Turn this role into an interview — a resume and cover letter built around what this employer wants.
CNA is seeking a Consulting Director, Attack Surface Management to shape strategy and governance for automation, AI, and agentic AI across security programs. You’ll drive AI-enabled risk identification, remediation, and secure development practices while partnering with senior leadership to improve efficiency and outcomes.
The role emphasizes defining strategy, deploying AI-centric solutions, and providing metrics to ensure regulatory alignment and program maturity in a hybrid work environment.
You have a clear vision of where your career can go. And we have the leadership to help you get there. At CNA, we strive to create a culture in which people know they matter and are part of something important, ensuring the abilities of all employees are used to their fullest potential.
The Consulting Director, Attack Surface Management defines strategy, adoption, and governance of automation, AI, and agentic AI across application security, vulnerability management, ethical hacking, and attack surface management programs. Oversees evaluation and deployment of AI-centric security solutions while establishing audit-defensible standards, processes, and secure AI development practices. Drives enterprise-scale identification, analysis, and remediation of external attack surface risk through advanced automation, analytics, and AI-enabled capabilities. Partners with senior leadership and cross-functional teams to prioritize risk, improve operational efficiency, and deliver measurable security outcomes. Provides expert guidance, metrics, and reporting to ensure effective risk management, regulatory alignment, and continuous program maturity.
Reporting Relationship Typically reports to Director or above.
In depth understanding of Vulnerability Management, Application Security, Cloud Security, Ethical Hacking, Threat Management, and Security Remediation programs and operations. Strong working knowledge of AI/ML, GenAI, LLM, and agentic AI security concepts, common attack/defense techniques, and use to solve application security, vulnerability management, and ethical hacking domain problems. Demonstrated experience developing and maturing service, tooling, and process automation. Demonstrated experience in software development and/or scripting. Strong understanding of security vulnerabilities and threats and industry standard methodologies of risk managing exposures effectively. Superior analytical and problem-solving skills and the ability to effectively communicate highly technical information to all audiences. Proven ability to interact effectively with senior business leadership to effectively address vulnerabilities and threats in a priority manner. Working knowledge of regulations (e.g., SOX, privacy, etc.) and internal controls as they apply to IT. Routinely stays up to date on current best practices / trends to identify, document, and drive resolution of security exposures through independent and collaborative industry research. Proven ability to influence change and drive the adoption of automation, AI, and agentic AI to applicable domain programs and teams. Ability to work extremely well under pressure while maintaining a professional image and approach.
Bachelor’s Degree required or equivalent work experience. Master’s Degree in Computer Science or technical field preferred. Typically, a minimum of ten years of information security or related work experience in one or more of the following: application security, vulnerability management or exposure management, ethical hacking, penetration testing, attack surface management, security engineering, or security architecture. Relevant certifications preferred. #LI-Hybrid #LI-DM1
In certain jurisdictions, CNA is legally required to include a reasonable estimate of the compensation for this role. In District of Columbia, California, Colorado, Connecticut, Illinois, Maryland, Massachusetts, New York and Washington, the national base pay range for this job level is $97,000 to $189,000 annually. Salary determinations are based on various factors, including but not limited to, relevant work experience, skills, certifications and location.
CNA offers a comprehensive and competitive benefits package to help our employees – and their family members – achieve their physical, financial, emotional and social wellbeing goals. For a detailed look at CNA’s benefits, please visit cnabenefits.com.
CNA utilizes AI-enabled technology during the recruiting process. For more information, please visit our careers page.
CNA is committed to providing reasonable accommodations to qualified individuals with disabilities in the recruitment process. To request an accommodation, please contact leaveadministration@cna.com
At CNA, we are focused on success, individually and collectively. We pride ourselves on promoting a culture that challenges and engages people. We strive to connect people, departments and business areas, to function as a team, and to serve our customers and communities with professionalism and respect. Our dedication to employee engagement, continuous learning and the open exchange of ideas is the cornerstone of our business. These ideals, combined with our focus on the customer, enable us to explore new market opportunities and build on our success. Our values, culture and financial strength are what differentiates us from other employers and make CNA the place you want to work.
At CNA, we are committed to advancing a culture of inclusion – one that attracts talent from all walks of life, fosters respect and collaboration, and enables all of our colleagues to do their best work. At CNA, we have a long standing commitment to the diverse communities in which we live and work. We actively make a difference for the greater good through partnerships, sustainability, initiatives, and working together for a better tomorrow. Corporate Social Responsibility is not one person, or one department, it's the entire enterprise coming together to make the world a better place.