Security Engineer - Vulnerability Management
Core
Advance proprietary vulnerability databases and improve AI pipelines for automated vulnerability validation, reachability analysis, and exploit generation.
Role type
Senior IC security engineer (vulnerability management & AI pipelines)
Builds
Production-grade systems for automated vulnerability triage, enrichment, prioritization, and exploit generation
Domain
Cybersecurity, Vulnerability Management, AI/ML Engineering
Deliverable
production ML models | product features
Required skills
Vulnerability research and management, CVE/CWE/CVSS/EPSS/PURL/NVD/OSV/VEX standards, CI/CD automation, SAST/SCA findings management, AI/LLM pipeline development, Python/JavaScript/TypeScript/Java/Go code analysis, security communications writing
Preferred skills
Proof-of-concept exploit development, fuzzing, static analysis, automated vulnerability discovery, open-source vulnerability database contributions, SAST/SCA/DAST tooling expertise, SLSA/SSDF supply-chain frameworks, public CVE credits
Technologies
Python, JavaScript, TypeScript, Java, Go, LLM frameworks, OSV, osv-scanner, OpenVEX, SAST, SCA, DAST, SLSA, SSDF
Responsibilities
Monitor and manage pipelines that triage, enrich, and prioritize vulnerabilities at scale; Investigate high-impact vulnerabilities and the broader vulnerability landscape; Author external-facing blog posts, technical write-ups, and advisories; Collaborate with internal teams to feed findings into detection and analysis pipelines
Seniority
Senior, hands-on IC