Remote job
Staff Vulnerability Management Engineer
Job details
About this role
Role overview Shape the next chapter of AI supply chain security as an individual-contributor Staff engineer leading vulnerability management for a hardened open source software platform. You will own the end-to-end pipeline for thousands of novel vulnerabilities identified weekly, calibrate response processes, and serve as a public-facing industry voice working with standards bodies, regulators, and AI model vendors. This is a technical leadership role focused on cross-team influence, automation at scale, and coordinating disclosures across customers, maintainers, and internal teams.
Responsibilities - Own measurement, disclosure, and reporting for a high-volume pipeline of newly identified vulnerabilities from frontier models and other sources. - Calibrate response processes based on emerging trends and evolving threat patterns. - Manage reporting of new vulnerabilities to upstream projects and maintainers. - Operate a CVE Numbering Authority (CNA) program, assigning CVEs where necessary. - Coordinate internal and external embargoes across customers, engineering teams, and external maintainers. - Work with public sector and industry standards bodies, including the Linux Foundation and CISA, to align on responses and emerging norms. - Represent the organization externally as a visible industry voice and partner with AI model vendors to guide the future of software supply chain security.
Requirements - Seven or more years in software security, open source maintenance, or vulnerability disclosure management. - Strong understanding of responsible disclosure principles and practices. - Practical expertise automating pipelines and processes at scale, reducing reliance on manual steps. - Deep experience working within open source communities. - Experience coordinating with public sector or industry standards bodies and working groups.
Nice to have - Established thought leadership in vulnerability disclosure management and embargoes. - Familiarity with minimal or hardened container base image ecosystems. - Experience operating a CNA. - Software engineering background in Python, Java, JavaScript, Go, or similar languages. - Background in security research, penetration testing, or bug bounties.
Benefits and work setup - Base salary range of $170,000–$231,000 USD. - Remote-first culture with team meetups, bi-annual destination summits, and a monthly stipend for coworking, phone, and internet. - Stock options with a 10-year exercise window and secondary offering participation. - 100% covered health, vision, and dental premiums for employees and dependents. - Flexible paid time off and 18 weeks paid parental leave for birthing parents, 12 weeks for non-birthing parents.