AI Attack Surface and Threat Exposure Management Consulting Director

CNA Financial

Confirmed live 2 days ago High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Chicago, IL
Salary
$97,000–$189,000 / yr
Posted
39 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $201k
This role $143k
$79k most similar roles pay here $260k

This role pays less than 87% of similar roles. Most pay $162,655–$239,512 — the shaded band above. At the midpoint, this role pays about $143k versus about $201k for comparable roles.

Based on 240 similar postings.

Employer

About CNA Financial

CNA Financial is a Chicago-based commercial property and casualty insurance company, offering business insurance and risk-management services to companies across the United States and internationally.

CNA Financial currently has 18 open roles on FindRole.

Listed pay typically runs $97,000–$189,000 across 15 roles with salary data.

Most-posted roles

View all roles at CNA Financial

At a glance

TL;DR · AI Attack Surface and Threat Exposure Management Consulting Director

The AI Attack Surface and Threat Exposure Management Consulting Director leads the strategy, adoption, and governance of automation, AI, and agentic AI across application security, vulnerability management, ethical hacking, and attack surface management programs. This role involves evaluating and deploying AI-centric solutions while establishing audit-defensible standards and secure development practices for tools involving prompts, workflows, and guardrails. The position focuses on identifying and remediating external attack surface risks through advanced automation and analytics to improve operational efficiency. Key technical competencies include a deep understanding of vulnerability management, cloud security, and threat management, alongside strong knowledge of GenAI, LLM, and agentic AI security concepts. Candidates must possess experience in software development or scripting to drive the use of AI for threat modeling, code review, penetration testing, and automated risk analysis across the enterprise.

What you'll do

  • Define and implement strategies for integrating automation, AI, and agentic AI into application security and vulnerability management programs.
  • Evaluate, deploy, and govern AI-centric solutions across ethical hacking and attack surface management domains.
  • Establish audit-defensible governance standards, playbooks, and processes for secure AI adoption and usage.
  • Develop secure AI development practices including guardrails, prompts, and workflows to ensure code adheres to security standards.
  • Identify and analyze external attack surface risks through the continuous improvement of automated tools and analytics.
  • Drive the use of AI to enhance threat modeling, code review, penetration testing, and vulnerability remediation.
  • Provide metrics, reporting, and expert guidance to senior leadership regarding risk management and regulatory alignment.

What we're looking for

  • Bachelor’s Degree required or equivalent work experience.
  • Master’s Degree in Computer Science or technical field (preferred).
  • Relevant certifications (preferred).
  • Minimum of ten years of information security or related work experience in fields such as application security, vulnerability management, ethical hacking, or security engineering.
  • In-depth understanding of Vulnerability Management, Application Security, Cloud Security, Ethical Hacking, Threat Management, and Security Remediation programs.
  • Strong working knowledge of AI/ML, GenAI, LLM, and agentic AI security concepts and common attack/defense techniques.
  • Demonstrated experience in software development, scripting, and developing or maturing service, tooling, and process automation.
  • Working knowledge of regulations such as SOX and privacy, along with internal controls as they apply to IT.

More like this

Similar roles

AI Security Program Lead

Micron Technology

Boise, ID 24 days ago
AI Security LLMs RAG Frameworks Threat Modeling Incident Response Prompt Injection Testing Security Architecture Risk Management Model Risk Management Adversarial Attack Simulation
5+ yrs exp

AI Security Consulting Director

CNA Financial

Chicago, IL 65 days ago $97,000$189,000
AI Machine Learning Generative AI LLM AWS Google Cloud DevSecOps CI/CD SDLC NIST AI RMF OWASP Top 10 for LLMs MITRE ATLAS Threat Modeling Vulnerability Management
5+ yrs exp Hybrid

AI Identity and Access Management Consulting Director

CNA Financial

Chicago, IL 17 days ago $97,000$189,000
Okta SailPoint CyberArk AI GenAI Cloud IAM RBAC ABAC Automation Orchestration Security Architecture Identity Governance Provisioning Audit Compliance
10+ yrs exp Hybrid

Director, Vulnerability Management & Security Configuration

Northern Trust

Chicago, IL 100 days ago $164,600$288,000
Vulnerability Management Security Configuration Cloud Security DevSecOps CTEM Risk-based Prioritization Automation Threat Intelligence Configuration Management Hardening Baselines Continuous Monitoring Drift Detection
10+ yrs exp

Director, Information Security Office AI/ML

Capital One Financial

McLean, VA +2 93 days ago $269,100$307,200
Generative AI Cloud Services Docker Microservices Serverless APIs DevOps SIEM SOAR Linux Unix Windows AWS Azure GCP Cyber Security Operations Data Analysis
7+ yrs exp

Principal Applied Threat Intelligence Manager

Microsoft

Redmond, WA +1 36 days ago $142,800$274,800
Threat Intelligence AI Large Language Models MITRE ATT&CK Cyber Kill Chain Diamond Model Python PowerShell C# C++ Reverse-engineering Anomaly Detection Vulnerability Research Network Protocols Incident Response
10+ yrs exp