Nelnet

Manager, Exposure Management

Nelnet  •  $120k - $160k/yr  •  Lincoln, NE (Remote)  •  9 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Nelnet is a diversified and innovative company committed to enriching lives through the power of service as a student loan servicer, professional services company, consumer loan originator and servicer, payments processor, renewable energy solutions, and K-12 and higher education expert. For over 40 years, Nelnet has been serving its customers, associates, and communities.

The perks of working at Nelnet go beyond our benefits package. When you join the Nelnet team, you're part of a community invested in the success of each individual. That support comes through in our work, as we are united by our mission of creating opportunities for people where they live, learn, and work.

Nelnet is seeking an experienced and motivated Cybersecurity Manager, Exposure Management to lead our vulnerability operations, attack surface management, and application security functions. The ideal candidate will combine strong cybersecurity knowledge with exceptional leadership and stakeholder-management skills, and a demonstrated ability to drive remediation outcomes across engineering, infrastructure, and business teams.

In this role you will lead a single, unified exposure management program — bringing findings from code, configuration, cloud, infrastructure, and external attack surface into one prioritized, risk-based view. You will guide the team through a transformative evolution of how the function operates, adopting a Continuous Threat Exposure Management (CTEM) approach and leveraging AI and automation to optimize the prioritization of work activity. As the Manager, Exposure Management, you will be responsible for reducing enterprise risk by ensuring the right exposures are identified, prioritized, and remediated through strong partnerships across the organization.

This position requires work in support of the Company’s contract with the United States Department of Education (“ED”). As such, the United States Government requires that any applicant for this position must complete United States Government security clearance. Effective June 1, 2018, ED has informed Nelnet that security clearance applications for foreign nationals are not being accepted or processed. In light of this direction from ED, Nelnet will be unable to hire applicants without United States citizenship for such positions.

This position offers a hybrid work option. Nelnet values flexibility and understands the importance of work-life integration. Our hybrid work environment allows associates within 30 miles of an office to work remotely for part of the week, while also fostering collaboration and team connection through in-office presence.

Please note that we are unable to provide visa sponsorship for this position. To be considered, candidates must already be authorized to work in the United States without the need for current or future sponsorship as security clearance is required.

Responsibilities:

Leadership and Team Development:

  • Provide leadership, guidance, and mentorship to a team of vulnerability analysts and application security practitioners.
  • Foster a collaborative, high-performance environment and lead the team through a transformative evolution of its operating model.
  • Conduct performance evaluations, identify training needs, and support professional development.
  • Evolve team roles toward judgment, validation, and stakeholder engagement as automation and AI-assisted workflows mature.

Exposure Management Operations:

  • Oversee a unified exposure management pipeline — intake, enrichment, prioritization, and remediation orchestration — across a dynamic, continuously changing vulnerability portfolio.
  • Operate the program as a Continuous Threat Exposure Management (CTEM) cycle of scoping, discovery, prioritization, validation, and mobilization.
  • Integrate findings across code, configuration, cloud, infrastructure, and external Attack Surface Management (ASM) into a single, risk-based view.
  • Develop and maintain exposure management policies, procedures, and workflows.

Prioritization and Risk-Based Remediation:

  • Apply risk-based prioritization beyond CVSS — including exploitability, reachability, asset criticality, and threat-intelligence context — to focus effort where risk is greatest.
  • Leverage AI and automation to enrich, rank, and continuously optimize the prioritization of work activity.
  • Establish and maintain a documented risk-acceptance workflow with clear business-owner accountability.
  • Define and report remediation SLAs, velocity, and risk-reduction metrics that leadership can trust.

Application Security:

  • Guide enterprise application security programs, including code analysis, secure development standards, developer guidance, and a security champions program.
  • Partner with development teams to integrate security into the SDLC and CI/CD workflows.

Stakeholder Engagement and Collaboration:

  • Build credibility and drive remediation outcomes with development, infrastructure, and platform teams across the organization.
  • Translate exposure into the appropriate framing for each audience — technical detail for engineers, delivery impact for managers, and business risk for executives.
  • Partner with GRC and internal audit to ensure defensible process, evidence, and risk-register alignment.
  • Deliver clear, concise exposure narratives to the CISO and executive leadership, including a board-ready view of enterprise exposure.
  • Satisfy FSA/OSA and similar regulated-process obligations as a baseline of the program.

Qualifications:

  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience.
  • Minimum of 3–6 years of experience in cybersecurity, including exposure to vulnerability management, application security, and/or attack surface management.
  • Minimum of 1–2 years of team lead or management experience.
  • Working knowledge of vulnerability management platforms (e.g., Tenable, Wiz, or equivalents), attack surface management tooling, and application security concepts (e.g., SAST, DAST, SCA).
  • Understanding of risk-based prioritization and modern exposure management concepts, including Continuous Threat Exposure Management (CTEM).
  • Demonstrated ability to influence and drive outcomes across teams without direct reporting authority.
  • Excellent communication, presentation, and interpersonal skills, with the ability to translate technical risk into clear business language.
  • Strong analytical, problem-solving, and decision-making skills.
  • Ability to work effectively in a fast-paced and evolving environment.
  • Relevant certifications such as CISSP, CISM, or SANS GIAC certifications (e.g., GCIH, GSEC) are highly desirable.

Preferred Qualifications:

  • Experience operating, building, or maturing a CTEM or exposure management program.
  • Familiarity with AI- and automation-assisted security workflows.
  • Familiarity with cloud security concepts and technologies (e.g., AWS, Azure, GCP).
  • Knowledge of relevant regulatory and compliance frameworks (e.g., NIST, ISO 27001, PCI DSS).
  • Experience with secure SDLC practices and security champions programs.
  • Experience with scripting languages (e.g., Python, PowerShell).

Compensation range for this role is $120,000-$160,000 annually, depending on experience.

#LI-Hybrid

#LI-CW1

Our benefits package includes medical, dental, vision, HSA and FSA, generous earned time off, 401K/student loan repayment, life insurance & AD&D insurance, employee assistance program, employee stock purchase program, tuition reimbursement, performance-based incentive pay, short- and long-term disability, and a robust wellness program. Click here to learn more about our benefits: LINK

Nelnet is committed to providing a welcoming and respectful workplace where all associates have the opportunity to succeed. As an Equal Opportunity Employer, we ensure that all qualified applicants are considered for employment. Employment decisions are made without regard to race, color, religion/creed, national origin, gender, sex, marital status, age, disability, use of a guide dog or service animal, sexual orientation, military/veteran status, or any other status protected by federal, state, or local law. We value the unique contributions of every team member and believe that a positive work environment benefits everyone.

Qualified individuals with disabilities who require reasonable accommodations in order to apply or compete for positions at Nelnet may request such accommodations by contacting Corporate Recruiting at 402-486-5725 or corporaterecruiting@nelnet.net

Nelnet is a Drug Free and Tobacco Free Workplace.

Use of Artificial Intelligence in Hiring


We may use automated or artificial intelligence enabled tools to assist with the initial review of applications, such as identifying relevant skills or experience. These tools are used to support human review and do not make hiring decisions. A recruiter reviews applications and determines which candidates move forward in the hiring process. For more information, see our Privacy Policy and Pre-Use Notice: Automated Tools in Hiring

Nelnet

About Nelnet

Nelnet is a leading student loan servicer – but we’re even more than that.

We provide payment technology for over 1,300 higher education institutions and 11,500 K-12 schools. We deliver world-class fiber internet, TV, and phone services to residents of Nebraska and Colorado. We help borrowers achieve their educational goals with private student loan and refinance solutions. And we help businesses boost their performance with our cutting-edge technology and trusted expertise.

Each day, over 7,000 Nelnet associates in more than 30 communities across the country work to serve our customers and make their dreams possible. And we’re on the lookout for new people to help us go even further.

Industry
Finance & Insurance
Company Size
1,001-5,000 employees
Headquarters
Lincoln, Nebraska
Year Founded
1996
Social Media