CNA
AI Attack Surface and Threat Exposure Management Consulting Director
Chicago, IL, USA · Director
Sponsorship not specified$97k-$189kDetected 13 days ago
Code ReviewMachine LearningLLMsAgentic AICybersecurityPenetration TestingComplianceLeadershipCommunicationProblem SolvingInternal Audit
About the role
- You have a clear vision of where your career can go.
- And we have the leadership to help you get there.
- The Consulting Director, Attack Surface Management defines strategy, adoption, and governance of automation, AI, and agentic AI across application security, vulnerability management, ethical hacking, and attack surface management programs.
Responsibilities
- Evaluate, deploy, manage, and govern best-in-class new and existing AI-centric solutions, services, and capabilities relevant to the application security, ethical hacking, and vulnerability management domains.
- Identify, prioritize, and drive high-value outcomes where automation and AI can improve operational effectiveness, speed, scale, and efficiency.
- Develop and contribute to audit-defensible governance, standards, processes, procedures, methodologies, practices, playbooks, etc. for secure AI adoption and use across application security, vulnerability management, and ethical hacking domains.
- Lead identification and risk analysis of the external attack surface through development and continuous improvement of automation to drive effective risk exposure response across the business.
- Drive the use of AI to improve threat modeling, code review, and application security testing; vulnerability analysis, prioritization, and remediation; penetration testing and red teaming; and attack surface discovery, risk analysis, and remediation.
- Partner with peer domain leaders and practitioners to understand, align, integrate, collaborate, etc. on AI initiatives that realize value to Cyber Defense, Global Enterprise Security, and the business at large.
- Demonstrated experience developing and maturing service, tooling, and process automation.
- Routinely stays up to date on current best practices / trends to identify, document, and drive resolution of security exposures through independent and collaborative industry research.
- Proven ability to influence change and drive the adoption of automation, AI, and agentic AI to applicable domain programs and teams.
- At CNA, we strive to create a culture in which people know they matter and are part of something important, ensuring the abilities of all employees are used to their fullest potential.
Requirements
- Strong understanding of security vulnerabilities and threats and industry standard methodologies of risk managing exposures effectively.
- Bachelor's Degree required or equivalent work experience. Master's Degree in Computer Science or technical field preferred.
Compensation
- I n certain jurisdictions, CNA is legally required to include a reasonable estimate of the compensation for this role.
This listing is sourced directly from CNA's careers page and normalized into a canonical job model.