Security Engineer - Vulnerability Management
Core
Advance Endor Labs' proprietary vulnerability database by extending AI pipelines for automated validation, reachability analysis, and exploit generation.
Role type
Senior IC security engineer (vulnerability management & AI pipelines)
Builds
Production-grade automated vulnerability discovery systems and an enriched vulnerability database
Domain
Cybersecurity, vulnerability management, AI/ML
Deliverable
production ML models
Required skills
Vulnerability research and triage, CVE/CWE/CVSS/EPSS/PURL/NVD/OSV/VEX standards, building production-grade security tooling at scale, AI/agentic systems development (LLM pipelines, agent frameworks, prompt design), code analysis (Python, JavaScript/TypeScript, Java, Go), technical writing for public audiences
Preferred skills
Writing proof-of-concept exploits, fuzzing, static analysis, automated vulnerability discovery, open source contributions to vulnerability databases, SAST/SCA/DAST triage, supply chain security frameworks (SLSA, SSDF), public CVE credits
Technologies
LLM pipelines, agent frameworks, CVE, CWE, CVSS, EPSS, PURL, NVD, OSV, GHSA, VEX, SBOM, SAST, SCA, DAST, SLSA, SSDF
Responsibilities
Monitor and manage pipelines that triage, enrich, and prioritize vulnerabilities at scale; collaborate with 0-day researchers to scale automated vulnerability discovery; investigate high-impact vulnerabilities and author external-facing content (blogs, advisories); feed findings into detection and analysis pipelines to improve automated coverage
Seniority
Senior, hands-on IC