# Vulnerability Engineer

**Company:** [Domino](https://hotfix.jobs/companies/domino-data-lab)
**Location:** Remote
**Role:** Security Engineering
**Skills:** Cvss, Python, Prisma Cloud, Twistlock, Jfrog, Trivy, SAST, DAST, Burp Suite, Owasp Top 10, Kubernetes, Linux, AWS, Api Security, Threat Modeling
**Posted:** 2026-08-05

> The Vulnerability Engineer will assess, reproduce, prioritize, and validate vulnerabilities across a SaaS environment, while maintaining scanning automation and partnering with Engineering on remediation. The role requires vulnerability-management experience, scripting skills, exploit validation, and knowledge of cloud, containers, and application security.

## Job Description

## Responsibilities
- Own first-pass CVSS scoring and exploitability analysis for vulnerability risk assessments.
- Reproduce and validate customer-reported and penetration-test findings before escalation to Engineering.
- Maintain SAST/DAST and vulnerability-scanning automations, troubleshoot failures, and tune configurations.
- Build or run proof-of-concept exploits for selected CVEs to validate real-world exploitability.
- Partner with Engineering to prioritize and ship fixes.
- Manage vulnerabilities across operating systems, containers, and dependencies for a large SaaS product.
- Reconcile findings across vulnerability-scanning tools and follow issues through resolution.
- Draft clear risk statements for technical and non-technical audiences.

## Requirements
- Hands-on vulnerability management experience for a SaaS or containerized product.
- Experience triaging and tracking CVEs, reading scan reports, prioritizing severity, and following findings through resolution.
- Experience reproducing and validating vulnerabilities from customer disclosures or penetration tests.
- Experience with Prisma Cloud/Twistlock, JFrog, Trivy, or similar vulnerability-scanning tools.
- Experience building or maintaining SAST/DAST pipeline automation.
- Strong scripting ability, preferably Python.
- Working knowledge of CVSS v3.1/v4.0 and risk assessment.
- Exploit development or proof-of-concept skills, including Burp Suite.
- Familiarity with OWASP Top 10 and security-testing methodologies.
- Working knowledge of containers, Kubernetes, Linux, AWS, and networking fundamentals.
- Understanding of authentication, authorization, tokens, session handling, authentication bypass patterns, and API security.
- Basic threat-modeling ability, including attack-path analysis.
- Strong communication and ability to work through ambiguous findings and risk discussions.

## Nice to Have
- OSWA, OSWE, GWAPT, GPEN, or similar offensive-security certification.
- Familiarity with Airflow and Snowflake.

## Benefits and Culture
- Growth-oriented environment with opportunities for teaching and learning.
- Commitment to diverse and inclusive teams.


## Similar jobs

- [Platform Security Engineer](https://hotfix.jobs/jobs/e556dd76-0f95-4dfa-9d3d-e476f24057c0) - Supabase - Remote
- [Manager, Security Operations](https://hotfix.jobs/jobs/0a4637da-6072-4ec3-a0a9-8b6d4a412d45) - Vanta - Remote - $178k – $209k/yr
- [Supply Chain Security Engineer](https://hotfix.jobs/jobs/7ea430fb-72cd-43f4-9700-2698a4cc949f) - Glean - Bengaluru, India
- [Specialist, CSIRT](https://hotfix.jobs/jobs/d5cdd102-2c55-4adf-a397-fb50362f7fea) - Coinbase - Remote
- [Senior Security Engineer](https://hotfix.jobs/jobs/2a1ede09-d608-462e-bb14-223603034206) - Greenlight - Bengaluru, India

**Apply:** https://hotfix.jobs/jobs/1ddf6e51-656d-49db-a619-7e20921281dd
**Canonical:** https://hotfix.jobs/jobs/1ddf6e51-656d-49db-a619-7e20921281dd