Full-Time

Senior UX Designer

Updated on 9/3/2026

SecurityScorecard

SecurityScorecard

501-1,000 employees

Cybersecurity security-ratings platform with AI analytics

Compensation Overview

$180k - $250k/yr

+ Bonus + Equity

No H1B Sponsorship

New York, NY, USA

Hybrid

Hybrid role in the New York metropolitan area; some on-site days may be required.

Category
Product & Experience Design (1)
Required Skills
Claude
UI/UX Design
Usability Testing/Engineering
Figma
Product Design

Get referred to SecurityScorecard

See people who can refer or advise you

Requirements
  • 6+ years of product design experience, with a portfolio that shows end-to-end ownership of complex features in a software or platform environment.
  • Demonstrated experience building and maintaining design systems and component libraries.
  • Strong fluency in Figma and modern design tooling, including an appetite for AI-assisted workflows.
  • Hands-on experience integrating usability testing and product analytics into your design process.
  • Working knowledge of accessibility standards (WCAG 2.2) and a track record of designing to them by default.
  • The ability to operate with autonomy — turning vague problems into shipped, high-quality solutions without heavy oversight.
Responsibilities
  • Own product design end-to-end. Take entire features and product areas from discovery and wireframes through high-fidelity UI and production-ready handoff — independently, with strong rationale behind every decision.
  • Contribute to and strengthen the design system. Actively build, maintain, and enforce a consistent component library that accelerates both design and engineering velocity.
  • Partner cross-functionally. Be an embedded partner to Product and Engineering. Translate ambiguous briefs into clear, defensible design solutions.
  • Integrate UX research into your work. Run usability tests, synthesize behavioral and product analytics (e.g., Fullstory, Pendo), and fold research findings into your design iterations.
  • Design accessibility-first. Treat WCAG 2.2 compliance as a default standard, not an afterthought.
  • Work AI-native. Leverage Figma AI, Claude, and emerging tooling to compress design cycles without compromising quality.

SecurityScorecard provides a comprehensive security ratings platform for a wide range of customers to manage cybersecurity risk. It uses AI-driven analytics to identify and prioritize threats, offering a unified view of threat and risk intelligence from an attacker’s perspective. The platform helps secure supply chains, manage third-party cyber risk, ensure regulatory compliance, and support cyber insurance and due diligence, including risk assessment for mergers and acquisitions. What sets it apart is its commitment to transparency—making its methodologies accessible to all and extending security ratings to any organization, not just select customers. Its goal is to create a safer world by providing clear, actionable risk information so organizations can reduce cyber risks and improve security across their networks.

Company Size

501-1,000

Company Stage

Series E

Total Funding

$292.2M

Headquarters

New York City, New York

Founded

2013

Get referred to SecurityScorecard

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Channel ARR grew 160% in 2025, with 600 partners worldwide by February 2026.
  • Sami Khoury joined August 2026, strengthening public-sector and critical-infrastructure sales motion.
  • Aon, CrowdStrike Marketplace, AWS, and WTW alliances widen distribution into insurance and enterprises.

What critics are saying

  • Bitsight ranked first in August 2026 lists; SecurityScorecard trails in integrated depth.
  • Competitors UpGuard, Panorays, Black Kite, and RiskRecon pressure pricing and retention.
  • TITAN AI, Driftnet, and AI Agents create integration drag if attribution quality slips.

What makes SecurityScorecard unique

  • SecurityScorecard rates over one million companies continuously, since 2013.
  • TITAN AI, launched at RSA 2026, automates TPRM workflows end-to-end.
  • Driftnet acquisition on May 14, 2026 adds real-time internet scanning and exposure discovery.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health benefits

Education stipend

Unlimited PTO

Parental leave

401K

Stock options

Referral bonuses

Remote work available

Growth & Insights and Company News

Headcount

6 month growth

3%

1 year growth

3%

2 year growth

2%
Associated Press
Aug 26th, 2026
SecurityScorecard appoints former Canadian cyber security chief Sami Khoury to advisory board

SecurityScorecard has appointed Sami Khoury, former Government of Canada Senior Official for Cyber Security, to its Public Sector Advisory Board. Khoury retired in July 2026 after representing Canada globally on cyber resilience and supply chain risk. From 2021 to 2024, he led the Canadian Centre for Cyber Security, Canada's national technical authority for cybersecurity. He spent over three decades at the Communications Security Establishment, joining as a research engineer in 1992. Khoury will provide strategic counsel as SecurityScorecard expands its work with public-sector organisations and critical infrastructure. The company's TITAN AI platform combines threat intelligence with third-party risk data to provide continuous supply chain monitoring. SecurityScorecard serves 3,000 organisations, including over 70% of the Fortune 100.

The Montreal Gazette
Aug 26th, 2026
SecurityScorecard appoints former Government of Canada Senior Official for Cyber Security Sami Khoury to public sector advisory board.

SecurityScorecard appoints former Government of Canada Senior Official for Cyber Security Sami Khoury to public sector advisory board. One of Canada's most senior cybersecurity leaders joins SecurityScorecard to help organizations strengthen supply chain resilience NEW YORK - SecurityScorecard, the global leader in threat-informed third-party risk management (TPRM), today announced that Sami Khoury, former Government of Canada Senior Official for Cyber Security and former Head of the Canadian Centre for Cyber Security, has joined...

DataBreachToday
May 15th, 2026
SecurityScorecard Buys Driftnet for more internet visibility.

SecurityScorecard Buys Driftnet for more internet visibility. Driftnet Acquisition Adds Real-Time Visibility Into Exposed Assets and AI Risks Michael Novinson (MichaelNovinson) - May 15, 2026 SecurityScorecard purchased an internet scanning startup led by a longtime United Kingdom government researcher to get deeper visibility into internet infrastructure and hidden exposures. The New York-based third-party risk management vendor said Driftnet was engineered to discover hidden infrastructure through highly targeted reconnaissance techniques that map relationships between configurations and identify chained misconfigurations, said co-founder and CEO Aleksandr Yampolskiy. Driftnet indexes about 40% more internet-exposed hosts than rival platforms, he said. "Artificial intelligence has changed the attack surface in ways that have outpaced most security programs," Yampolskiy told ISMG. "Agents are deployed across vendor environments at scale and speed that really creates entirely new categories of third-party risk." Driftnet, founded in 2019, employs fewer than 10 people and hasn't disclosed any outside funding. The company has been led since inception by Ben Schofield, who previously spent more than 12 years as a U.K. government researcher, seven of which were focused on the architecture and implementation of large-scale cyber systems (see: SecurityScorecard Buys HyperComply to Expand Risk Platform). Why SecurityScorecard chose to buy Driftnet rather than partner. Yampolskiy said Driftnet dynamically maps both IPv4 and IPv6 environments and monitors more than 3 billion IP host-port combinations as well as more than 650 million domain names. Using Driftnet's reconnaissance data, Yampolskiy said SecurityScorecard researchers were able to identify publicly accessible OpenClaw control panels in real time. "We were able to use Driftnet technology and Driftnet data to get a live view of all the OpenClaw instances out there, because a lot of people deploy these OpenClaw assistants, but then they don't secure them properly," Yampolskiy said. "And so using this live real-time reconnaissance data, we were able to instantly discover all the publicly accessible OpenClaw control panels." SecurityScorecard also grappled with a Chinese espionage campaign involving more than 1,000 infected operational relay boxes targeting U.S. infrastructure through compromised small office routers and edge devices. He said Driftnet's visibility helped researchers identify malicious infrastructure attack patterns and uncover activity that SecurityScorecard previously would not have been able to detect. "We weren't able to discover this type of data before, but now we can, so as a result, we're able to make much faster, smarter business decisions," Yampolskiy said. Owning Driftnet allows SecurityScorecard to directly control data quality, attribution accuracy and future innovation, Yampolskiy said. Rather than licensing data externally, Yampolskiy said the company can now customize and expand the intelligence platform internally to support evolving use cases tied to AI security, threat hunting and internet-scale visibility. "SecurityScorecard's differentiator has always been that we chose to collect all of our data ourselves because we want to own the accuracy of the data," Yampolskiy said. "We want to own the attribution of the data. So basically, the threat landscape changed faster than many programs have, and now that we have this data, we can basically evolve with a change in the landscape." How Driftnet unites third-party risk, security operations. Driftnet's capabilities extend beyond compliance-oriented third-party risk management programs and into core security operations workflows by giving organizations real-time operational visibility into internet infrastructure, exposed assets and active targeting activity, Yampolskiy said. The platform can feed intelligence directly into security operations centers, enabling organizations to detect risks faster. "Driftnet allows you to gain real-time visibility into your OT, IoT environments to protect operational resilience, to discover your cloud footprint assets, to measure shadow AI and protectively defend against threats," Yampolskiy said. "So, we basically become the bridge between the compliance-focused TPRM teams and the actual threat-focused SOC teams." SecurityScorecard plans to integrate Driftnet tightly into its Titan platform while also continuing to sell it as a separate product. Customers in industries such as financial services want to consume the intelligence directly through APIs and integrate the data into their own SOC environments, SIEMs and threat intel platforms. SecurityScorecard also wants Driftnet to improve visibility across all customer workflows. "People love it as a standalone product, because they can put it into their SOC immediately," Yampolskiy said. "But we're not in the business of having 10 standalone products. It's a separate SKU that you can purchase separately, but it's all part of the SecurityScorecard Titan platform to make sure that all these pieces benefit from being part of this platform." Driftnet's capabilities are particularly attractive to large enterprises, financial institutions and public sector organizations since they have dedicated threat hunting teams capable of operationalizing large-scale threat intelligence and internet reconnaissance data. Smaller organizations often outsource their SOC functions and may lack the internal resources necessary to fully leverage this type of intelligence. "Those Tier Is can do more with the Driftnet data," Yampolskiy said. "They can better hunt the threats. They can better detect the threats, they can protect the environment. So all of a sudden, they see what the hacker sees. Effectively, they're able to see the unique 0.1% of what the hackers see and sell on the dark web, and they're able to see that infrastructure that could be malicious."

Business Wire
May 14th, 2026
SecurityScorecard acquires Driftnet to enhance real-time third-party risk management with AI threat intelligence

SecurityScorecard, a third-party risk management provider, has acquired Driftnet, a specialist in global internet scanning and threat intelligence. Financial terms were not disclosed. The acquisition integrates Driftnet's internet discovery engine into SecurityScorecard's TITAN AI platform, enabling real-time identification of third-party risks. Driftnet's scanning capabilities include non-standard port enumeration and advanced fingerprinting, indexing 40% more internet-exposed hosts than competitors, according to SecurityScorecard. The combined platform will serve threat hunters, security operations teams and TPRM practitioners with unified intelligence. SecurityScorecard recently used Driftnet's technology to identify over 816,000 internet-exposed AI OpenClaw agent deployments, many linked to prior breaches. SecurityScorecard serves over 3,300 organisations, including 70% of the Fortune 100, and is backed by Evolution Equity Partners, Silver Lake Partners and Sequoia Capital.

SecurityScorecard
Apr 9th, 2026
Introducing SecurityScorecard AI Agents.

Introducing SecurityScorecard AI Agents. Transform your vendor risk management with new SecurityScorecard AI Agents. Learn how to automate security questionnaire management, gain real-time threat insights, and accelerate remediation to stay ahead of emerging cyber threats. Third-Party Risk Management (TPRM) demands time that most teams do not have. Most security teams spend several hours of their day conducting manual tasks, navigating page-by-page through vendor profiles, chasing down score drops, and manually compiling remediation plans. These workflows slow your team and limit your ability to reduce risk. This isn't just exhausting; it's a strategic bottleneck. Every hour spent on a spreadsheet is an hour not spent on identifying and addressing critical vulnerabilities. With an increase in third-party attacks doubling over the past year it is now more important than ever for teams to catch critical vulnerabilities This release addresses those limitations. SecurityScorecard is pleased to announce the official release of 10 new SecurityScorecard AI Agents. These aren't just chatbots; these AI agents execute defined TPRM workflows without manual intervention. They are autonomous assistants designed to handle the manual grind of traditional TPRM workflows. They analyze vendor data, identify risks, and support remediation planning in seconds. This allows you to reclaim your time and focus on what matters most: strategy and resilience. Introducing 10 new AI Agents to accelerate your TPRM program Why manual Third-Party Risk Management slows security teams. Monitoring critical vendors in traditional TPRM programs often relies on reactive processes. You receive an alert, you log in, you investigate the cause, and you manually draft an email to the vendor. SecurityScorecard's AI Agents flip this script. They act as an extension of your team, executing complex workflows in seconds that used to take hours. You can identify and address risk before it escalates into a breach. How AI Agents automate Third-Party Risk Management workflows: SecurityScorecard Inc. has three categories of agents: Analysis and Monitoring Agents, Breach Analysis Agents, and Remediation Planning Agents. AI Agents for Analysis and Monitoring. Streamline your internal operations and make your data more portable with AI agents for data, reporting, and workflows. * Reporting Agent: Transform complex metrics into line charts or trend graphs. Track portfolio health over time and export results as CSVs or images for your next board deck. * Rule Builder Agent: Set up alert rules and monitoring for entire portfolios at once, replacing tedious manual configuration. * Monitoring Agent: Set up alert for score drops and breach events for proactively monitoring vendors * Questionnaire Gap Analysis Agent: In addition to sending questionnaires to vendors, you can leverage agents to analyze received responses to identify gaps and create follow-up requirements. AI Agents for Breach Analysis. Leverage Breach Analysis Agents for your vendors as well as fourth party vendors with specialized AI agents for malware, ransomware, and supply chain risk. * Downstream Breach Analyst (Automatic Vendor Detection): Gain an intuitive view of fourth-party risk. Understand how breaches at your vendors' vendors impact your security posture. * Malware & Ransomware Analyst: Conduct broad scans for infection events to identify high-risk areas before they escalate. AI Agents for Remediation Planning. Close the gap between finding a risk and fixing it with AI agents for vulnerability monitoring and remediation plans. * KEV Remediation Plan Agent: Quickly identify Known Exploited Vulnerabilities (KEVs) across your portfolio and draft vendor-facing emails for immediate outreach. * Score Drop Remediation Agent: Instantly explain the "why" behind score fluctuations and outline specific corrective actions. * Critical Vulnerability Agent: Scan your entire portfolio for general Common Vulnerabilities Exposures (CVEs) to prioritize your response. * Breach Remediation Plan Agent: Pinpoint breach events and build a step-by-step recovery and communication plan. How AI reduces vendor Review time and manual effort. Efficiency is essential for scaling TPRM as vendor ecosystems grow and as AI changes threat actors' calculus. By automating the repetitive parts of portfolio monitoring and vendor outreach, its AI agents are designed to save teams dozens of hours per month. * Manual Task: Reviewing over 100 vendors for new ransomware infections. (Estimated: 2-3 hours) * AI Agent Task with SecurityScorecard: "Show me which vendors in my 'Critical' portfolio have infection events from the last 30 days." (Estimated: 30 seconds) When you automate the "how," you can finally focus on the "why": You can shift from manual execution to measurable risk reduction. As one SecurityScorecard customer shared: "The reporting and rule builder agents are immediate opportunities for us. By using AI to filter out the noise, we can make our monitoring significantly more relevant to what we actually need to see." - Security Analyst at a major medical provider Data security, privacy, and AI governance. SecurityScorecard Inc. understand that data storage and privacy are important to its customers and SecurityScorecard Inc. take those needs seriously. * Agents are not trained on your input. SecurityScorecard Inc. use foundational third-party models. * Agents pull information available from the SecurityScorecard API within your subscription; their scope matches what you and other customers can manually extract. * Review SecurityScorecard's Artificial Intelligence Addendum here for details on the AI Features SecurityScorecard Inc. currently offer, data handling, your rights, and responsible AI governance. AI-generated outputs should be reviewed by qualified personnel before implementation and do not constitute professional advice. All AI actions require human approval. Use of AI Features is subject to its Terms of Service and Artificial Intelligence Addendum. Start automating Third-Party Risk Management today. You can now access these agents in the SecurityScorecard platform by selecting the purple sparkle in the bottom right corner or using the ChatSSC search bar at the top of the platform. Click on the purple sparkle icon in the bottom right corner to open the chat window and access the AI agents. You can also access the AI agents via the search bar. Stop checking boxes and start moving the needle. It's time to let the agents handle the manual effort so you can handle the strategy. Frequently asked questions. What are AI agents in Third-Party Risk Management? AI agents at SecurityScorecard automate tasks such as questionnaire analysis, rule-building, vendor monitoring, and remediation planning, reducing manual workload. How do AI agents improve vendor risk management? SecurityScorecard AI agents identify risks faster, automate reporting, and enable continuous monitoring across third- and fourth-party vendors. They also reduce the manual grind of TPRM. How do AI agents improve the accuracy and speed of security questionnaire management? The Questionnaire Gap Analysis Agent at SecurityScorecard significantly improves security questionnaire workflows by analyzing a questionnaire and identifying any issues in the responses. The AI force multiplier: scale your security team with Agents and automation. SecurityScorecard Inc. recently hosted a webinar to show its new AI agents - check it out below to see them in action!