Senior Security Engineer, Vulnerability Management
Senior Security Engineer responsible for scaling vulnerability detection, prioritization, remediation, and verification across multi-cloud products. The role combines hands-on engineering, AI and automation, risk analysis, and cross-functional security collaboration.
About the job
Responsibilities
- Manage the vulnerability lifecycle from detection and impact assessment through risk-based prioritization, remediation, and verification.
- Build AI- and automation-driven tools, services, and workflows to scale vulnerability management.
- Reduce engineering toil using a “PRs, not tickets” approach, including enriching findings, identifying ownership, recommending or delivering fixes, and tracking outcomes.
- Analyze recurring vulnerabilities and remediation failures to identify root causes and prevent issues earlier in the SDLC.
- Partner with SDLC Security, Product Security, platform, engineering, product, and compliance teams to develop scalable solutions.
- Provide evidence and subject matter expertise for vulnerability management processes and controls across SOC 2, HIPAA, PCI, FedRAMP, and ISO frameworks.
Requirements
- Experience identifying, prioritizing, and driving remediation of vulnerabilities in large software, cloud, or infrastructure environments.
- Ability to solve complex technical problems with one or more programming languages, such as Go, Python, or Java.
- Experience with cloud-native or multi-cloud environments, containers or orchestration platforms, infrastructure as code, and modern software-delivery workflows.
- Experience reproducing and validating externally reported vulnerabilities.
- Ability to assess and communicate risk using data, exploitability, exposure, technical context, and business impact.
- Ability to work independently in ambiguous environments, test assumptions, document tradeoffs, and adapt to new information.
- Thoughtful use and validation of AI-assisted tools.
- Strong communication, technical credibility, and cross-functional influence.
- BS, MS, or PhD in Computer Science, Engineering, or a related scientific field, or equivalent practical experience.
Benefits and Compensation
- New-hire stock equity (RSUs) and employee stock purchase plan (ESPP).
- Continuous professional development, product training, and career pathing.
- Intradepartmental mentor and buddy program.
- Inclusive company culture and employee resource groups.
- Access to internal inclusion talks.
- Global mental health benefits for employees and dependents age six and older.
- Competitive benefits, varying by country of employment and employment arrangement.
Skills
Vulnerability Management, Go, Python, Java, Cloud-Native, Multi-Cloud, Containers, Kubernetes, Infrastructure As Code, CI/CD, Artificial Intelligence, Automation, SOC 2, HIPAA, Pci Dss
Similar jobs
Security Engineering jobsLeads cloud-native security operations, incident response, threat hunting, and forensic investigations while mentoring SOC analysts and improving detection processes. Requires 8+ years in information security, including hands-on cloud incident response and experience with Kubernetes, CI/CD, and advanced security tools.
Senior Security Engineer responsible for application, cloud, and platform security, with a focus on automating security workflows, threat modeling, secure development, and remediation. Requires hands-on SaaS security, cloud infrastructure, code review, and agent or automation experience.
Leads the company’s security GRC function, owning SOC 2, ISO 27001, enterprise audits, third-party risk, policy governance, and automated evidence workflows. Requires 7+ years of GRC or audit experience, end-to-end SOC 2 and ISO 27001 ownership, and strong security tooling expertise.
Leads technical SOX controls assurance for financially significant systems, translating audit requirements into engineering acceptance criteria and continuous monitoring. Requires ITGC and SOX 404 expertise, strong engineering fluency, programming ability, and cross-functional collaboration with Finance, Engineering, and auditors.
Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.