Senior Security Engineer, Vulnerability Management
Accountabilities: Lead end-to-end response for product security incidents, including identification, triage, investigation, remediation, disclosure, and post-incident review.
Own and continuously improve the Product Security Incident Response (PSIRT) program, including response playbooks, severity frameworks, escalation procedures, and operational standards.
Manage coordinated vulnerability disclosure activities by working with external security researchers and bug bounty programs to ensure responsible vulnerability handling.
Partner cross-functionally with Engineering, Legal, Communications, Customer Success, and other stakeholders to coordinate security incidents and customer communications.
Develop automation, tooling, and AI-powered workflows that improve incident detection, investigation, response times, and operational efficiency.
Contribute to customer-facing security advisories, CVE publications, and public incident communications while ensuring accuracy and transparency.
Conduct post-incident reviews, identify root causes, and implement long-term improvements to products, detection capabilities, and operational processes.
Mentor security engineers, contribute to the maturity of vulnerability management programs, and participate in an on-call rotation supporting critical security incidents.
Requirements
5+ years of experience in IT, software engineering, or cybersecurity with a strong focus on product security or vulnerability management.
Proven experience leading or participating in security incident response within SaaS, cloud, or product-driven environments.
Hands-on knowledge of coordinated vulnerability disclosure processes and working with external security researchers.
Strong understanding of vulnerability assessment methodologies, incident severity frameworks, and security best practices.
Experience developing incident response playbooks, automation, security tooling, or response frameworks from the ground up.
Ability to read and write code to support investigations, automation, scripting, or forensic analysis.
Experience using AI or machine learning technologies to improve security operations, automate workflows, or enhance detection capabilities.
Excellent analytical, communication, and stakeholder management skills with the ability to make sound decisions under pressure.
Ability to collaborate across technical and non-technical teams while mentoring colleagues and driving continuous improvement.
Experience with CVSS, EPSS, SBOMs, supply chain security, compliance frameworks (SOC 2, ISO 27001), or relevant security certifications is considered an advantage.
Benefits
Annual base salary ranging from $153,000 to $214,000 USD , based on experience and qualifications.
Comprehensive medical, dental, and health insurance coverage.
Equity grant and participation in incentive programs.
401(k) retirement savings program.
Generous paid time off and parental leave benefits.
Remote-first work environment with opportunities for in-person team gatherings and offsites.
Paid volunteer days and employee recognition programs.
Complimentary premium account access.
Professional development opportunities within a collaborative, innovative security organization.
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1