
Senior Security Engineer – Vulnerability Research
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Identify target attack surfaces and bug classes while developing capabilities to uncover new vulnerabilities.
• Assess newly identified vulnerabilities, prioritizing them based on exploitability and business impact.
• Offer engineering teams patch recommendations and provide working pull requests along with vulnerability reports.
• Maintain an up-to-date threat model for Tanium’s software and services.
• Propel vulnerability research through advanced AI capabilities, utilizing both in-house and external tools, as well as agentic workflows.
• Create and sustain tools for vulnerability research, which include AI competencies, fuzzing harnesses, and both static and dynamic analyzers.
• Minimize the time from detection to remediation by decreasing false positives and enhancing the quality of findings.
• Conduct source code reviews and focused security assessments on high-risk components.
• Bachelor's Degree in Computer Science or a related field, or equivalent experience.
• Over 5 years of industry experience (7+ years preferred).
• Deep understanding of web and native application security.
• Practical experience in vulnerability research through source code review, manual application penetration testing, or fuzzing.
• Proficiency in evaluating vulnerability severity, exploitability, and business impact.
• Ability to read and write code in at least one of the following: Go, C++, TypeScript/JavaScript, or Python.
• Experience in developing, building, and delivering secure code.
• Familiarity with applying advanced models to vulnerability research.
• Knowledge of reachability or exploitability analysis.
• Experience with native code security (C/C++) in privileged or agent-based software environments.
• Familiarity with cloud platforms, preferably AWS or Azure.
• Published research on vulnerabilities, credited CVEs, bounty findings, open-source security tools, or conference presentations.
• Strong understanding of applied cryptography, including encryption, hashing, and secure key management.
• Equity awards.
• Medical, dental, and vision plans.
• Family planning benefits.
• Health savings account.
• Flexible spending account.
• Transportation savings account.
• 401(k) retirement savings plan with company match.
• Life, accident, and disability coverage.
• Business travel accident insurance.
• Employee assistance programs.
• Disability insurance.
• Additional well-being benefits.
• 5 days of volunteer time off (VTO).
Cloudiax
BLUVIT GmbH
Eli Lilly and Company
S + S Regeltechnik GmbH
Get handpicked remote jobs straight to your inbox weekly.