Vulnerability Engineer
The Vulnerability Engineer will assess, reproduce, prioritize, and validate vulnerabilities across a SaaS environment, while maintaining scanning automation and partnering with Engineering on remediation. The role requires vulnerability-management experience, scripting skills, exploit validation, and knowledge of cloud, containers, and application security.
About the job
Responsibilities
- Own first-pass CVSS scoring and exploitability analysis for vulnerability risk assessments.
- Reproduce and validate customer-reported and penetration-test findings before escalation to Engineering.
- Maintain SAST/DAST and vulnerability-scanning automations, troubleshoot failures, and tune configurations.
- Build or run proof-of-concept exploits for selected CVEs to validate real-world exploitability.
- Partner with Engineering to prioritize and ship fixes.
- Manage vulnerabilities across operating systems, containers, and dependencies for a large SaaS product.
- Reconcile findings across vulnerability-scanning tools and follow issues through resolution.
- Draft clear risk statements for technical and non-technical audiences.
Requirements
- Hands-on vulnerability management experience for a SaaS or containerized product.
- Experience triaging and tracking CVEs, reading scan reports, prioritizing severity, and following findings through resolution.
- Experience reproducing and validating vulnerabilities from customer disclosures or penetration tests.
- Experience with Prisma Cloud/Twistlock, JFrog, Trivy, or similar vulnerability-scanning tools.
- Experience building or maintaining SAST/DAST pipeline automation.
- Strong scripting ability, preferably Python.
- Working knowledge of CVSS v3.1/v4.0 and risk assessment.
- Exploit development or proof-of-concept skills, including Burp Suite.
- Familiarity with OWASP Top 10 and security-testing methodologies.
- Working knowledge of containers, Kubernetes, Linux, AWS, and networking fundamentals.
- Understanding of authentication, authorization, tokens, session handling, authentication bypass patterns, and API security.
- Basic threat-modeling ability, including attack-path analysis.
- Strong communication and ability to work through ambiguous findings and risk discussions.
Nice to Have
- OSWA, OSWE, GWAPT, GPEN, or similar offensive-security certification.
- Familiarity with Airflow and Snowflake.
Benefits and Culture
- Growth-oriented environment with opportunities for teaching and learning.
- Commitment to diverse and inclusive teams.
Skills
Cvss, Python, Prisma Cloud, Twistlock, Jfrog, Trivy, SAST, DAST, Burp Suite, Owasp Top 10, Kubernetes, Linux, AWS, Api Security, Threat Modeling
Similar jobs
Security Engineering jobsSecures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.
Secures Glean's software supply chain by managing vulnerabilities, hardening images, protecting open-source dependencies, and embedding trusted release controls in CI/CD. Requires 3+ years in application security or vulnerability management, strong cloud-native and container security knowledge, and experience with FedRAMP audits.
Owns frontline security alert triage, incident response, detection coverage, and automation across cloud, SaaS, container, and Web3 environments. Requires at least three years of hands-on security operations experience and proficiency with scripting, SIEM platforms, and threat intelligence tooling.
Senior product security engineer responsible for embedding security across the SDLC, building security automation, conducting reviews and penetration testing, and leading vulnerability response. Requires 5+ years of security experience, strong web and mobile security expertise, and hands-on AWS, CI/CD, and security tooling knowledge.