Vulnerability Engineer

Posted Aug 5

This is a fully remote position, open to applicants in India.

πŸ“‹ Description

β€’ Take ownership of initial CVSS scoring and exploitability evaluations for vulnerability risk assessments.

β€’ Reproduce and validate findings reported by customers and penetration tests prior to escalation to the Engineering team.

β€’ Oversee SAST/DAST and vulnerability-scanning automation, resolve failures, and fine-tune configurations.

β€’ Create or execute proof-of-concept exploits for chosen CVEs.

β€’ Collaborate with Engineering to prioritize and implement vulnerability fixes.

β€’ Assist the Staff Security Engineer by managing the daily workload related to vulnerability management.


⛳️ Requirements

β€’ Practical experience in managing vulnerabilities for a large SaaS product covering OS, container, and dependency exposure.

β€’ Proficient in triaging and tracking CVEs for a SaaS or containerized product.

β€’ Proven track record of reproducing and validating vulnerabilities reported by customers or identified in penetration tests.

β€’ Familiarity with vulnerability-scanning tools such as Prisma Cloud/Twistlock, JFrog, or Trivy.

β€’ Capability to build or maintain SAST/DAST pipeline automation.

β€’ Experience collaborating with Engineering to prioritize and deliver fixes.

β€’ Background in a highly regulated environment or a contemporary software company.

β€’ Strong scripting skills, preferably in Python.

β€’ Working knowledge of CVSS v3.1/v4.0 scoring.

β€’ Skills in exploit development or proof-of-concept creation, including tools like Burp Suite.

β€’ Understanding of OWASP Top 10 and related testing methodologies.

β€’ Familiarity with containers, Kubernetes, Linux, AWS, and basic networking principles.

β€’ Knowledge of authentication/authorization and API security fundamentals.

β€’ Basic ability in threat modeling.

β€’ Excellent communication skills with the ability to draft risk statements for non-technical audiences.

β€’ Ability to work effectively in ambiguous situations.

β€’ OSWA, OSWE, or similar offensive-security certification is a plus.

β€’ Familiarity with Airflow and Snowflake is a plus.


🏝️ Benefits

β€’ A teaching and learning environment equipped with the necessary tools for success.

β€’ A diverse and inclusive workplace.

β€’ A growth-oriented mindset with opportunities for personal and professional improvement.

People also viewed

AiGent2 days ago

Field Project Engineer

US flagIllinois, +10 more statesFull-timeEngineer
ApplyView job
Mercor2 days ago

Industrial Engineer

US flagUnited States OnlyFreelanceEngineer$70 – $110/hour
ApplyView job
RTX2 days ago

Principal Equipment Engineer, Adhesion & Assembly

US flagFlorida OnlyFull-timeEngineer$107.5k – $204.5k/year
ApplyView job
Expel2 days ago

Senior Detection & Response Engineer

US flagVirginia OnlyFull-timeEngineer$142.9k – $207.2k/year
ApplyView job
Qualus3 days ago

Engineer II – Relay Settings, System Protection

US flagFlorida, +2 more statesFull-timeEngineer
ApplyView job
General Dynamics Information Technology3 days ago

Senior VDI / Citrix Engineer

US flagUnited States OnlyFull-timeEngineer$149.5k – $195.5k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers