Nelnet Logo

Nelnet

Manager, Exposure Management

Posted 21 Days Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in Centennial, CO, USA
120K-160K Annually
Mid level
In-Office or Remote
Hiring Remotely in Centennial, CO, USA
120K-160K Annually
Mid level
Lead a unified exposure management program combining vulnerability, attack surface, cloud, infrastructure, and application findings into a prioritized, risk-based remediation pipeline. Manage and mentor a team, implement CTEM processes, leverage AI/automation to prioritize work, partner with engineering and stakeholders to drive remediation, and report exposure metrics to executive leadership while ensuring compliance with regulatory and contractual obligations.
The summary above was generated by AI

Nelnet is a diversified and innovative company committed to enriching lives through the power of service as a student loan servicer, professional services company, consumer loan originator and servicer, payments processor, renewable energy solutions, and K-12 and higher education expert. For over 40 years, Nelnet has been serving its customers, associates, and communities.

The perks of working at Nelnet go beyond our benefits package. When you join the Nelnet team, you're part of a community invested in the success of each individual. That support comes through in our work, as we are united by our mission of creating opportunities for people where they live, learn, and work.

Nelnet is seeking an experienced and motivated Cybersecurity Manager, Exposure Management to lead our vulnerability operations, attack surface management, and application security functions. The ideal candidate will combine strong cybersecurity knowledge with exceptional leadership and stakeholder-management skills, and a demonstrated ability to drive remediation outcomes across engineering, infrastructure, and business teams.
In this role you will lead a single, unified exposure management program — bringing findings from code, configuration, cloud, infrastructure, and external attack surface into one prioritized, risk-based view. You will guide the team through a transformative evolution of how the function operates, adopting a Continuous Threat Exposure Management (CTEM) approach and leveraging AI and automation to optimize the prioritization of work activity. As the Manager, Exposure Management, you will be responsible for reducing enterprise risk by ensuring the right exposures are identified, prioritized, and remediated through strong partnerships across the organization.
This position requires work in support of the Company’s contract with the United States Department of Education (“ED”). As such, the United States Government requires that any applicant for this position must complete United States Government security clearance. Effective June 1, 2018, ED has informed Nelnet that security clearance applications for foreign nationals are not being accepted or processed. In light of this direction from ED, Nelnet will be unable to hire applicants without United States citizenship for such positions.

This position offers a hybrid work option. Nelnet values flexibility and understands the importance of work-life integration. Our hybrid work environment allows associates within 30 miles of an office to work remotely for part of the week, while also fostering collaboration and team connection through in-office presence.

Please note that we are unable to provide visa sponsorship for this position. To be considered, candidates must already be authorized to work in the United States without the need for current or future sponsorship as security clearance is required.

Responsibilities:

Leadership and Team Development:

  • Provide leadership, guidance, and mentorship to a team of vulnerability analysts and application security practitioners.
  • Foster a collaborative, high-performance environment and lead the team through a transformative evolution of its operating model.
  • Conduct performance evaluations, identify training needs, and support professional development.
  • Evolve team roles toward judgment, validation, and stakeholder engagement as automation and AI-assisted workflows mature.

Exposure Management Operations:

  • Oversee a unified exposure management pipeline — intake, enrichment, prioritization, and remediation orchestration — across a dynamic, continuously changing vulnerability portfolio.
  • Operate the program as a Continuous Threat Exposure Management (CTEM) cycle of scoping, discovery, prioritization, validation, and mobilization.
  • Integrate findings across code, configuration, cloud, infrastructure, and external Attack Surface Management (ASM) into a single, risk-based view.
  • Develop and maintain exposure management policies, procedures, and workflows.

Prioritization and Risk-Based Remediation:

  • Apply risk-based prioritization beyond CVSS — including exploitability, reachability, asset criticality, and threat-intelligence context — to focus effort where risk is greatest.
  • Leverage AI and automation to enrich, rank, and continuously optimize the prioritization of work activity.
  • Establish and maintain a documented risk-acceptance workflow with clear business-owner accountability.
  • Define and report remediation SLAs, velocity, and risk-reduction metrics that leadership can trust.

Application Security:

  • Guide enterprise application security programs, including code analysis, secure development standards, developer guidance, and a security champions program.
  • Partner with development teams to integrate security into the SDLC and CI/CD workflows.

Stakeholder Engagement and Collaboration:

  • Build credibility and drive remediation outcomes with development, infrastructure, and platform teams across the organization.
  • Translate exposure into the appropriate framing for each audience — technical detail for engineers, delivery impact for managers, and business risk for executives.
  • Partner with GRC and internal audit to ensure defensible process, evidence, and risk-register alignment.
  • Deliver clear, concise exposure narratives to the CISO and executive leadership, including a board-ready view of enterprise exposure.
  • Satisfy FSA/OSA and similar regulated-process obligations as a baseline of the program.

Qualifications:

  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience.
  • Minimum of 3–6 years of experience in cybersecurity, including exposure to vulnerability management, application security, and/or attack surface management.
  • Minimum of 1–2 years of team lead or management experience.
  • Working knowledge of vulnerability management platforms (e.g., Tenable, Wiz, or equivalents), attack surface management tooling, and application security concepts (e.g., SAST, DAST, SCA).
  • Understanding of risk-based prioritization and modern exposure management concepts, including Continuous Threat Exposure Management (CTEM).
  • Demonstrated ability to influence and drive outcomes across teams without direct reporting authority.
  • Excellent communication, presentation, and interpersonal skills, with the ability to translate technical risk into clear business language.
  • Strong analytical, problem-solving, and decision-making skills.
  • Ability to work effectively in a fast-paced and evolving environment.
  • Relevant certifications such as CISSP, CISM, or SANS GIAC certifications (e.g., GCIH, GSEC) are highly desirable.

Preferred Qualifications:

  • Experience operating, building, or maturing a CTEM or exposure management program.
  • Familiarity with AI- and automation-assisted security workflows.
  • Familiarity with cloud security concepts and technologies (e.g., AWS, Azure, GCP).
  • Knowledge of relevant regulatory and compliance frameworks (e.g., NIST, ISO 27001, PCI DSS).
  • Experience with secure SDLC practices and security champions programs.
  • Experience with scripting languages (e.g., Python, PowerShell).

Compensation range for this role is $120,000-$160,000 annually, depending on experience.

#LI-Remote

#LI-CW1

Our benefits package includes medical, dental, vision, HSA and FSA, generous earned time off, 401K/student loan repayment, life insurance & AD&D insurance, employee assistance program, employee stock purchase program, tuition reimbursement, performance-based incentive pay, short- and long-term disability, and a robust wellness program. Click here to learn more about our benefits: Benefits & Perks - Nelnet Inc.


Nelnet is committed to providing a welcoming and respectful workplace where all associates have the opportunity to succeed. As an Equal Opportunity Employer, we ensure that all qualified applicants are considered for employment. Employment decisions are made without regard to race, color, religion/creed, national origin, gender, sex, marital status, age, disability, use of a guide dog or service animal, sexual orientation, military/veteran status, or any other status protected by federal, state, or local law. We value the unique contributions of every team member and believe that a positive work environment benefits everyone.  


Qualified individuals with disabilities who require reasonable accommodations in order to apply or compete for positions at Nelnet may request such accommodations by contacting Corporate Recruiting at 402-486-5725 or [email protected].


Nelnet is a Drug Free and Tobacco Free Workplace.


Use of Artificial Intelligence in Hiring

We may use automated or artificial intelligence enabled tools to assist with the initial review of applications, such as identifying relevant skills or experience. These tools are used to support human review and do not make hiring decisions. A recruiter reviews applications and determines which candidates move forward in the hiring process. For more information, see our Privacy Policy and Pre-Use Notice: Automated Tools in Hiring

Nelnet Centennial, Colorado, USA Office

7150 S Fulton Street, Centennial, United States, 80112

Similar Jobs

18 Days Ago
Remote
USA
155K-210K Annually
Senior level
155K-210K Annually
Senior level
Information Technology • Internet of Things • Security • Software • Cybersecurity
Lead positioning, messaging, and GTM for Censys' Internet Exposure portfolio. Translate technical and competitive insights into sales and marketing assets, enable sales, run launches, present to customers, and partner cross-functionally to drive awareness, pipeline, and consistent storytelling.
30 Minutes Ago
Remote
United States
110K-130K Annually
Mid level
110K-130K Annually
Mid level
AdTech • Artificial Intelligence • Big Data • Digital Media • eCommerce • Machine Learning • Marketing Tech
Plan and execute regional and large-scale industry events, design executive-level activations, manage partner marketing and budgets, track lead flow and ROI, collaborate with Sales/Product/Global Marketing, and standardize event and partner marketing processes.
Top Skills: AsanaCRMRoi DashboardsSpreadsheets
4 Hours Ago
Remote
United States
253K-275K Annually
Senior level
253K-275K Annually
Senior level
Blockchain • Software • Cryptocurrency • Web3
Design, build, test, and deploy smart contracts and decentralized applications. Maintain blockchain integrations and backend services, optimize for security and gas efficiency, contribute to architecture and technical strategy, conduct code reviews, mentor junior engineers, and collaborate with product, frontend, and security teams.
Top Skills: AnchorAvalancheBnb ChainCi/CdCloud InfrastructureDaosDatabasesDefiEthereumEthers.JsFoundryGitGoHardhatNftsNode.jsPolygonPythonRustSmart ContractsSolanaSolidityTruffleTypescriptWallet IntegrationsWeb3.Js

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account