware and messaging administrators, system administrators, and IT security teams to develop and implement remediation plans for identified vulnerabilities.
Work closely with software development teams to address vulnerabilities in applications and ensure secure coding practices.
Implement and maintain middleware security best practices, including access controls, encryption, and data masking, to mitigate the risk of exploitation.
Monitor middleware patch management processes and ensure timely deployment of security patches and maintenance updates to address known vulnerabilities.
Provide guidance and support to middleware, messaging administrators and other stakeholders on secure configuration, hardening, and maintenance practices.
Stay current on emerging threats, vulnerabilities, and best practices related to middleware and messaging security through industry sources, vendor advisories, and professional networks.
Document processes, procedures, policies, standards related to middleware and messaging vulnerability management activities.
Ensure the Patching & Compliance Program satisfies remediation of cyber risks identified by Global Cyber Security, Corporate Audit, Technology Risk Management and Internal/External Regulators.
Drive Continuous Service Improvement by looking at lesson learns and gap analysis and implement improvement plans to automate, document, update and improve daily operation procedures
Develop reports using data that is hosted in multiple sources/tools (e.g., spreadsheets, dashboards) and communicate clearly to leadership.
Education & Preferred Qualifications
Bachelor's degree in computer science, information technology, or related field.
10+ years of experience in middleware administration and web services production support production environment, with a focus on vulnerability management and patch remediation.
Ability to effectively coordinate and communicate between technical teams and business stakeholders with varying technical proficiencies
Strong understanding of middleware technologies, including application servers, web servers, messaging systems, and integration platforms.
Experience with vulnerability assessment tools, such as ServiceNow Security Ops Module, Qualys, Nessus,etc. patch management systems (Tanium, Ansible Tower), and scripting languages for automation (e.g., Python, PowerShell).
Knowledge of industry standard security frameworks, (NIST, COBIT, DORA, CIS, etc.) security principles, threat modeling, and common vulnerabilities affecting middleware applications and environments.
Excellent analytical and problem-solving skills with the ability to prioritize and manage multiple tasks in a dynamic environment.
Industry certifications such as Certified Information Systems Security Professional (CISSP), CISM, CISA
This position offers the opportunity to play a key role in maintaining the security and resilience of our middleware infrastructur
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s