Back to jobs
Duke Energy

Lead Cybersecurity Threat and Vulnerability Analyst

Charlotte, NC

What you’ll work on

Full posting
  • Develop and mature AI Attack Surface Management capabilities, including discovery, inventory, monitoring, assessment, and prioritization of AI-related risks.

  • Partner with AI Governance, Cyber Architecture, Enterprise Architecture, and Technology teams to establish security requirements, standards, and controls for AI deployments.

  • Support architecture reviews and risk assessments for emerging AI initiatives.

From the employer’s posting
Serve as the cybersecurity subject matter expert for AI technologies deployed across the enterprise. Develop and mature AI Attack Surface Management capabilities, including discovery, inventory, monitoring, assessment, and prioritization of AI-related risks. Evaluate risks associated with AI applications, AI agents, Large Language Models (LLMs), Retrieval Augmented Generation (RAG) implementations, third-party AI platforms, and AI-enabled business processes.
Assess security threats including prompt injection, model manipulation, insecure integrations, excessive permissions, data leakage, unauthorized AI use, and AI supply chain risks. Partner with AI Governance, Cyber Architecture, Enterprise Architecture, and Technology teams to establish security requirements, standards, and controls for AI deployments. Support architecture reviews and risk assessments for emerging AI initiatives.
Partner with AI Governance, Cyber Architecture, Enterprise Architecture, and Technology teams to establish security requirements, standards, and controls for AI deployments. Support architecture reviews and risk assessments for emerging AI initiatives. Monitor evolving AI threats, vulnerabilities, attack techniques, and industry best practices.

See how this role fits your experience

Add your resume to compare the role’s scope, tools and requirements with your experience.

Pay, work setup, and employment type unconfirmed

Not confirmed in this saved copy: pay, work setup, employment type. Check the full posting

Find answers in the posting

AI
How answers work

AI selects complete passages from this posting. Check them for conditions and exceptions.

Uses this posting and your question. No profile needed.

Already applied? Track this application

About applying

Apply opens the employer’s site in a new tab. Add your outcome here after you submit.

Source details & eligibility

Before you apply

Source excerpts

Selected passages from the saved posting. Check the full description for conditions and exceptions.

Pay

No pay amount identified in the saved description.

Location & working pattern

Charlotte, NC

Working Conditions - Hybrid Mobility Classification – Work will be performed from both remote and onsite locations after the onboarding period. However, hybrid employees should live within a reasonable daily commute to a Duke Energy facility. - Office Environment
More source context
#LI-ZM1 #LI-Hybrid Travel Requirements
Work authorization
No Visa Sponsored Position No. This is not a Visa Sponsored Position. This role requires the ability to work lawfully in the U.S. without employment-based immigration sponsorship, now or in the future. Please note that in order to be considered for this position, you must possess all of the basic/required qualifications.
Posting history
Status in our records
Active
First seen by us
Sep 9, 2026
Recorded sightings
1

These dates show when we found the listing. Check the employer’s website to confirm it is still accepting applications.

Report an error
Education & alternatives
Basic/Required Qualifications - Bachelor's degree in Cybersecurity, Computer Science, Engineering, Management Information Strategies (MIS), or Other Related experience. - 8 years Minimum Required Related Work Experience
- 8 years Minimum Required Related Work Experience - In lieu of Bachelors degree(s) AND 8 year(s) related work experience listed above, High School/GED AND 12 year(s) related work experience Desired Qualifications

Job description

Important Application Submission Information

In order to ensure your application is successfully received before the job posting expires, please submit your application by 11:59 PM on Saturday, September 19, 2026

More than a career - a chance to make a difference in people's lives.

Build an exciting, rewarding career with us – help us make a difference for millions of people every day. Consider joining the Duke Energy team, where you'll find a friendly work environment, opportunities for growth and development, recognition for your work, and competitive pay and benefits.

Job Summary

The Lead Cybersecurity Threat and Vulnerability Analyst serves as the technical lead for Duke Energy's emerging AI Attack Surface Management capability. This role is responsible for identifying, assessing, prioritizing, and mitigating risks associated with the use, development, deployment, and operation of Artificial Intelligence technologies across the enterprise. This position is expected to dedicate the majority of its focus to Artificial Intelligence security initiatives, including both the secure adoption of AI technologies and the assessment and management of risks associated with AI systems.

The position has a dual mission:

Security for AI: Secure AI applications, models, agents, data pipelines, and supporting infrastructure through risk assessment, security architecture review, governance integration, continuous validation, and threat-informed defense strategies.

AI for Security: Drive the adoption of AI-enabled capabilities that improve cybersecurity outcomes through automation, intelligence augmentation, risk prioritization, attack surface visibility, and remediation acceleration.

As a senior technical leader, this individual will partner closely with Cybersecurity, Enterprise Architecture, Cloud Security, Data & Analytics, AI Governance, Technology Delivery, and business stakeholders to establish and mature Duke Energy's AI Attack Surface Management program while enabling the secure adoption of transformative AI technologies.

Primary Responsibilities

Security for AI

  • Serve as the cybersecurity subject matter expert for AI technologies deployed across the enterprise.

  • Develop and mature AI Attack Surface Management capabilities, including discovery, inventory, monitoring, assessment, and prioritization of AI-related risks.

  • Evaluate risks associated with AI applications, AI agents, Large Language Models (LLMs), Retrieval Augmented Generation (RAG) implementations, third-party AI platforms, and AI-enabled business processes.

  • Assess security threats including prompt injection, model manipulation, insecure integrations, excessive permissions, data leakage, unauthorized AI use, and AI supply chain risks.

  • Partner with AI Governance, Cyber Architecture, Enterprise Architecture, and Technology teams to establish security requirements, standards, and controls for AI deployments.

  • Support architecture reviews and risk assessments for emerging AI initiatives.

  • Monitor evolving AI threats, vulnerabilities, attack techniques, and industry best practices.

  • Develop executive-level reporting and risk communication related to AI security posture.

AI for Security

  • Identify opportunities to leverage Artificial Intelligence and automation to improve cybersecurity operations.

  • Drive adoption of AI-enabled capabilities that improve vulnerability prioritization, attack surface visibility, ownership identification, remediation workflows, and security analytics.

  • Support development and enhancement of advanced security capabilities including risk-context engines, automated analysis pipelines, and intelligent security workflows.

  • Evaluate emerging AI security technologies and identify opportunities to improve cybersecurity effectiveness and operational efficiency.

  • Validate AI-driven recommendations and outputs to ensure alignment with enterprise risk management and cybersecurity requirements.

  • Develop performance metrics demonstrating measurable reductions in manual effort, improved prioritization accuracy, and accelerated remediation outcomes.

Attack Surface Management & Risk Prioritization

  • Support the evolution of Duke Energy's Attack Surface Management program across Internal, External, and AI Attack Surfaces.

  • Apply threat intelligence, exposure context, business criticality, and exploitability data to improve risk prioritization.

  • Support continuous validation initiatives and exposure management improvements.

  • Provide expertise in vulnerability management, threat intelligence, application security, cloud security, and emerging technology risk as they relate to AI adoption.

  • Assist with development of risk methodologies, metrics, and decision-support capabilities for cybersecurity leadership.

Leadership Expectations

  • Employees at this level are expected to:

  • Serve as a recognized subject matter expert in AI security and emerging cyber risk.

  • Lead highly complex cybersecurity initiatives with minimal supervision.

  • Influence strategic cybersecurity decisions across organizational boundaries.

  • Build partnerships across cybersecurity, technology, architecture, data, and business teams.

  • Develop scalable processes, automation opportunities, and innovative approaches to cyber risk reduction.

  • Translate complex technical risks into business-focused recommendations for senior leadership and executives.

  • Mentor other cybersecurity professionals and contribute to capability development across the organization.

Basic/Required Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Engineering, Management Information Strategies (MIS), or Other Related experience.

  • 8 years Minimum Required Related Work Experience

  • In lieu of Bachelors degree(s) AND 8 year(s) related work experience listed above, High School/GED AND 12 year(s) related work experience

Desired Qualifications

  • 7+ years of cybersecurity experience with expertise in Security Architecture, Application Security, Cloud Security, Attack Surface Management, Threat & Vulnerability Management, or Threat Intelligence.

  • Experience assessing security risks associated with AI technologies and/or leveraging AI-enabled capabilities to improve cybersecurity operations, automation, analytics, or risk prioritization.

  • Experience in one or more of the following areas:

    • AI Security

    • Vulnerability Management

    • Threat Intelligence

    • Attack Surface Management

    • Application Security

    • Cloud Security

    • Security Architecture

  • Demonstrated ability to lead complex cybersecurity initiatives involving multiple stakeholders.

  • Strong analytical, communication, and problem-solving skills.

Preferred Qualifications

  • Experience securing AI, machine learning, generative AI, agentic AI, or data science environments.

  • Experience evaluating AI governance, AI risk management, or AI security controls.

  • Hands-on experience with AI-enabled cybersecurity tooling, automation platforms, analytics solutions, or security orchestration capabilities.

  • Knowledge of emerging AI threats and adversarial machine learning techniques.

  • Experience with cloud-native security technologies and modern application architectures.

  • Familiarity with NIST AI RMF, NIST Cybersecurity Framework, NERC CIP, PCI DSS, and related industry standards.

  • Professional certifications such as CISSP, CISM, GCIH, GSEC, GRID, or equivalent.

Working Conditions

  • Hybrid Mobility Classification – Work will be performed from both remote and onsite locations after the onboarding period. However, hybrid employees should live within a reasonable daily commute to a Duke Energy facility.

  • Office Environment

#LI-ZM1

#LI-Hybrid

Travel Requirements

Not required

Relocation Assistance Provided (as applicable)

No

Represented/Union Position

No

Visa Sponsored Position

No. This is not a Visa Sponsored Position. This role requires the ability to work lawfully in the U.S. without employment-based immigration sponsorship, now or in the future.


Please note that in order to be considered for this position, you must possess all of the basic/required qualifications.

Privacy

Do Not Sell My Personal Information (CA)

Terms of Use

Accessibility