Product Security Analyst (Vulnerability Operations Focus)
We Are
Synopsys is the leader in engineering solutions from silicon to systems, enabling customers to rapidly innovate AI-powered products. We deliver industry-leading silicon design, IP, simulation and analysis solutions, and design services. We partner closely with our customers across a wide range of industries to maximize their R&D capability and productivity, powering innovation today that ignites the ingenuity of tomorrow.
You Are:
You are a technically grounded and operationally driven security professional with a passion for protecting products and customers through effective vulnerability management. You thrive in fast-paced environments where responsiveness, clarity, and precision matter, and you are energized by the challenge of managing security issues across a diverse product portfolio.
You bring experience in Product Security Incident Response (PSIRT) and vulnerability coordination. At the same time, you are forward-thinking and excited about evolving toward a modern model—where scale, automation, and AI-driven acceleration transform how vulnerabilities are managed and remediated.
You are comfortable operating independently, owning day-to-day vulnerability intake, triage, and remediation tracking, while actively engaging with engineering and product teams to ensure timely and effective resolution. You leverage AI agents and intelligent assistants to augment your workflows—accelerating triage, enriching vulnerability context, generating insights, and reducing manual effort—while maintaining human oversight and making decisions.
You are detail-oriented and process-minded, yet adaptable enough to help shape new ways of working as PSIRT evolves to support rapid development cycles and emerging technologies, including frontier AI-models. You bring a pragmatic mindset, focusing on measurable risk reduction, continuous improvement, and operational scale.
What You’ll Be Doing:
- Manage the end-to-end vulnerability lifecycle: intake, triage, validation, tracking, remediation, and disclosure.
- Operate within and help evolve processes ensuring consistency and quality in incident response.
- Serve as a primary point of contact for vulnerability coordination, working closely with product teams, engineering, legal, and communications.
- Perform technical triage and risk assessment, including CVSS scoring, CWE assignment, and exploitability analysis.
- Leverage AI agents and assistants to:
- Perform vulnerability intake normalization and deduplication
- Enrich findings with threat intelligence, exploit data, and attack context
- Generate initial triage summaries, severity recommendations, and remediation guidance
- Assist in root cause analysis and pattern identification across vulnerabilities
- Drive remediation efforts by partnering with product and engineering teams to ensure timely fixes and risk mitigation.
- Support coordinated vulnerability disclosure (CVD) processes with external researchers and stakeholders.
- Contribute to a VulnOps model by improving prioritization, automation, and scalability of vulnerability handling.
- Assist in the development of playbooks, workflows, and AI-enabled tooling to support high-velocity security operations.
- Participate in security advisories and customer communications, leveraging automation to improve speed and consistency.
- Support incident response efforts for product-related security issues as needed.
- Contribute to discussions on modernizing PSIRT, including leveraging AI to support scale, speed, and frontier technologies.
The Impact You Will Have:
- Improve the organization’s ability to identify, prioritize, and remediate vulnerabilities at speed and scale, powered by AI-assisted workflows.
- Reduce overall risk exposure across the product portfolio through efficient, data-driven vulnerability management.
- Strengthen customer trust through transparent, timely, and effective vulnerability handling.
- Enable engineering teams to address vulnerabilities faster and with clearer context.
- Drive operational efficiency gains, reducing manual effort and improving consistency through AI augmentation.
- Contribute to a future-ready PSIRT capability designed for high-velocity development and frontier AI-models.
What You’ll Need:
- Degree in Cybersecurity, Computer Science, Engineering, or related field (or equivalent experience).
- 3–6 years of experience in PSIRT or Product Security.
- Strong understanding of vulnerability management processes and standards (e.g., CVSS, CWE, CVE, FIRST.org PSIRT Framework).
- Familiarity coordinated vulnerability disclosure practices and CVE Numbering Authority (CAN).
- Exposure to or interest in AI/automation in security operations, including use of assistants, copilots, or workflow automation tools.
- Understanding of cloud, SaaS, and modern application architectures (preferred).
- Experience with scripting, APIs, or data analysis (Python or similar) is a plus.
- Security certifications (e.g., OSCP, CEH, CSSLP) are a plus but not required.
Who You Are:
- A self-starter who can operate independently and manage multiple workstreams effectively.
- Comfortable working alongside AI-enabled tooling, using it to enhance productivity and decision-making.
- A strong communicator, able to translate security findings into actionable guidance.
- Detail-oriented with a focus on accuracy, accountability, and follow-through.
- A problem solver who can navigate ambiguity and make informed decisions quickly.
- Collaborative and approachable, with the ability to build relationships across teams.
- Adaptable and resilient in fast-moving, evolving environments.
- Curious and forward-thinking, eager to help redefine PSIRT through VulnOps and AI-driven approaches.
The Team You’ll Be A Part Of:
You will join a forward-leaning Product Security team that is actively redefining how PSIRT operates in a modern, high-velocity environment. The team is evolving from traditional incident response toward a Vulnerability Operations (VulnOps) model, leveraging AI agents, automation, and data-driven decision-making to handle scale, speed, and complexity.
Working closely with Product Security, engineering, and cross-functional partners, you will play a key role in both daily operations and the transformation of PSIRT. The team values ownership, innovation, and continuous improvement, and is committed to building a scalable, AI-augmented security program capable of supporting next-generation and frontier technologies.
Rewards and Benefits
We offer a comprehensive range of health, wellness, and financial benefits to cater to your needs. Our total rewards include both monetary and non-monetary offerings. Your recruiter will provide more details about the salary range and benefits during the hiring process.
#LI-Hybrid