Uploaded May 2026 | Updated September 2026, 13 hours ago
Sophia Sanles-Luksetich (GitHub, US), Zachary Goldman (GitHub, US)
Modern vulnerability management is drowning in noise: massive alert volumes, inconsistent vendor scores, and fragmented data sources make it difficult to understand what truly matters. This session shows how GitHub flipped its inverted risk funnel by building a unified, extensible risk‑scoring model that normalizes findings across 20+ heterogeneous sources and hundreds of thousands of daily alerts. We’ll demonstrate how combining CVSS with threat‑driven metrics like EPSS and KEV, asset‑specific context, and the newly updated FedRAMP SLA requirements turns raw findings into actionable prioritization. We’ll also cover the engineering systems that make this scale possible, including routing strategies and enrichment pipelines. You’ll learn how to evolve industry standards rather than replace them, tune formulas and weights using calibration sets, and future‑proof your scoring model as new metadata and detection strategies emerge. If your critical alerts outnumber all other severities, this talk will show you how to restore clarity, reduce alert fatigue, and drive remediation where it has the greatest impact.
---
Sophia Sanles-Luksetich: Senior Security Analyst with 6+ years of experience, focused on building data visualizations and producing analytics for vulnerability management, with prior experience in bug bounty triage. Her work has been critical in navigating and leveraging vulnerability management’s massive and continuously growing database of security findings.
Zach Goldman: Security Engineer with 5+ years of experience, currently specializing in developing the Exceptions feature to better track and manage deviations from standard remediation processes. His work directly supports leadership at both the organizational and team levels, requiring a high degree of polish and cross‑departmental collaboration.
Sophia Sanles-Luksetich (GitHub, US), Zachary Goldman (GitHub, US)
Modern vulnerability management is drowning in noise: massive alert volumes, inconsistent vendor scores, and fragmented data sources make it difficult to understand what truly matters. This session shows how GitHub flipped its inverted risk funnel by building a unified, extensible risk‑scoring model that normalizes findings across 20+ heterogeneous sources and hundreds of thousands of daily alerts. We’ll demonstrate how combining CVSS with threat‑driven metrics like EPSS and KEV, asset‑specific context, and the newly updated FedRAMP SLA requirements turns raw findings into actionable prioritization. We’ll also cover the engineering systems that make this scale possible, including routing strategies and enrichment pipelines. You’ll learn how to evolve industry standards rather than replace them, tune formulas and weights using calibration sets, and future‑proof your scoring model as new metadata and detection strategies emerge. If your critical alerts outnumber all other severities, this talk will show you how to restore clarity, reduce alert fatigue, and drive remediation where it has the greatest impact.
---
Sophia Sanles-Luksetich: Senior Security Analyst with 6+ years of experience, focused on building data visualizations and producing analytics for vulnerability management, with prior experience in bug bounty triage. Her work has been critical in navigating and leveraging vulnerability management’s massive and continuously growing database of security findings.
Zach Goldman: Security Engineer with 5+ years of experience, currently specializing in developing the Exceptions feature to better track and manage deviations from standard remediation processes. His work directly supports leadership at both the organizational and team levels, requiring a high degree of polish and cross‑departmental collaboration.










