Vulnerability Management

Project Overview

Security teams often manage thousands of vulnerabilities across cloud infrastructure, applications, and endpoints. However, most security platforms overwhelm analysts with raw data without helping them understand what actually matters.

Product

Vul. Management

users

SecOps

timeline

3 Months

team

1 PM · 4 developers · me

Product

Vul. Management

users

SecOps

timeline

3 Months

team

1 PM · 4 developers · me

Product

Vul. Management

users

SecOps

timeline

3 Months

team

1 PM · 4 developers · me

// My Role

Designing Vulnerability Prioritization for Security Teams

I led the design of the vulnerability management experience, working across product requirements, UX strategy, and interface design.

My role involved defining the user experience for how security analysts discover, evaluate, and prioritize vulnerabilities within the platform. I collaborated closely with product and engineering teams to translate technical requirements into clear product flows and usable interfaces.

As part of the process, I conducted competitive analysis across existing vulnerability management tools to understand industry patterns and identify opportunities for improvement. Based on these insights, I designed the core workflows and the vulnerability detail drawer, ensuring analysts could access deeper context and remediation data without leaving their primary workspace.

This work covered the full design process, including research, UX definition, and visual design.

// Problem

Security teams were overwhelmed with vulnerability alerts but lacked clear signals to prioritize real risk.

Security platforms generate thousands of vulnerability findings, but most tools present them as flat lists of CVEs without meaningful runtime context. Without insights from runtime monitoring and ADR signals, analysts lack the visibility needed to determine whether a vulnerability is actually reachable or actively exploitable in their environment. This forces security teams to spend significant time manually triaging alerts instead of focusing on the vulnerabilities that pose real risk to running workloads.

50k+

vulnerabilities detected weekly

5%

actually exploitable

Days

to identify critical risks

// Research

Understanding How Analysts Triage Vulnerabilities

To better understand how users interacted with the vulnerability management workflow, I analyzed session recordings and behavioral data.

By observing real user sessions, I studied how analysts navigated the vulnerability list, which actions they performed during triage, and where they encountered friction while investigating CVEs.

These observations helped identify patterns in how users evaluated vulnerabilities and informed the design of a prioritization approach that surfaces the vulnerabilities most likely to require immediate attention.

6

Behavior Analysis

8

Security Platforms Studied

20+

Alert Workflows Analyzed

Key Insight

Security teams didn't lack vulnerability data, they lacked context about exploitability and reachability.

Design Opportunity

How might we help security teams prioritize the vulnerabilities that actually pose real risk?

Early Concepts

We explored ways to visualize vulnerability risk using graph relationships between assets, attack paths, and exploitability signals.

Early design of the vulnerability management

Design concept of the Vulnerability Management Drawer

// Final Product

Turning Vulnerability Noise into Clear Priorities

The final platform introduced a vulnerability funnel that progressively filtered vulnerabilities based on reachability, exploitability, and remediation feasibility.

Vulnerability Management Page

Vulnerability Management experience currently used in production, designed to provide security teams with the critical context needed to investigate, prioritize, and remediate vulnerabilities efficiently.

Vulnerabilities Drawer

The Vulnerability Drawer provides analysts with deeper context about each CVE, including its timeline, GitHub popularity signals, Alma’s risk score and scoring logic, available fix versions, runtime context, remediation and more.

// Impact

After launching the prioritization workflow, security teams were able to focus on the vulnerabilities that actually posed risk to their infrastructure.

92%

noise reduction in vulnerability alerts

4x

faster vulnerability triage

70%

faster remediation of critical issues

Key Learning

  • Security platforms must reduce noise rather than surface more alerts.

  • Visualizing attack paths helps analysts understand real risk faster.

  • Prioritization is the most critical workflow in vulnerability management.

Let's get in touch and /build something together

© 2026 matan. all rights reserved.

Let's get in touch and /build something together

© 2026 matan. all rights reserved.

Let's get in touch and /build something together

© 2026 matan. all rights reserved.

Create a free website with Framer, the website builder loved by startups, designers and agencies.