The Lead Information Security Vulnerability role leads the integration of AI into vulnerability management operations while driving triage of findings generated from AI-enabled scans. As a subject matter expert in vulnerability assessment, this role advises on corrective actions and risk-based prioritization, and serves as a hands-on builder of the AI capabilities powering the program - including developing AI-driven scanning workflows, building AI-based validation agents, and maturing future agentic efforts. This is an individual-contributor role that bridges traditional vulnerability management with emerging AI-driven capabilities, ensuring findings are accurately validated, prioritized, and remediated at machine speed.
Key Responsibilities and Duties- Builds and matures AI-enabled vulnerability scanning capabilities using AI development tools and platforms, helping develop and strengthen the team's skills and repeatable practices for AI-driven scans.
- Designs, builds, and iterates on AI-based validation agents (e.g., verification of scan findings, SAST verification) to improve accuracy and reduce false positives at scale.
- Leads the triage, validation, and prioritization of vulnerability findings generated from AI-enabled identification tools, defining validation criteria and triage standards.
- Drives the integration of AI and agentic capabilities into vulnerability management BAU, improving the speed, accuracy, and scale of identification, prioritization, and remediation workflows.
- Develops standardized evaluation criteria to benchmark performance across testing harnesses, LLM providers, and iterations, ensuring AI processes are repeatable and sustainable for new applications.
- Advises management on vulnerability corrections and risk-based prioritization, producing reports that outline findings, intrusion paths, and recommended remediation.
- Supports the advancement of AI vulnerability identification and verification from proof-of-concept to production, including evaluation of AI scanning harnesses and approaches.
- Contributes to risk-based prioritization models (asset criticality, EPSS, CISA KEV, risk scoring) that drive remediation sequencing within the Unified Vulnerability Management (UVM) program.
- Determines causes and exploitation methods of identified vulnerabilities, and analyzes complex software systems and findings to assess functionality, intent, and exploitability.
- Designs and implements process automation and tooling specific to cyber and vulnerability operations.
- Collaborates with threat intelligence, remediation, AI, platform, and application teams to ensure timely resolution of critical and high-severity vulnerabilities within defined SLAs.
- Serves as a technical resource and mentor to vulnerability management practitioners, sharing AI tooling practices and consistent triage approaches (no direct reports).
- Leads and participates in future AI-driven vulnerability management initiatives that build on these capabilities as the program evolves.
Educational Requirements- University (Degree) Preferred
Work Experience- 5+ Years Required; 7+ Years Preferred
Physical Requirements- Physical Requirements: Sedentary Work
Career Level 8IC
Required Qualifications- 5+ years of experience in information security, vulnerability management, assessment, or related security operations.
- Experience and understanding of vulnerability prioritization frameworks (CVSS, EPSS, CISA KEV) and risk-based remediation.
Preferred Qualifications- Experience building with AI development tools and/or platforms (e.g., LLM- and agent-based tooling), including developing, prompting, and/or iterating on AI-driven workflows or agents.
- 7+ years of experience in information security or vulnerability management.
- Ability to work independently as an individual contributor across infrastructure, application, cloud, and container security contexts.
- Familiarity with vulnerability scanning and management platforms (e.g., Tenable, Wiz) and findings triage.
- Experience building or evaluating AI-based validation/verification agents and developing evaluation criteria for LLM/agent performance.
- Familiarity with agentic operating models, SAST/DAST/SCA tooling (e.g., Snyk), ServiceNow, and CI/CD pipeline integration.
- Relevant certifications a plus but not required (e.g., CISSP, GWAPT, GCIH, OSCP).
- Experience mentoring or guiding security practitioners.
Related Skills
Accountability, Adaptability, Business Continuity Planning, Cloud Computing Security, Collaboration, Communication, Compliance, Consultative Communication, Cybersecurity, Detail-Oriented, General Risk Management, Network Security, Prioritizes Effectively
Anticipated Posting End Date:2026-10-13
Base Pay Range: $116,000/yr - $152,000/yr
Actual base salary may vary based upon, but not limited to, relevant experience, time in role, base salary of internal peers, prior performance, business sector, and geographic location. In addition to base salary, the competitive compensation package may include, depending on the role, participation in an incentive program linked to performance (for example, annual discretionary incentive programs, non-annual sales incentive plans, or other non-annual incentive plans).