Senior Vulnerability Management Engineer
Core
Senior Vulnerability Management Engineer bridging offensive security and engineering to translate penetration test results into actionable remediation guidance and drive closure of findings.
Role type
Senior IC vulnerability management engineer (offensive security)
Builds
Secure fixes and remediation patterns for application and platform teams
Domain
Financial markets infrastructure / Application Security / Offensive Security
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Penetration testing (Web Apps, APIs, Thick Client, Infra), Cloud platforms (AWS, Azure, GCP), Containerization (Docker, Kubernetes), OWASP Top 10, Secure coding (Java/Springboot, .NET, JavaScript/Node, Python), Custom scripting, Root cause analysis, SDLC/DevSecOps integration
Preferred skills
Threat modelling, Relevant security certifications
Technologies
Burp Suite, Command-line tools, AWS, Azure, GCP, Docker, Kubernetes, Java, .NET, JavaScript, Node, Python
Responsibilities
Analyze penetration test reports for technical impact and business risk; Develop and maintain remediation guidance and blueprints for common vulnerabilities; Consult application and platform teams on secure design and remediation; Coordinate remediation activities across teams with clear ownership and timelines; Validate fixes via retesting and update finding status; Manage remediation backlog including SLAs and aging findings; Produce status reports and metrics on risk reduction; Perform root cause analysis for systemic issues; Contribute to automation and standardization of the pentest-to-remediation lifecycle
Seniority
Senior, hands-on IC
