Role Summary
We are seeking a highly skilled Product Vulnerability Management Architect to lead the design, implementation, and evolution of enterprise-wide vulnerability management programs across products and applications. This role will also drive innovation through Agentic AI–powered security solutions, enabling automated vulnerability discovery, triage, and remediation.
The ideal candidate combines deep cybersecurity expertise, strong software engineering skills, and modern AI-driven approaches to build intelligent, scalable, and secure systems.
Key Responsibilities
- Define and architect the end-to-end Product Vulnerability Management (PVM) framework
- Design and implement Agentic AI systems for:
- Automated vulnerability detection and classification
- Intelligent triage and prioritization using contextual risk signals
- Autonomous or semi-autonomous remediation recommendations
- Develop Python-based automation frameworks for vulnerability ingestion, correlation, and response
- Build custom integrations and wrappers around security scanners and AI models
- Integrate vulnerability management into CI/CD pipelines and DevSecOps workflows
- Establish vulnerability discovery, triage, prioritization, and remediation processes across SDLC
- Drive risk-based vulnerability management aligned with business impact and threat intelligence
- Collaborate with engineering teams to ensure timely remediation and secure coding practices
- Perform root cause analysis and implement systemic fixes using data-driven insights
- Define security standards aligned with frameworks like OWASP (Open Worldwide Application Security Project), NIST (National Institute of Standards and Technology), and ISO/IEC 27001
- Partner with AppSec, Red Team, and Threat Intelligence teams to enhance detection and response
- Establish metrics, dashboards, and SLAs for vulnerability posture and remediation efficiency
Required Skills & Experience
Cybersecurity & Vulnerability Management
- 10-15 years in cybersecurity, application security, or product security roles
- Deep expertise in vulnerability management at enterprise scale
- Strong knowledge of:
- CVE (Common Vulnerabilities and Exposures)
- CVSS (Common Vulnerability Scoring System)
- OWASP Top 10
- MITRE ATT&CK
Advanced Python & Automation Engineering
- Strong programming expertise in Python with focus on:
- API orchestration (REST, GraphQL integrations)
- Data pipelines (parsing scan outputs, logs, telemetry)
- Automation scripts for vulnerability remediation workflows
- Experience with:
- Asynchronous processing for large-scale scanning systems
- SDK integrations with security tools and cloud platforms
- Ability to:
- Build custom wrappers and orchestration layers around scanners and AI/LLM models
Agentic AI & Intelligent Automation
- Hands-on experience designing Agentic AI systems and LLM-driven workflows
- Understanding of:
- Multi-step reasoning agents and tool orchestration
- Context management, memory, and guardrails
- Experience integrating AI into real-world security workflows
DevSecOps & Integration Architecture
- Deep understanding of:
- CI/CD pipelines (GitHub Actions, Jenkins, GitLab CI)
- Infrastructure as Code using Terraform and CloudFormation
- Experience implementing:
- Pre-commit security checks
- Build-time scanning (SAST/SCA/container scans)
- Runtime monitoring and feedback loops
- Strong ability to embed security controls seamlessly into developer workflows
Cloud & Container Security
- Hands-on experience with:
- AWS, Azure, or GCP security models
- Kubernetes and container security
- Strong understanding of:
- Identity and access misconfigurations
- Container and image vulnerabilities
- Secrets management and secure configuration practices
Preferred Certifications (Required / Highly Valued)
Core Security Certifications
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CISA (Certified Information Systems Auditor)
Application & Offensive Security
- CSSLP (Certified Secure Software Lifecycle Professional)
- OSCP (Offensive Security Certified Professional)
- GIAC GWEB (GIAC Web Application Penetration Tester)
Cloud & Emerging Technologies
- AWS Certified Security – Specialty
- Microsoft Certified: Azure Security Engineer Associate
- Google Professional Cloud Security Engineer
AI / Automation (Nice to Have)
- Certifications or coursework in AI/ML, LLMs, or autonomous systems
Nice to Have
- Experience with AI-assisted vulnerability management platforms
- Familiarity with bug bounty programs (HackerOne, Bugcrowd)
- Knowledge of Zero Trust Architecture
- Experience in regulated industries (banking, fintech, healthcare)
Soft Skills
- Strong analytical and systems-thinking mindset
- Ability to bridge security, AI, and engineering teams
- Excellent communication and architecture documentation skills
- Strategic thinking with hands-on execution capability