VulnOps Engineer
Core
Own the end-to-end vulnerability operations function, managing a unified risk-scored backlog and operating the ASPM/RBVM platform to reduce breach risk and mean-time-to-remediate.
Role type
Senior IC vulnerability operations engineer (ASPM/RBVM platform owner)
Builds
Unified vulnerability management platform, automated remediation workflows, executive dashboards, and regulatory reports
Domain
Cybersecurity, DevSecOps, Cloud Infrastructure Security
Deliverable
production ML models | product features | dashboards & analysis
Required skills
Vulnerability management, ASPM/RBVM platform operations, SAST/SCA/container/IaC scanning, Python scripting, risk scoring (CVSS/EPSS/KEV), SBOM standards (CycloneDX/SPDX), SLA management, automated remediation workflows
Preferred skills
Regulated environment experience (FSI/healthcare/gov), OWASP DSOMM Level 2, CSPM tooling, DORA Article 19 incident reporting
Technologies
Python, CVSS v3.1, CVSS v4.0, EPSS, KEV, CycloneDX, SPDX, AWS, SAST, DAST, SCA, Container scanning, IaC scanning, Secret scanning, CSPM
Responsibilities
Manage and optimize the ASPM/RBVM platform including tool integrations and risk scoring; Drive vulnerability remediation and SLA compliance with engineering teams; Operate security automation capabilities for detection and response; Coordinate vulnerability communications and regulatory reporting; Reduce operational overhead and improve remediation efficiency.
Seniority
Senior, hands-on IC
