Principal Vulnerability Management Engineer
Core
Modernize vulnerability and exposure management across infrastructure, cloud, APIs, and containers by evolving the function from reporting to a high-leverage product security engineering capability.
Role type
Principal Vulnerability Management Engineer (Individual Contributor)
Builds
Scalable workflows, automated data pipelines, risk-based prioritization models, and external attack surface management (EASM) programs.
Domain
Cybersecurity / Cloud Security / Vulnerability Management
Deliverable
production ML models | product features | infrastructure
Required skills
Vulnerability and exposure management program scaling, risk-based prioritization models (beyond CVSS), scanner mechanics (authenticated/unauthenticated), automation (Python, PowerShell, APIs), threat intelligence integration, asset correlation, CI/CD/DevSecOps pipeline integration
Preferred skills
AI/ML for intelligent triage and predictive analysis, multi-cloud security (AWS, Azure, GCP), container security (Kubernetes), advanced vulnerability prioritization strategies (EASM, CTEM, attack-path analysis)
Technologies
Tenable, Qualys, Wiz, CrowdStrike, Burp Suite, Kubernetes, AWS, Azure, GCP
Responsibilities
Lead comprehensive vulnerability and exposure management initiatives; Define advanced, risk-based prioritization models; Design and deploy automated data pipelines and workflow orchestration; Drive external attack surface management (EASM); Collaborate with DevOps and Engineering teams to translate vulnerability data into technical guidance and metrics.
Seniority
Principal, hands-on IC with strategic influence