Product Security Analyst (Vulnerability Operations Focus)
Synopsys
- Level
- Mid
- H-1B history
- 112 approvals (FY2023)
- Posted
- Jul 16, 2026
About this role
Descriptions & Requirements
Job Description and Requirements
We Are Synopsys is the leader in engineering solutions from silicon to systems, enabling customers to rapidly innovate AI-powered products. We deliver industry-leading silicon design, IP, simulation and analysis solutions, and design services. We partner closely with our customers across a wide range of industries to maximize their R&D capability and productivity, powering innovation today that ignites the ingenuity of tomorrow. You Are: You are a technically grounded and operationally driven security professional with a passion for protecting products and customers through effective vulnerability management. You thrive in fast-paced environments where responsiveness, clarity, and precision matter, and you are energized by the challenge of managing security issues across a diverse product portfolio. You bring experience in Product Security Incident Response (PSIRT) and vulnerability coordination. At the same time, you are forward-thinking and excited about evolving toward a modern model—where scale, automation, and AI-driven acceleration transform how vulnerabilities are managed and remediated. You are comfortable operating independently, owning day-to-day vulnerability intake, triage, and remediation tracking, while actively engaging with engineering and product teams to ensure timely and effective resolution. You leverage AI agents and intelligent assistants to augment your workflows—accelerating triage, enriching vulnerability context, generating insights, and reducing manual effort—while maintaining human oversight and making decisions. You are detail-oriented and process-minded, yet adaptable enough to help shape new ways of working as PSIRT evolves to support rapid development cycles and emerging technologies, including frontier AI-models. You bring a pragmatic mindset, focusing on measurable risk reduction, continuous improvement, and operational scale. What You’ll Be Doing: Manage the end-to-end vulnerability lifecycle: intake, triage, validation, tracking, remediation, and disclosure. Operate within and help evolve processes ensuring consistency and quality in incident response. Serve as a primary point of contact for vulnerability coordination, working closely with product teams, engineering, legal, and communications. Perform technical triage and risk assessment, including CVSS scoring, CWE assignment, and exploitability analysis. Leverage AI agents and assistants to: Perform vulnerability intake normalization and deduplication Enrich findings with threat intelligence, exploit data, and attack context Generate initial triage summaries, severity recommendations, and remediation guidance Assist in root cause analysis and pattern identification across vulnerabilities Drive remediation efforts by partnering with product and engineering teams to ensure timely fixes and risk mitigation. Support coordinated vulnerability disclosure (CVD) processes with external researchers and stakeholders. Contribute to a VulnOps model by improving prioritization, automation, and scalability of vulnerability handling. Assist in the development of playbooks, workflows, and AI-enabled tooling to support high-velocity security operations. Participate in security advisories and customer communications, leveraging automation to improve speed and consistency. Support incident response efforts for product-related security issues as needed. Contribute to discussions on modernizing PSIRT, including leveraging AI to support scale, speed, and frontier technologies. The Impact You Will Have: Improve the organization’s ability to identify, prioritize, and remediate vulnerabilities at speed and scale, powered by AI-assisted workflows. Reduce overall risk exposure across the product portfolio through efficient, data-driven vulnerability management. Strengthen customer trust through transparent, timely, and effective vulnerability handling. Enable engineering teams to address