Staff Vulnerability Management Engineer
Leads vulnerability disclosure operations at scale, including novel vulnerability measurement, CVE assignment, embargo coordination, and industry collaboration. The Staff individual contributor provides technical leadership and requires extensive software security or open source experience.
About the job
Responsibilities
- Manage the novel vulnerabilities pipeline.
- Own measurement, disclosure, and reporting for thousands of novel vulnerabilities identified weekly by frontier models and other sources.
- Calibrate response processes based on emerging trends.
- Report newly discovered vulnerabilities to upstream projects and maintainers.
- Run the CNA program and assign new CVEs where necessary.
- Coordinate internal and external embargoes with customers, internal engineering teams, and external maintainers.
- Work with the Linux Foundation, CISA, and other organizations to coordinate actions and responses.
- Guide industry direction so emerging standards and norms meet customer needs.
- Represent Chainguard externally and visibly.
- Work with AI model vendors to guide the evolution of the software supply chain.
Requirements
- 7+ years of experience in software security, open source maintenance, or vulnerability disclosure management.
- Strong understanding of responsible disclosure.
- Practical expertise automating pipelines and processes at large scale while reducing human involvement.
- Deep experience with open source communities.
- Experience coordinating with public-sector organizations or industry standards bodies and working groups.
Nice to Have
- Established industry thought leadership in vulnerability disclosure management and embargoes.
- Familiarity with Chainguard Images or other minimal, hardened container base-image ecosystems.
- Experience operating a CNA.
- Software engineering background in Python, Java, JavaScript, Go, or similar languages.
- Background in security research, penetration testing, or bug bounties.
Compensation and Benefits
- Base salary: $170,000–$231,000 USD.
- Remote-first culture with team meetups, biannual destination summits, and a monthly coworking, phone, and internet stipend.
- Stock options upon hire and promotion; eligibility to participate in secondary offerings and a 10-year option exercise period.
- 100% covered health, vision, and dental insurance premiums for employees and dependents.
- Flexible time off.
- 18 weeks of paid parental leave for birthing parents and 12 weeks for non-birthing parents.
Skills
Vulnerability Management, Responsible Disclosure, Open Source, Python, Java, JavaScript, Go, Cve, Cna, Container Security, Security Research, Penetration Testing, Bug Bounties, Linux Foundation, Cisa
Similar jobs
Security Engineering jobsOwn security-critical identity and corporate security controls, managing IAM platforms, SSO/MFA integrations, RBAC policies, and endpoint trust for macOS/Windows environments.
Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.
Staff-level security engineer leading enterprise IAM, cloud identity, AI platform access, and non-human identity governance. The role requires deep Okta, infrastructure-as-code, Python, GCP or AWS, and regulated-environment experience.
Leads corporate endpoint security architecture and automation, with emphasis on macOS, Terraform, GitOps, and scalable controls across device platforms. The role partners across security and IT, improves detection and auditability, and mentors engineers.
Own the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.