What you'll do
Program Ownership: Own and continuously improve the vulnerability management program, including intake, severity scoring (CVSS/risk-based), SLA definition, and remediation tracking across all asset types.
Bug Bounty Operations: Manage the triage/payouts/rewards workflow, and report on program health and trends.
Cloud Remediation (GCP): Drive remediation of vulnerabilities found in GCP infrastructure — IAM, networking, Compute/GKE, storage, and logging/monitoring configuration — by partnering with security, cloud, and platform engineering teams.
Code & Supply Chain Security: Coordinate remediation of vulnerabilities surfaced through SAST/DAST/SCA tooling (Wiz Code, Snyk, Dependabot, code scanning, secret scanning) across engineering repos, including dependency and supply-chain risk.
SaaS Vendor Risk: Build and manage the process for assessing and tracking security posture across third-party SaaS applications.
Escalation & Exceptions: Define and enforce escalation paths for overdue or critical/high-severity findings, including risk acceptance and exception processes with appropriate sign-off.
Cross-Team Accountability: Partner with engineering managers and tech leads to embed remediation work into sprint planning and hold teams accountable to remediation SLAs.
Reporting & Alerting: Establish and maintain a single source of truth for vulnerability status, aging, SLA compliance, and risk trends, with dashboards for engineering leadership, security leadership, and executives.
Audit & Compliance Support: Support audit and compliance efforts (SOC 2, ISO 27001, customer security questionnaires) by keeping vulnerability management evidence and metrics audit-ready.
Process & Automation: Drive process improvements and automation to reduce manual triage effort and improve time-to-remediation across all vulnerability sources.
Required Skills & Experience
- 4–6+ years of experience in technical program management, security program management, or security operations, with direct ownership of a vulnerability management or application security program.
- Hands-on experience running a bug bounty program (e.g., HackerOne, Bugcrowd, Intigriti), including triage and payout workflows.
- Working knowledge of GCP security fundamentals: IAM, VPC/networking, Security Command Center, Cloud Logging/Monitoring, and common cloud misconfiguration risks.
- Familiarity with GitHub-based development workflows and code security tooling (Wiz Code, Dependabot, SAST/DAST/SCA tools such as Snyk, Semgrep, or CodeQL).
- Strong grasp of vulnerability scoring frameworks (CVSS) and risk-based prioritization.
- Excellent cross-functional communication skills — able to translate technical vulnerability data into business risk for executive audiences and hold engineering teams accountable without owning the code themselves.
- Proven ability to build reporting/dashboards (e.g., Linear, Jira, ServiceNow, Tableau, Looker) that give leadership real-time visibility into program health.
- Experience supporting compliance frameworks such as SOC 2, ISO 27001, PCI-DSS, or FedRAMP.
What we value
- Systems Thinking: The ability to see the “big picture” and understand how vulnerability management decisions impact the entire stack — cloud, code, and vendor ecosystem alike.
- Technical Influence: The ability to drive alignment across engineering and security through expertise and collaboration rather than direct authority.
- Autonomy: Comfortable owning a program end to end and driving outcomes with minimal oversight.
- Bias for Action: A track record of closing the gap between finding a vulnerability and actually getting it fixed.