Overview
Security Engineer focused on vulnerability management and remediation operations, supporting the flow from vulnerability findings to risk reduction.
What you’ll do
- Triage and validate vulnerabilities from security tooling (Wiz, Semgrep, CrowdStrike Exposure Management, and EASM).
- Prioritise findings using risk-based factors such as severity, exploitability, asset criticality, and business context.
- Automate remediation workflows in the vulnerability management platform (Seemplicity) including routing, ticketing, deduplication, and escalation.
- Verify and validate fixes via targeted re-scans or manual checks before ticket closure.
- Build reports and dashboards for vulnerability posture, remediation progress, SLA adherence, and trends.
- Maintain remediation pipeline health by monitoring ageing findings and identifying systemic blockers.
- Contribute to continuous improvement of remediation operations (processes, SLAs, taxonomies, and tooling configuration).
What you’ll need
- Hands-on experience in vulnerability management or a similar analytical security role.
- Familiarity with vulnerability/exposure tooling such as Wiz, Semgrep, CrowdStrike, or EASM platforms.
- Understanding of vulnerability scoring and prioritisation concepts including CVSS, EPSS, CISA KEV exploitability, and asset context.
- Experience with or interest in workflow automation and orchestration (platform work, scripting, or tool integrations).
- Ability to facilitate risk acceptance and exception management workflow with proper documentation and tracking.
- Confidence building reports and dashboards that communicate insights clearly.
- Strong communication and stakeholder skills to explain findings and remediation progress.
Details
- Role sits in Product Security’s Remediation Operations function.
- Works within a flexible workplace model with remote work supported and encouragement of in-person gatherings.
Read the full description and apply on the company’s own careers page.