Job details
About this role
Role overview Build and evolve an automation-first vulnerability management platform that replaces manual ticket triage with systems that carry findings through validation, ownership, and remediation. This is a senior, hands-on engineering role focused on integrations, data models, and workflows rather than manual queue chasing.
Responsibilities - Own and extend a custom VM platform across deployment, integrations, data modeling, and automation pipelines in a greenfield capacity - Build automation across the full vulnerability lifecycle: triage, ticket routing, SLA tracking, ownership resolution, and follow-up using AI-assisted development tooling and an orchestration layer - Adapt a platform originally built around one team's workflow so it fits how the broader engineering organization operates, embedding it into existing processes - Integrate scanner output into the VM pipeline and maintain enrichment workflows that turn raw findings into actionable, well-owned tickets - Build queries, dashboards, and automated reports giving security and engineering leadership clear visibility into vulnerability posture - Stay current on the threat landscape, particularly AI's growing role in vulnerability research and exploitation, and factor that into prioritization - Progress toward a model where validated findings are sandbox-tested and surfaced as ready-to-merge pull requests
Requirements - 4+ years of hands-on vulnerability management and/or security engineering experience, including scanner integration, triage workflows, and remediation tracking - Production AWS experience - Deep familiarity with VM tooling such as Tenable, Semgrep, Rapid7, or comparable scanners, including API-based integrations - Strong automation-first mindset with a track record of replacing manual processes - End-to-end understanding of the software development lifecycle, including where vulnerabilities tend to originate and how to spot false positives from AI tooling - Active use of AI-assisted development workflows (such as Claude Code, Cursor, or Copilot) as a force multiplier
Nice to have - Experience with security orchestration platforms such as Tracecat, Tines, or XSOAR - Bug bounty or responsible disclosure program experience - Familiarity with CVSS, EPSS, or SSVC scoring and prioritization frameworks - Background in fintech or other regulated industries - Open-source security tooling contributions
Benefits and work setup - Health and life insurance benefits - Long-term group savings plan with employer match - 20 vacation days, wellness days, and unlimited sick and mental health days - Option to work outside the country for up to 90 days per year - Employee resource groups - Hybrid team structure with employees across North America