CNA

CNA

AI Attack Surface and Threat Exposure Management Consulting Director

Chicago, IL, USA · Director

Sponsorship not specified$97k-$189kDetected 13 days ago
Code ReviewMachine LearningLLMsAgentic AICybersecurityPenetration TestingComplianceLeadershipCommunicationProblem SolvingInternal Audit

About the role

  • You have a clear vision of where your career can go.
  • And we have the leadership to help you get there.
  • The Consulting Director, Attack Surface Management defines strategy, adoption, and governance of automation, AI, and agentic AI across application security, vulnerability management, ethical hacking, and attack surface management programs.

Responsibilities

  • Evaluate, deploy, manage, and govern best-in-class new and existing AI-centric solutions, services, and capabilities relevant to the application security, ethical hacking, and vulnerability management domains.
  • Identify, prioritize, and drive high-value outcomes where automation and AI can improve operational effectiveness, speed, scale, and efficiency.
  • Develop and contribute to audit-defensible governance, standards, processes, procedures, methodologies, practices, playbooks, etc. for secure AI adoption and use across application security, vulnerability management, and ethical hacking domains.
  • Lead identification and risk analysis of the external attack surface through development and continuous improvement of automation to drive effective risk exposure response across the business.
  • Drive the use of AI to improve threat modeling, code review, and application security testing; vulnerability analysis, prioritization, and remediation; penetration testing and red teaming; and attack surface discovery, risk analysis, and remediation.
  • Partner with peer domain leaders and practitioners to understand, align, integrate, collaborate, etc. on AI initiatives that realize value to Cyber Defense, Global Enterprise Security, and the business at large.
  • Demonstrated experience developing and maturing service, tooling, and process automation.
  • Routinely stays up to date on current best practices / trends to identify, document, and drive resolution of security exposures through independent and collaborative industry research.
  • Proven ability to influence change and drive the adoption of automation, AI, and agentic AI to applicable domain programs and teams.
  • At CNA, we strive to create a culture in which people know they matter and are part of something important, ensuring the abilities of all employees are used to their fullest potential.

Requirements

  • Strong understanding of security vulnerabilities and threats and industry standard methodologies of risk managing exposures effectively.
  • Bachelor's Degree required or equivalent work experience. Master's Degree in Computer Science or technical field preferred.

Compensation

  • I n certain jurisdictions, CNA is legally required to include a reasonable estimate of the compensation for this role.

This listing is sourced directly from CNA's careers page and normalized into a canonical job model.