Vice President, AI Vulnerability Operations

Socket.dev

O’Fallon (MO)

On-site

USD 212,000 - 339,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
401k with company match
Paid time off
Tuition reimbursement

Job summary

Mastercard seeks a seasoned executive to lead AI Vulnerability Operations, building and running a 24/7 command center that detects, triages, and remediates AI-driven vulnerabilities across development and runtime environments.

The VP will partner with engineering, risk, product, and regional teams to translate findings into measurable risk reduction, establish governance, and deliver enterprise metrics from the US security program in a fast-moving environment.

Qualifications

  • 15+ years in cybersecurity or related enterprise security leadership roles.
  • Experience leading large-scale security or technology risk functions with accountability for strategy, execution, metrics, governance, and stakeholder outcomes.
  • Strong understanding of vulnerability management, cloud security, software supply-chain risk, remediation operations and continuous detection.
  • Demonstrated ability to operationalize AI, automation, analytics, and command center concepts into repeatable enterprise processes.
  • Executive communication skills to translate complex risk into clear priorities, decisions and expectations.
  • Strong cross-functional influence with engineering, risk, audit, legal, sourcing, and business stakeholders.

Responsibilities

  • Set the enterprise strategy for AI Vulnerability Operations and the AI-Powered Vulnerability Command Center, including scope, governance, and global execution.
  • Define end-to-end lifecycle: detection, validation, triage, prioritization, ownership, remediation, and verified closure.
  • Establish 24/7 operating cadence, service levels, escalation paths, and global coverage.
  • Lead a multidisciplinary organization spanning command center operations, security engineering, analytics, and remediation coordination.
  • Translate command center performance into executive risk narratives, dashboards, and investment priorities.

Job description

Our Purpose

Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build asustainableeconomy where everyone can prosper. We support a wide range of digital payments choices, making transactionssecure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.

Title and Summary

Vice President, AI Vulnerability OperationsVice President, AI Vulnerability Operations

About the Role

We are transforming vulnerability management for the AI era. Frontier models and agentic systems are changing the speed, scale, and economics of vulnerability discovery, creating new defensive opportunities and operational demands. This role leads the organization responsible for turning AI-discovered vulnerabilities into measurable enterprise risk reduction. As Vice President, AI Vulnerability Operations, you will lead the enterprise AI-Powered Vulnerability Command Center, owning strategy, operating model, governance, and global execution for continuous vulnerability detection and response. You will build a high-performing organization that integrates AI-driven detection, triage, prioritization, and coordinated response across development and runtime environments, connecting technical findings to accountable remediation across engineering, infrastructure, platform, application security, risk, and business teams. This is a senior leadership role for someone who can set enterprise direction, scale operating discipline, influence senior stakeholders, and drive outcomes through teams. The VP will lead the charge to make AI Vulnerability Operations a durable, trusted, measurable function embedded into how the company manages technology risk. The mandate is to move beyond experimentation and establish a 24/7 command center capability that continuously identifies exploitable risk, accelerates decisions, coordinates response across regions and platforms, and gives leadership clear visibility into exposure, remediation progress, and risk reduction.

What You’ll Do
Enterprise Strategy & Operating Model
  • Set the enterprise strategy for AI Vulnerability Operations and the AI-Powered Vulnerability Command Center, including scope, priorities, governance, operating principles, global execution model, and success measures.
  • Define how AI-discovered vulnerabilities move from detection to validation, triage, risk prioritization, ownership assignment, coordinated response, remediation, exception handling, and verified closure.
  • Establish the organizational model, decision rights, escalation paths, service levels, and 24/7 operating cadence required to operate at enterprise scale.
  • Prioritize coverage across critical services, externally exposed assets, high-risk applications, development and runtime environments, third-party and open-source components, cloud environments, and other material technology risk areas.
Organizational Leadership & Execution
  • Build, lead, and develop a multidisciplinary organization spanning command center operations, technical program management, vulnerability operations, security engineering, automation, analytics, and remediation coordination.
  • Drive operational excellence through clear intake, triage, prioritization, case management, remediation tracking, reporting, quality control, and rapid decision-making.
  • Turn model-generated signal into accountable action while managing false positives, duplicate findings, noise, escalation paths, and remediation fatigue.
  • Develop leaders and managers, establishing a culture of urgency, discipline, technical credibility, global coordination, and partnership with engineering teams.
AI-Enabled Vulnerability Operations
  • Lead AI-enabled discovery and continuous vulnerability detection across source code, open-source dependencies, infrastructure-as-code, cloud configurations, applications, services, development and runtime environments, and enterprise platforms.
  • Partner with security architecture, application security, product security, platform engineering, infrastructure, regional technology teams, and technology leadership to embed AI vulnerability operations into delivery, monitoring, incident response, and remediation workflows.
  • Oversee standards for validation, severity calibration, exploitability assessment, reachability analysis, prioritization, remediation guidance, and closure verification.
Governance, Risk & Executive Engagement
  • Translate command center performance into executive-level risk narratives, metrics, investment priorities, and decision points.
  • Establish dashboards and reporting that show exposure, coverage, detection volume, triage outcomes, remediation performance, aging risk, exceptions, and progress against enterprise priorities.
  • Serve as a senior escalation point for major vulnerability campaigns, systemic risk themes, coordinated response actions, remediation blockers, and ownership challenges.
  • Represent the function with senior technology, security, risk, audit, legal, sourcing, business, regional, and platform stakeholders.
What You Bring
Required
  • 15+ years in cybersecurity, technology risk, vulnerability management, application security, security operations, incident response, or related enterprise security leadership roles.
  • Experience leading large-scale security or technology risk functions with accountability for strategy, execution, operating discipline, metrics, governance, and stakeholder outcomes.
  • Strong understanding of vulnerability management, application security, cloud security, software supply-chain risk, remediation operations, continuous detection, response coordination, and enterprise risk prioritization.
  • Demonstrated ability to operationalize emerging capabilities, including AI, automation, analytics, command center operations, or advanced security tooling, into repeatable enterprise processes.
  • Executive communication skills, with the ability to translate complex technical risk into clear priorities, decisions, operating expectations, and tradeoffs.
  • Strong cross-functional influence with engineering, infrastructure, product, security, risk, audit, legal, sourcing, regional, platform, and business stakeholders.
Strongly Preferred
  • Experience leading vulnerability management, product security, application security, security operations, PSIRT, or software supply-chain security in a large enterprise.
  • Experience using AI, machine learning, automation, or agentic workflows to improve security operations, vulnerability discovery, triage, or remediation.
  • Background in a regulated, high-assurance environment such as financial services, payments, government, healthcare, or critical infrastructure.
  • Familiarity with CVSS, EPSS, KEV, OWASP, MITRE ATT&CK, NIST, secure software development practices, and software supply-chain risk frameworks.
  • Track record building new enterprise capabilities, influencing senior stakeholders, and improving measurable risk outcomes across complex organizations.
What Success Looks Like in the First 12 Months
  • Approved enterprise strategy and operating model for AI Vulnerability Operations and the AI-Powered Vulnerability Command Center, with clear scope, governance, roles, metrics, escalation paths, and executive sponsorship.
  • Staffed and functioning 24/7 command center capability that continuously detects, intakes, validates, triages, prioritizes, assigns, tracks, and drives AI-discovered vulnerabilities through coordinated response and verified closure.

Mastercard is a merit-based, inclusive, equal opportunity employer that considers applicants without regard to gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law. We hire the most qualified candidate for the role. In the US or Canada, if you require accommodations or assistance to complete the online application process or during the recruitment process, please contact reasonable_accommodation@mastercard.com and identify the type of accommodation or assistance you are requesting. Do not include any medical or health information in this email. The Reasonable Accommodations team will respond to your email promptly.

Corporate Security Responsibility
  • Abide by Mastercard’s security policies and practices;

  • Ensure the confidentiality and integrity of the information being accessed;

  • Report any suspected information security violation or breach, and

  • Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines.

In line with Mastercard’s total compensation philosophy and assuming that the job will be performed in the US, the successful candidate will be offered a competitive base salary and may be eligible for an annual bonus or commissions depending on the role. The base salary offered may vary depending on multiple factors, including but not limited to location, job-related knowledge, skills, and experience. Mastercard benefits for full time (and certain part time) employees generally include: insurance (including medical, prescription drug, dental, vision, disability, life insurance); flexible spending account and health savings account; paid leaves (including 16 weeks of new parent leave and up to 20 days of bereavement leave); 80 hours of Paid Sick and Safe Time, 25 days of vacation time and 5 personal days, pro-rated based on date of hire; 10 annual paid U.S. observed holidays; 401k with a best-in-class company match; deferred compensation for eligible roles; fitness reimbursement or on-site fitness facilities; eligibility for tuition reimbursement; and many more. Mastercard benefits for interns generally include: 56 hours of Paid Sick and Safe Time; jury duty leave; and on-site fitness facilities in some locations.

Pay Ranges

O'Fallon, Missouri: $212,000 - $339,000 USD

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vice President, AI Vulnerability Operations
Vice President, AI Vulnerability Operations

MasterCard • O’Fallon (MO)

On-site
USD 212,000 - 339,000
Insurance
401k with company match
Paid time off
Principle, Vulnerability Analyst
Principle, Vulnerability Analyst

Mastercard • O’Fallon (MO)

On-site
USD 152,000 - 258,000
Health insurance
Dental insurance
Vision insurance
+6
Principle, Vulnerability Analyst
Principle, Vulnerability Analyst

Socket.dev • O’Fallon (MO)

On-site
USD 152,000 - 258,000
Vice President, Information Security Engineering
Vice President, Information Security Engineering

Socket.dev • Arlington (VA)

On-site
USD 244,000 - 390,000
Mastercard Director - AI Development Engineer
Mastercard Director - AI Development Engineer

lwtsquad • O’Fallon (MO)

On-site
USD 165,000 - 264,000
Comprehensive health insurance
401(k) with company match
Generous paid leave policies
+1
Manager ForwardDeployed AI Engineer AI Mobilization Transformation
Manager ForwardDeployed AI Engineer AI Mobilization Transformation

Mastercard • Purchase (NY)

On-site
USD 161,000 - 266,000
Lead Software Development Engineer
Lead Software Development Engineer

Mastercard • O’Fallon (MO)

On-site
USD 140,000 - 231,000
Medical Insurance
401(k) Match
Paid Leave
+1
Vice President Platform Engineering
Vice President Platform Engineering

Mastercard • O’Fallon (MO)

On-site
USD 200,000 - 330,000
Health insurance
401(k) match
Paid time off
Vice President, Software Supply Chain Security
Vice President, Software Supply Chain Security

Mastercard • O’Fallon (MO)

On-site
USD 212,000 - 339,000
Director, Project Management (AI)
Director, Project Management (AI)

Mastercard • O’Fallon (MO)

On-site
USD 143,000 - 236,000
Medical insurance
401k match
Paid leave & holidays
+2