At Julius Baer, we celebrate and value the individual qualities you bring, enabling you to be impactful, to be entrepreneurial, to be empowered, and to create value beyond wealth. Let’s shape the future of wealth management together.
GENERAL DESCRIPTIONAs an Exposure Manager within our Security Compliance Competence Centre, you will play a key role in supporting our proactive security testing program and exposure mitigation activities. You will coordinate the execution of penetration testing engagements, ensuring our applications and infrastructure remain resilient against evolving cyber threats. You will manage key processes within our Exposure Management initiative: providing process support and guidance to the technology teams, reporting adherence to the management, and working with peers internationally to maintain adherence to standards, guidelines, and local regulations. This position offers mentorship from senior security experts and clear growth opportunities.YOUR CHALLENGE
KEY FEATURES AND ACCOUNTABILITIES
Process Management
- Manage multiple penetration testing engagements from initiation through reporting and remediation tracking. Define objectives, timelines, and resources in collaboration with application owners and technical experts
Stakeholder Engagement
- Act as the central point of contact for exposure management activities, liaising with internal teams (Application Owners, Development Leads, Product Owners) and external vendors
Requirements Gathering
- Organize and lead scoping sessions to align business needs, technical constraints, and security best practices
Vendor Coordination
- Oversee external penetration testing partners – review statements of work, track deliverables, and ensure adherence to timelines
Logistics & Preparation
- Coordinate pre-engagement activities such as access provisioning, environment setup, and documentation readiness
Expert Liaison
- Collaborate with senior security specialists to validate scopes, clarify findings, and escalate complex technical issues
Escalation & Coordination
- Act as the central point for questions and escalations related to EM process. Communicate effectively across teams and escalate when necessary
Teamwork
- You will work closely with other EM managers and technical experts across international hubs, ensuring processes run smoothly and stakeholders are supported
Reporting & Communication
- Provide regular updates on testing progress, findings, and remediation status. Respond to inquiries within agreed SLAs (e.g., acknowledgement within 1 business day, next steps within 2 business days)
Exposure Management
- Support the response process for infrastructure vulnerabilities and configuration deviations tracked in ServiceNow Vulnerability Response (VR), ensuring timely and audit-compliant resolution
Regulatory Responsibilities &/OR Risk Management
- Demonstration of appropriate values and behaviours including but not limited to standards on honesty and integrity, due care and diligence, fair dealing (treating customers fairly), management of conflicts of interest, competence and continuous development, adequate risk management, and compliance with applicable laws and regulations
SKILLS REQUIREMENTS
Personal and Social
- Strong organizational and time-management skills; ability to manage multiple projects simultaneously
- Excellent communication and stakeholder management skills, with a proactive and solution-oriented mindset
- Professional proficiency in English
Professional and Technical
- Bachelor’s degree in computer science, information security, or equivalent practical experience
- 3–5 years of experience in IT/security governance, compliance, or vulnerability management, or technical project management
- Experience using ServiceNow or similar ITSM/GRC platforms
Regulatory
- Foundational understanding of security configuration standards (e.g., OWASP Top 10, CIS benchmarks) and vulnerability management principles
- Familiarity with penetration testing phases and methodologies
Optional Requirements (Considered a Plus):
- Experience coordinating penetration testing or security assessment projects
- Familiarity with vulnerability scanning tools (e.g., Nexpose) and exposure management workflows
- Experience working with external vendors
- IT or Security certifications (e.g., Security+, CISM, CISSP, CEH, OSCP)
- Basic understanding of infrastructure security concepts
- Experience in financial services or regulated environments
We are looking forward to receiving your full job application through our online application tool. Further interesting job opportunities can be found on our Career site.
Is this not quite what you are looking for? Set up a job alert by creating a candidate account here.
