Product Security Analyst (Vulnerability Operations Focus)
Teknik, data och digitalt · IT-infrastruktur och säkerhet · Cybersäkerhet · Mjukvaruutveckling · Datavetenskap
I korthet
Synopsys is seeking a Product Security Analyst with a focus on Vulnerability Operations in Greece. This role involves managing the end-to-end vulnerability lifecycle, utilizing AI agents for triage and enrichment, and driving remediation efforts. The ideal candidate has 3-6 years of experience in PSIRT or Product Security, a strong understanding of vulnerability management processes, and an interest in AI/automation in security operations.
Ansvarsområden
- Manage the end-to-end vulnerability lifecycle: intake, triage, validation, tracking, remediation, and disclosure.
- Operate within and help evolve processes ensuring consistency and quality in incident response.
- Serve as a primary point of contact for vulnerability coordination, working closely with product teams, engineering, legal, and communications.
- Perform technical triage and risk assessment, including CVSS scoring, CWE assignment, and exploitability analysis.
- Leverage AI agents and assistants to normalize and deduplicate vulnerability intake, enrich findings with threat intelligence, generate triage summaries, and assist in root cause analysis.
- Drive remediation efforts by partnering with product and engineering teams.
- Support coordinated vulnerability disclosure (CVD) processes.
- Contribute to a VulnOps model by improving prioritization, automation, and scalability of vulnerability handling.
- Assist in the development of playbooks, workflows, and AI-enabled tooling.
- Participate in security advisories and customer communications.
- Support incident response efforts for product-related security issues.
- Contribute to discussions on modernizing PSIRT, including leveraging AI to support scale, speed, and frontier technologies.
Krav
- Degree in Cybersecurity, Computer Science, Engineering, or related field (or equivalent experience).
- 3–6 years of experience in PSIRT or Product Security.
- Strong understanding of vulnerability management processes and standards (e.g., CVSS, CWE, CVE, FIRST.org PSIRT Framework).
- Familiarity coordinated vulnerability disclosure practices and CVE Numbering Authority (CAN).
- Exposure to or interest in AI/automation in security operations, including use of assistants, copilots, or workflow automation tools.
Önskade kvalifikationer
- Understanding of cloud, SaaS, and modern application architectures (preferred).
- Experience with scripting, APIs, or data analysis (Python or similar) is a plus.
- Security certifications (e.g., OSCP, CEH, CSSLP) are a plus but not required.
Förmåner
- Competitive salaries.
- Comprehensive medical and healthcare plans.
- ETO and FTO Programs (Time Away).
- Maternity and paternity leave, parenting resources, adoption and surrogacy assistance.
- ESPP (Purchase Synopsys common stock at a 15% discount, with a 24 month look-back).
- Retirement Plans.
- Benefits vary by country and region.
#cybersecurity#product security#vulnerability management#incident response#automation#AI