About this role
At BNY, our culture allows us to run our company better and enables employees’ growth and success. As a leading global financial services company at the heart of the global financial system, we influence nearly 20% of the world’s investible assets. Every day, our teams harness cutting-edge AI and breakthrough technologies to collaborate with clients, driving transformative solutions that redefine industries and uplift communities worldwide. Recognized as a top destination for innovators, BNY is where bold ideas meet advanced technology and exceptional talent. Together, we power the future of finance – and this is what #LifeAtBNY is all about. Join us and be part of something extraordinary. We’re seeking a future team member for the role of Senior Vice President, Infrastructure Solution Engineer to join our controls hub team. This role is located in New York. In this role, you’ll make an impact in the following ways:
• Vulnerability Detection & Triage : Continuously monitor the VMAD vulnerability intelligence system to identify newly disclosed CVEs and policy violations affecting managed applications and infrastructure
• Design and implement CI/CD-integrated remediation pipelines that automates the steps from scoping the change, running tests, certify for release, manage change controls and deploys components through stages of nonprod/prepprod/prod with sufficient controls and approvals.
• Build pipelines that handle three distinct remediation surfaces independently for application dependencies, host patching, cluster upgrades.
• Platform Improvement & Speed of Migration: Identify systemic bottlenecks — manual approval gates, flaky tests, environment provisioning lag — and eliminate them through automation, tooling, or process re-design
• Cross-Application Collaboration: Serve as the embedded vulnerability remediation partner for application teams across AIM, providing both automation tooling and advisory support for complex or high-risk remediation scenarios
To be successful in this role, we’re seeking the following:
• 5+ years in platform, DevSecOps, or infrastructure engineering with demonstrated ownership of security remediation programs at scale
• Hands-on experience building and operating CI/CD pipelines (GitLab CI, Jenkins, GitHub Actions, or equivalent) for automated testing and deployment
• Working proficiency in at least two of: Java/JVM ecosystem, Go, Python — specifically around dependency management, build tooling, and vulnerability scanning
• Experience with Kubernetes operations including cluster lifecycle management, node pool upgrades, and workload disruption budgeting
• Familiarity with OS-level patch management tooling and host configuration management (Ansible, Chef, or equivalent)
• Strong understanding of the vulnerability lifecycle: CVE scoring (CVSS/EPSS), exploit maturity, and risk-based prioritization