Job Description
Your work will turn security findings into durable defensive improvements, including remediation guidance, engineering-ready fix proposals, reusable AI-SDLC patterns, secure coding guidance, and product-security insights that reduce exposure and raise the bar for secure engineering.
Key Responsibilities:Identify and prioritize meaningful security risks across first-party code, services, infrastructure, build pipelines, and software supply chain components.
Validate findings for exploitability, severity, affected products, business impact, and remediation priority.
Collaborate with Security Research and Product to translate novel findings, malicious component discoveries, and emerging attack patterns into research-ready outputs, product improvements, detection opportunities, and customer-facing intelligence.
Work closely with Application Security and Engineering to move validated findings through remediation and reduce repeat vulnerability patterns.
Champion modern AI-SDLC practices by translating recurring vulnerability classes, insecure coding patterns, and effective remediation approaches into reusable guidance, detection logic, secure coding standards, and remediation playbooks.
Create clear remediation guidance, engineering-ready fix proposals, and pull requests where appropriate.
We’re seeking an experienced engineer who thrives in an agile, collaborative environment and enjoys tackling technical challenges.
Minimum Qualifications:8+ years of professional software engineering experience, including 2+ years in a Staff Engineer or equivalent technical leadership role.
Proven experience identifying, validating, and helping remediate vulnerabilities in production software, services, APIs, infrastructure, or software supply chain components.
Strong ability to read, understand, and reason about complex codebases, preferably including Java, Kotlin, or other JVM-based backend systems.
Hands-on experience with application security testing methods and tools, such as SAST, DAST, SCA, secret scanning, threat modeling, secure code review, or vulnerability validation.
Practical experience using AI-assisted engineering, security analysis, or automation techniques to improve software quality outcomes.
Ability to translate security findings into clear remediation guidance, engineering-ready recommendations, and practical risk-based priorities.
Bachelor’s degree in Computer Science, Engineering, or a related field—or equivalent practical experience.
Strong communication and collaboration skills, with experience working across Application Security, Engineering, Product, or Security Research teams.
Nice-to-Have Skills:
Solid understanding of cloud-native architecture, CI/CD workflows, build pipelines, containers, and modern DevOps practices.
Passion for raising the security bar through technical leadership, mentoring, secure engineering practices, and continuous improvement.
Relevant certifications such as:
SANS Certifications: GSEC, GCIH, GCLD, GCID, GMON
(ISC) Certifications: CISSP, CC, SSCP, CCSP, CAP, CSSL
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
