Senior Vulnerability Engineer
Core
Design, build, and scale enterprise vulnerability management capabilities across cloud, application, and corporate environments, integrating security into CI/CD pipelines and supporting offensive security initiatives.
Role type
Senior IC security engineer (vulnerability management & offensive security)
Builds
Scalable vulnerability scanning and asset discovery solutions, automation workflows, and risk-based prioritization models
Domain
Cybersecurity, Cloud Security, DevSecOps
Deliverable
production ML models | product features | infrastructure
Required skills
Vulnerability scanning tools, CVE/CVSS scoring, exploit analysis, Python/PowerShell scripting, API integration, cloud platforms (AWS/GCP/Azure), CI/CD pipeline security, penetration testing, red teaming, bug bounty triage, compliance frameworks (NIST/SOC2/ISO)
Preferred skills
OSCP/GIAC/CISSP certifications, data analytics/visualization (Splunk/Elastic), exploit development, asset inventory platforms, internal security tooling
Technologies
Python, PowerShell, AWS, GCP, Azure, Splunk, Elastic, CI/CD platforms, ticketing systems, source control tools
Responsibilities
Design and implement scalable vulnerability scanning and asset discovery solutions across multi-cloud and SaaS environments; Engineer and maintain integrations between vulnerability management tools and internal systems; Automate vulnerability ingestion, enrichment, prioritization, and remediation workflows; Develop risk-based prioritization models by correlating vulnerability data with threat intelligence; Build and maintain pipelines to integrate vulnerability scanning into CI/CD processes; Create dashboards and analytics to track vulnerability exposure, remediation SLAs, and risk trends; Support the execution of red team exercises, penetration tests, and bug bounty programs; Coordinate and validate findings from internal and external testing activities; Integrate offensive security findings into vulnerability management workflows; Partner with external vendors and researchers to triage submissions; Continuously improve testing methodologies, coverage, and tooling; Correlate red team, penetration testing, and bug bounty findings with vulnerability data; Contribute to secure architecture and hardening efforts across cloud and application environments; Support compliance requirements through technical implementation and evidence generation
Seniority
Senior, hands-on IC