Improve and maintain automated vulnerability triaging capabilities and vulnerability data quality through data enrichment (internal and external intelligence feeds), quality metrics, AI-assisted triage, context-aware risk scoring, and vulnerability correlation/chaining
Hands-on validation and triaging of most critical/zero-days vulnerabilities
Work closely with vulnerability data consumers and stakeholders across the organization to meet engineering, compliance, and regulatory requirements by delivering high-quality, actionable findings and driving effective remediation
Contribute to the development of internal platforms, including the Unified Vulnerability Management (UVM) system and the security orchestration platform, to automate core vulnerability management workflows and reduce manual effort
Identify current deficiencies in patch management, drive and oversee improvements across engineering teams and business units to improve remediation efficiency and reduce organizational risk
Own vulnerability intake from all sources - scanners, bug bounty, threat intel feeds, and penetration tests
Prioritize findings using risk-based frameworks (CVSS, EPSS, SSVC, asset criticality, exploitability context, business impact) and reduce false positive noise
Drive remediation accountability across infrastructure, platform, and product engineering teams
Identify, track and report vulnerability management metrics, present KPIs and trends to security leadership
Coordinate response to critical/zero-day vulnerabilities, acting as the primary point of contact across security, engineering, and operations
Define and maintain integration between VOC tooling and the broader security ecosystem