Vulnerability Management
Project Overview
Security teams often manage thousands of vulnerabilities across cloud infrastructure, applications, and endpoints. However, most security platforms overwhelm analysts with raw data without helping them understand what actually matters.
// My Role
Designing Vulnerability Prioritization for Security Teams
I led the design of the vulnerability management experience, working across product requirements, UX strategy, and interface design.
My role involved defining the user experience for how security analysts discover, evaluate, and prioritize vulnerabilities within the platform. I collaborated closely with product and engineering teams to translate technical requirements into clear product flows and usable interfaces.
As part of the process, I conducted competitive analysis across existing vulnerability management tools to understand industry patterns and identify opportunities for improvement. Based on these insights, I designed the core workflows and the vulnerability detail drawer, ensuring analysts could access deeper context and remediation data without leaving their primary workspace.
This work covered the full design process, including research, UX definition, and visual design.
// Problem
Security teams were overwhelmed with vulnerability alerts but lacked clear signals to prioritize real risk.
Security platforms generate thousands of vulnerability findings, but most tools present them as flat lists of CVEs without meaningful runtime context. Without insights from runtime monitoring and ADR signals, analysts lack the visibility needed to determine whether a vulnerability is actually reachable or actively exploitable in their environment. This forces security teams to spend significant time manually triaging alerts instead of focusing on the vulnerabilities that pose real risk to running workloads.
50k+
vulnerabilities detected weekly
5%
actually exploitable
Days
to identify critical risks
// Research
Understanding How Analysts Triage Vulnerabilities
To better understand how users interacted with the vulnerability management workflow, I analyzed session recordings and behavioral data.
By observing real user sessions, I studied how analysts navigated the vulnerability list, which actions they performed during triage, and where they encountered friction while investigating CVEs.
These observations helped identify patterns in how users evaluated vulnerabilities and informed the design of a prioritization approach that surfaces the vulnerabilities most likely to require immediate attention.
6
Behavior Analysis
8
Security Platforms Studied
20+
Alert Workflows Analyzed
Key Insight
Security teams didn't lack vulnerability data, they lacked context about exploitability and reachability.
Design Opportunity
How might we help security teams prioritize the vulnerabilities that actually pose real risk?
Early Concepts
We explored ways to visualize vulnerability risk using graph relationships between assets, attack paths, and exploitability signals.
Early design of the vulnerability management
Design concept of the Vulnerability Management Drawer
// Final Product
Turning Vulnerability Noise into Clear Priorities
The final platform introduced a vulnerability funnel that progressively filtered vulnerabilities based on reachability, exploitability, and remediation feasibility.
Vulnerability Management Page
Vulnerability Management experience currently used in production, designed to provide security teams with the critical context needed to investigate, prioritize, and remediate vulnerabilities efficiently.
Vulnerabilities Drawer
The Vulnerability Drawer provides analysts with deeper context about each CVE, including its timeline, GitHub popularity signals, Alma’s risk score and scoring logic, available fix versions, runtime context, remediation and more.
// Impact
After launching the prioritization workflow, security teams were able to focus on the vulnerabilities that actually posed risk to their infrastructure.
92%
noise reduction in vulnerability alerts
4x
faster vulnerability triage
70%
faster remediation of critical issues
Key Learning
Security platforms must reduce noise rather than surface more alerts.
Visualizing attack paths helps analysts understand real risk faster.
Prioritization is the most critical workflow in vulnerability management.

