Cyber - AI-Enabled Vulnerability Management - Senior - Consulting
Listed on 2026-09-30
-
IT/Tech
Cybersecurity, AI Business & Operations
Location:
Anywhere in Country
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
The OpportunityClients across every industry look to us for trusted solutions to increasingly complex threats. As a Senior in AI-Enabled Vulnerability Management, you’ll help them move from scan-and-patch cycles to continuous threat exposure management (CTEM) — applying AI across the vulnerability lifecycle and building the automation that makes it repeatable. You’ll also help clients extend their programs to cover the AI systems they’re adopting.
Yourkey responsibilities
As a Senior on the Vulnerability Management team, you would:
Design and operate AI-enabled vulnerability and exposure management capabilities across cloud, on-premises, container, application, and endpoint environments.
Build the asset data foundation the program depends on — identity resolution, CMDB reconciliation, and deduplication across overlapping scanner coverage.
Drive risk-based prioritization using threat intelligence, exploit prediction, known-exploited-vulnerability data, reachability, and business criticality.
Build and tune AI and agentic workflows that triage findings, generate remediation guidance, and drive closure through orchestrated patching, IaC, and validated fixes.
Measure what the AI produces — benchmarking triage against human baselines and tracking false-positive reduction and time-to-remediate.
Apply guardrails, human-in-the-loop thresholds, and auditability to AI-generated actions in client environments.
Help clients extend vulnerability management to their AI systems, covering model, prompt, integration, and supply chain weaknesses.
Mentor junior team members and contribute reusable accelerators that outlast a single engagement.
You’ll need a blend of technical and business skills, along with the judgment to navigate complex problems and make informed decisions.
Human-forward skills — empathy, curiosity, adaptability, and clear communication.
Advanced problem-solving and critical thinking.
Sound judgment in validating AI output, including spotting false positives and unsupported findings.
A builder’s instinct — a preference for creating something reusable over configuring a tool once.
Digital and learning agility in adopting new AI tooling.
A platform-agnostic mindset, evaluating tooling based on client need rather than a single vendor stack.
3-5 years of relevant experience in vulnerability or exposure management. No bachelor’s degree required.
Hands‑on experience across the full VM lifecycle — discovery, data quality, prioritization, remediation tracking, validation, and reporting — using platforms such as Tenable, Qualys, Rapid7, Wiz, Microsoft Defender, or equivalent.
Experience applying risk‑based prioritization using severity scoring, exploit prediction, threat context, and asset criticality.
Demonstrated aptitude for applying AI or machine learning to vulnerability management — in production, through experimentation, or via adjacent automation work — with scripting and API integration proficiency (Python, Power Shell, or similar).
A relevant certification in AI security, vulnerability management, or cybersecurity, or the ability to acquire one after employment.
Production experience using AI to reduce vulnerability noise at scale.
Experience benchmarking or evaluating AI‑assisted security workflows.
Experience with automated remediation — patch orchestration, IaC fixes, or pull‑request‑generated fixes with rollback.
Experience assessing or securing AI…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).