
Senior Security Research Engineer
Posted Aug 7

Posted Aug 7
This is a fully remote position, open to applicants in California.
• Oversee intricate Global Vulnerability Management workstreams to enhance Threat Exposure Management and facilitate the transition to a Continuous Threat Exposure Management operating model.
• Convert annual TEM objectives into actionable delivery plans, milestones, success metrics, dependencies, and standardized operating practices.
• Conduct direct vulnerability research and technical analysis to verify security conditions, eliminate false positives, assess exploitability and business impact, and offer remediation or mitigation recommendations.
• Enhance vulnerability discovery and evaluation across various technology environments including network, cloud, endpoint, application, container, and database.
• Establish risk-based prioritization by leveraging vulnerability and threat intelligence, evidence of exploitation, asset and business context, control effectiveness, and remediation considerations.
• Direct security validation efforts and create proofs of concept when necessary.
• Collaborate with Information Security teams and technology stakeholders to drive remediation efforts and track progress.
• Advance vulnerability management platforms, integrations, data analytics, automation, and AI-driven workflows.
• Convey vulnerability trends, significant risks, remediation status, and program results to technical, operational, and leadership audiences.
• Coach engineers and partner teams, contribute to technical standards and procedures, and enhance vulnerability analysis methodologies.
• Keep up-to-date with vulnerabilities, exploitation methods, threat activities, security technologies, and industry standards.
• Some travel may be necessary.
• 8+ years of relevant experience in information security, information technology, systems engineering, or a related field, with significant experience in vulnerability management, security research, or exposure management.
• Bachelor’s degree or equivalent in computer science, information security, or a related field.
• Proven ability to lead complex technical workstreams across multiple teams and achieve measurable outcomes without direct reporting authority.
• Practical experience in vulnerability research, technical analysis, security validation, risk-based prioritization, and providing remediation or mitigation guidance.
• Experience in assessing vulnerabilities across operating systems, networks, cloud services, applications, endpoints, containers, databases, or hybrid infrastructures.
• Familiarity with vulnerability discovery, assessment, validation, or exposure management platforms and their respective integrations.
• Understanding of adversarial tactics, exploitation techniques, threat intelligence, and attack frameworks like MITRE ATT&CK.
• Proficient in scripting, programming, APIs, or automation; relevant technologies may include Python, SQL, Bash, PowerShell, or JavaScript.
• Ability to analyze and contextualize security data across asset, service, business, threat, control, and remediation information.
• Knowledge of version control, testing, code review, CI/CD, reusable components, and controlled production releases.
• Strong communication skills to articulate complex security conditions, priorities, trade-offs, and recommendations clearly.
• Experience mentoring engineers or analysts and influencing technical practices across teams.
• Background check required at the offer stage for new hires.
• Preferred: experience with TEM/CTEM operating models, continuous security validation, exploit research, cloud/container/application/build-pipeline security, Snowflake or Domo, and automation, analytics, or AI-enabled security workflows.
• Medical insurance
• Dental insurance
• Vision insurance
• Matching 401(k)
• Paid time off
• Wellness program
• Employee discounts for Sony products
• Potential eligibility for a bonus package
• Flexible/remote work arrangement
• Background checks conducted at the offer stage
Netflix
XBOX
Wells Fargo
Avenga
Get handpicked remote jobs straight to your inbox weekly.