
Senior Staff Software Engineer, Vulnerability Management
Posted Jul 17

Posted Jul 17
This is a fully remote position, open to applicants in United States.
• Taking ownership of the technical roadmap for an automated, AI-driven vulnerability scanning platform that spans cloud infrastructure, container registries, operating systems, and application-layer software.
• Developing context-engine models that link findings from SAST, DAST, SCA, and cloud posture tools to assess true runtime exploitability.
• Establishing AI-assisted triage workflows that categorize vulnerabilities, minimize false positives, and direct confirmed issues to the appropriate engineering teams.
• Leading focused red teaming and collaborative purple teaming exercises to verify exploitable paths and enhance runtime defenses.
• Collaborating directly with Software Engineering and DevOps teams to create automated remediation pipelines, which include dependency update pull requests and base-image patching workflows.
• Integrating security scanning guardrails into CI/CD pipelines and offering structured telemetry to ensure continuous compliance and provide executive risk visibility.
• Utilizing advanced GenAI tools and technologies to analyze findings, enhance prioritization, and expedite remediation workflows.
• Substantial experience in security engineering, vulnerability management, or software development, with a minimum of 8 years concentrated on infrastructure, container platforms, and product security.
• A demonstrated history of creating production-grade automation scripts and developing custom security tools at scale.
• Practical experience in planning or executing offensive security exercises, including red teaming, purple teaming, or penetration testing.
• Extensive experience securing cloud infrastructure and containerized ecosystems using platforms like AWS, GCP, or Azure, as well as Docker and Kubernetes.
• Advanced skills in Python, Go, or Rust for automation, integrating scanner APIs, and orchestrating automated patching workflows.
• Strong understanding of adversarial frameworks, vulnerability scoring systems like CVSS and EPSS, and common application and infrastructure attack vectors, including the OWASP Top 10.
• Experience in integrating security scanners into CI/CD workflows and utilizing AI or LLM APIs to analyze code or log data for swift prioritization.
• Essential: the capability to incorporate generative AI tools into daily workflows to automate tasks, encourage innovation, and maximize productivity.
• Advanced security certifications such as OSCE, OSCP, GXPN, CISSP, or comparable practical engineering experience are highly esteemed.
• Flexible work environment
• Unlimited Vacation
• 100% paid employee health benefit options (including medical, dental, and vision)
• 401(k) with employer funded match
• Corporate wellness programs with Headspace and Peloton
• Sabbatical leave (for employees with 5+ years of service)
• Competitive paid parental leave and fertility/family planning reimbursement
• Cell phone reimbursement
• Employee Resource Groups and ZocClubs to promote shared community and belonging
• Great Place to Work Certified
Spartech LLC
Montreal Oficial
HappyOps
Medallion
Get handpicked remote jobs straight to your inbox weekly.