Remote job
Senior Security Engineer, Customer Transparency
Job details
About this role
Role overview A Senior Security Engineer role on the Customer Transparency team within an R&D Security organization that protects software and cloud services used by enterprise customers. The position represents the security function externally, owning the vulnerability disclosure program, SBOM and vulnerability management, and customer-facing security communications. It blends hands-on security engineering with customer engagement and external researcher coordination.
Responsibilities - Build and maintain security tooling, applying AI where it genuinely streamlines security work. - Identify blind spots in what customers can observe about their own deployment and partner with Engineering and Product to close them. - Operate the SBOM and vulnerability management program and surface appropriate visibility to internal and external stakeholders. - Act as a security technical resource for customer-facing teams, answering inbound inquiries, maintaining a reusable answer library, and interfacing directly with customers when needed. - Administer the bug bounty program, triaging submissions against SLA, assessing exploitability and severity, judging duplicates and scope, recommending awards, and managing researcher relationships. - Author and publish security advisories and CVE records with CWE classification and CVSS scoring. - Coordinate disclosure timing and embargoes across researchers, customers, partners, and external coordinating bodies.
Requirements - Bachelor's degree in Computer Science or a related field, or equivalent experience. - 5+ years of industry experience, with 7+ preferred, in product or application security, vulnerability research, or security-focused software engineering. - Track record interacting with customers and external security researchers. - Practical experience applying AI tooling to security work, with a clear view of where it helps and where it adds noise. - Experience building tools or data interfaces consumed by external stakeholders such as support and customers. - Familiarity with modern software engineering tooling including git and CI/CD pipelines. - Demonstrated ability to judge the severity and exploitability of vulnerabilities and their business impact.
Nice to have - Experience with SCA/SBOM tooling and third-party dependency vulnerability management. - Coordinated vulnerability disclosure expertise, including CVE assignment, CVSS, CWE, and CNA operations. - Experience running or substantially supporting a bug bounty program or VDP. - Published research, credited CVEs, bug bounty findings, open-source security tooling, or conference talks. - Applied cryptography knowledge including encryption, hashing, and secure key management.
Benefits and work setup - Annual base salary range of $191,000 to $293,000, plus equity awards. - Medical, dental, and vision coverage, family planning benefits, HSA and FSA options, transportation savings account, and 401(k) with company match. - Life, accident, disability, and business travel accident insurance, plus employee assistance programs. - Volunteer time off and a recognized inclusive workplace culture.