Hiring.Camp

Lead Info Sec Vulnerability

TIAA started out over

·

Today

Location
3965 Dallas Parkway Frisco, TX 75034, United States of America · Charlotte, NC, USA · Iselin, NJ, USA
Workplace
Hybrid
Type
Full-time
Seniority
Lead
Experience
5+ years
Closing date
Today
Source
Workday

Description

The Lead Information Security Vulnerability role leads the integration of AI into vulnerability management operations while driving triage of findings generated from AI-enabled scans. As a subject matter expert in vulnerability assessment, this role advises on corrective actions and risk-based prioritization, and serves as a hands-on builder of the AI capabilities powering the program — including developing AI-driven scanning workflows, building AI-based validation agents, and maturing future agentic efforts. This is an individual-contributor role that bridges traditional vulnerability management with emerging AI-driven capabilities, ensuring findings are accurately validated, prioritized, and remediated at machine speed.

Key Responsibilities and Duties

  • Builds and matures AI-enabled vulnerability scanning capabilities using AI development tools and platforms, helping develop and strengthen the team's skills and repeatable practices for AI-driven scans.
  • Designs, builds, and iterates on AI-based validation agents (e.g., verification of scan findings, SAST verification) to improve accuracy and reduce false positives at scale.
  • Leads the triage, validation, and prioritization of vulnerability findings generated from AI-enabled identification tools, defining validation criteria and triage standards.
  • Drives the integration of AI and agentic capabilities into vulnerability management BAU, improving the speed, accuracy, and scale of identification, prioritization, and remediation workflows.
  • Develops standardized evaluation criteria to benchmark performance across testing harnesses, LLM providers, and iterations, ensuring AI processes are repeatable and sustainable for new applications.
  • Advises management on vulnerability corrections and risk-based prioritization, producing reports that outline findings, intrusion paths, and recommended remediation.
  • Supports the advancement of AI vulnerability identification and verification from proof-of-concept to production, including evaluation of AI scanning harnesses and approaches.
  • Contributes to risk-based prioritization models (asset criticality, EPSS, CISA KEV, risk scoring) that drive remediation sequencing within the Unified Vulnerability Management (UVM) program.
  • Determines causes and exploitation methods of identified vulnerabilities, and analyzes complex software systems and findings to assess functionality, intent, and exploitability.
  • Designs and implements process automation and tooling specific to cyber and vulnerability operations.
  • Collaborates with threat intelligence, remediation, AI, platform, and application teams to ensure timely resolution of critical and high-severity vulnerabilities within defined SLAs.
  • Serves as a technical resource and mentor to vulnerability management practitioners, sharing AI tooling practices and consistent triage approaches (no direct reports).
  • Leads and participates in future AI-driven vulnerability management initiatives that build on these capabilities as the program evolves.

Educational Requirements

  • University (Degree) Preferred

Work Experience

  • 5+ Years Required; 7+ Years Preferred

Physical Requirements

  • Physical Requirements: Sedentary Work


Career Level
8IC

Required Qualifications

  • 5+ years of experience in information security, vulnerability management, assessment, or related security operations.
  • Experience and understanding of vulnerability prioritization frameworks (CVSS, EPSS, CISA KEV) and risk-based remediation.

 

Preferred Qualifications

  • Experience building with AI development tools and/or platforms (e.g., LLM- and agent-based tooling), including developing, prompting, and/or iterating on AI-driven workflows or agents.
  • 7+ years of experience in information security or vulnerability management.
  • Ability to work independently as an individual contributor across infrastructure, application, cloud, and container security contexts.
  • Familiarity with vulnerability scanning and management platforms (e.g., Tenable, Wiz) and findings triage.
  • Experience building or evaluating AI-based validation/verification agents and developing evaluation criteria for LLM/agent performance.
  • Familiarity with agentic operating models, SAST/DAST/SCA tooling (e.g., Snyk), ServiceNow, and CI/CD pipeline integration.
  • Relevant certifications a plus but not required (e.g., CISSP, GWAPT, GCIH, OSCP).
  • Experience mentoring or guiding security practitioners.

Related Skills

Accountability, Adaptability, Business Continuity Planning, Cloud Computing Security, Collaboration, Communication, Compliance, Consultative Communication, Cybersecurity, Detail-Oriented, General Risk Management, Network Security, Prioritizes Effectively

Anticipated Posting End Date:

2026-10-13

Base Pay Range: $116,000/yr - $152,000/yr

Actual base salary may vary based upon, but not limited to, relevant experience, time in role, base salary of internal peers, prior performance, business sector, and geographic location.  In addition to base salary, the competitive compensation package may include, depending on the role, participation in an incentive program linked to performance (for example, annual discretionary incentive programs, non-annual sales incentive plans, or other non-annual incentive plans). 

_____________________________________________________________________________________________________

Company Overview

Every worker deserves a secure retirement. For more than 100 years, TIAA has delivered it for millions of people. Founded to help educators retire with dignity, today weʼre a market-leading retirement company fueled by world-class asset management. But weʼre not just another legacy financial services firm. Weʼre fighting harder than ever before for our clients and the many Americans who need us.

Our Culture of Impact

At TIAA, we're on a mission to build on our 100+ year legacy of delivering for our clients while evolving to meet tomorrow's challenges. We equip our associates with future-focused skills and AI tools that enable us to advance our mission. Together, we are fighting to ensure a more secure financial future for all and for generations to come. We are guided by our values: Champion Our People, Be Client Obsessed, Lead with Integrity, Own It, and Win As One. They influence every decision we make and how we work together to serve our clients every day. We thrive in a collaborative in-office environment where teams work across organizational boundaries with shared purpose, accelerating innovation and delivering meaningful results. Our workplace brings together TIAA and Nuveen's entrepreneurial spirit, where we work hard and work together to create lasting impact. Here, every associate can grow through meaningful learning experiences and development pathways—because when our people succeed, our impact on clients' lives grows stronger.

Benefits and Total Rewards

The organization is committed to making financial well-being possible for its clients, and is equally committed to the well-being of our associates. That’s why we offer a comprehensive Total Rewards package designed to make a positive difference in the lives of our associates and their loved ones. Our benefits include a superior retirement program and highly competitive health, wellness and work life offerings that can help you achieve and maintain your best possible physical, emotional and financial well-being. To learn more about your benefits, please review our Benefits Summary.

Equal Opportunity

We are an Equal Opportunity Employer. TIAA does not discriminate against any candidate or employee on the basis of age, race, color, national origin, sex, religion, veteran status, disability, sexual orientation, gender identity, or any other legally protected status.

Our full EEO & Non-Discrimination statement is on our careers home page, and you can read more about your rights and view government notices here.

Accessibility Support

TIAA offers support for those who need assistance with our online application process to provide an equal employment opportunity to all job seekers, including individuals with disabilities. 

If you are a U.S. applicant and desire a reasonable accommodation to complete a job application please use one of the below options to contact our accessibility support team: 

Phone: (800) 842-2755

Email: [email protected]

Drug and Smoking Policy

TIAA maintains a drug-free and smoke/free workplace.

Privacy Notices

For Applicants of TIAA, Nuveen and Affiliates residing in US (other than California), click here.

For Applicants of TIAA, Nuveen and Affiliates residing in California, please click here.

For Applicants of TIAA Global Capabilities, click here.

For Applicants of Nuveen residing in Europe and APAC, please click here.

Skills

CI/CDServiceNowCybersecurityRisk ManagementComplianceCISSP

Similar Jobs

2

Lead Info Security Engineer

Icwgroup·Innovation Point, US

1w ago

Sr Info Systems Security Manager / Fleet Support Lead

Scires·Goodfellow AFB, TX

4w ago