Overview
Staff Offensive Security Engineer focused on application security and vulnerability management programs across cloud, internal systems, and IoT firmware.
What you'll do
- Lead vulnerability management strategy, operations, and continuous improvement.
- Drive down mean time to remediate (MTTR) across the vulnerability backlog as SLAs tighten.
- Build and champion automation and tooling for scalable vulnerability detection and response across cloud, firmware/IoT, and corporate systems.
- Set technical and architectural direction for the program and translate strategic priorities into execution plans.
- Partner with engineering and technical program management on remediation guidance and reporting.
- Mentor engineers on secure design and remediation practices.
- Participate in security incident investigations and support critical vulnerability response.
What you'll need
- 10+ years of relevant experience as a cloud engineer or security engineer, including hands-on vulnerability management across a broad, multi-product enterprise environment.
- Proficiency in Go, Python, and JavaScript.
- Ability to independently set technical and architectural direction for a security program.
- Experience with modern vulnerability management tooling such as Wiz and Semgrep.
- Deep familiarity with vulnerability scoring frameworks such as CVSS and EPSS.
- Strong AWS cloud services background.
- Deep understanding of SAST, DAST, and SCA.
Details
- Remote position open to candidates residing in the US (excluding the San Francisco Bay Metro Area, NYC Metro Area, and Washington, D.C. Metro Area) with working hours in the Central or Eastern time zone.
- Annual base salary range: $165,200 to $265,500 USD.
- Relocation assistance will not be provided.
Read the full description and apply on the company’s own careers page.