Source Job

$170,000–$231,000/yr
United States Unlimited PTO 18w maternity 12w paternity

  • Manage a novel vulnerabilities pipeline, owning measurement, disclosure, and reporting of thousands of vulnerabilities weekly.
  • Coordinate across the industry with bodies like the Linux Foundation and CISA, and represent Chainguard externally.
  • Guide industry direction and work with AI model vendors to evolve software supply chain security.

Vulnerability Management Security Research Python Automation

20 jobs similar to Staff Vulnerability Management Engineer

Jobs ranked by similarity.

United States

  • Lead complex Global Vulnerability Management workstreams to advance Threat Exposure Management capabilities and transition to a Continuous Threat Exposure Management model.
  • Conduct hands-on vulnerability research, technical analysis, and security validation to eliminate false positives, characterize exploitability, and provide actionable remediation guidance.
  • Partner across Information Security and engineering teams to evolve platforms, integrations, and automation for improved discovery, prioritization, and remediation outcomes.

Sony Interactive Entertainment (SIE) is the company behind the PlayStation brand, delivering innovative gaming hardware and network services to over 100 million people worldwide. As a subsidiary of Sony Group Corporation, SIE is a dynamic and entertainment-focused organization that values innovation, excellence, and employee empowerment.

Canada

  • Leads product security work across Black Duck's portfolio, including architecture reviews, threat models, vulnerability triage, and customer-facing security inquiries.
  • Maintains detection content in CrowdStrike NG-SIEM and Sumo Logic, contributes to SOAR automations, and coordinates vulnerability fixes with engineering teams.
  • Acts as an informal technical resource for less experienced team members, explains complex security topics to diverse stakeholders, and documents runbooks and SOPs.

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. A recognized pioneer in application security with industry-leading tools and services, they partner with teams to maximize security and quality in DevSecOps.

India

  • Manage vulnerability assessments across operating systems, containers, dependencies, and application environments.
  • Perform vulnerability triage, validation, and proof-of-concept testing to determine real-world security impact.
  • Collaborate with engineering teams to communicate risks and drive remediation efforts.

This company provides a large-scale software platform for AI and data science solutions, serving organizations with demanding compliance and risk requirements. It fosters a culture of innovation, transparency, and collaboration, with a growing security function and an inclusive workplace.

EMEA

  • You'll lead the VIPR & VMDR function, integrating vulnerability intelligence, detection, and response for customers across APJ/APAC.
  • You'll operate and tune vulnerability detection tools like Tenable, Qualys, and Rapid7, and automate pipelines using Python and REST APIs.
  • You'll build risk dashboards and executive briefings, and collaborate with Customer Success and Security Engineering to improve remediation metrics.

ServiceNow is the AI control tower for business reinvention, bringing together AI, data, and workflows to help 85% of the Fortune 500 work smarter. The company fosters an AI-native culture where technology and talent are unstoppable together.

$121,000–$181,600/yr
United States Canada

  • Analyze, assess, reproduce, and triage incoming security vulnerability reports from the bug bounty program.
  • Communicate clearly with security researchers and drive the lifecycle of submissions through to resolution.
  • Understand root causes of vulnerabilities and advise on mitigation strategies to improve security posture.

Stripe is a financial infrastructure platform for businesses, enabling millions of companies to accept payments, grow revenue, and accelerate new business opportunities. As a large, mission-driven company, Stripe fosters a culture of passion, grit, and integrity with diverse perspectives.

$41–$51/hr
US

  • Own the vulnerability management program, prioritizing and driving a culture of ownership across business units.
  • Drive metrics and program review to transparently communicate performance and accountability.
  • Provide expert leadership to highly visible, multi-faceted projects while coordinating across teams and geographies.

We empower organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity of our customers and trusted alliance of elite hackers with our patented data and AI-powered Security Knowledge Platform. We are based in San Francisco and New Hampshire, supported by General Catalyst and others, and we foster a diverse and inclusive culture.

US 3w PTO

  • Lead the enterprise Vulnerability Management and CDM program, directing scanning and prioritization strategies.
  • Coordinate remediation activities across system owners, engineering teams, and ISSOs to reduce cyber risk.
  • Develop executive metrics, dashboards, and reports to communicate vulnerability posture and operational risk trends.

True Zero Technologies is a veteran-owned small business that focuses on purposeful enablement of people and technology. Recognized as a Best Places to Work in 2023 and 2025, and listed on the Inc. 5000 fastest-growing companies, the company emphasizes a people-first culture and dedication to excellence.

$153,000–$214,000/yr
US Canada

  • Lead end-to-end response to product security incidents, from discovery to disclosure.
  • Own and evolve 1Password's PSIRT function, including severity frameworks and playbooks.
  • Drive coordinated vulnerability disclosure and partner with external security researchers.

1Password is a cybersecurity company providing enterprise password management and Unified Access Management, trusted by over 180,000 businesses. With $400M ARR and a remote-first culture, it values collaboration, transparency, and innovation.

US

  • Oversee the enterprise vulnerability management program, including administering Tenable platforms and conducting regular assessments.
  • Monitor and respond to MDR alerts, investigate security incidents, and coordinate remediation efforts.
  • Review and approve cybersecurity-related change requests, ensuring security risks are communicated and mitigated.

Loenbro is a trusted, long-term construction lifecycle partner serving thousands of customers across the U.S. They have a national presence with a local approach, and build careers grounded in integrity, teamwork, excellence, and purpose.

US

  • Diagnose and resolve customer-reported issues quickly, from investigation through durable fix.
  • Deliver high-quality engineering work that improves platform reliability and directly addresses customer needs.
  • Partner closely with Customer Success to align on technical solutions and maintain backend systems, APIs, and data pipelines.

VulnCheck is The Exploit Intelligence Company, delivering structured exploit intelligence for exploitation prevention. Founded in 2021, the company has a transparent, collaborative, and supportive culture with a team of cybersecurity experts.

$205,000–$231,000/yr
US Unlimited PTO 18w maternity 12w paternity

  • Own detection quality, platform strategy, and customer experience for Chainguard's malware scanning platform.
  • Drive the roadmap for the shared scanning platform, scaling it to support containers, libraries, and AI agent skills.
  • Partner with Engineering and Product Security to expand threat detection capabilities and define how organizations evaluate software trust.

Chainguard provides hardened, secure, and production-ready builds of open source software. They are a venture-backed company with Fortune 500 clients and a culture focused on customer obsession and intentional action.

$120,000–$140,000/yr
US Unlimited PTO

  • Define and enforce security requirements for software products, features, and components.
  • Design, perform, and maintain security analysis on commercial products throughout the product lifecycle.
  • Collaborate with cross-functional teams to perform vulnerability management and implement mitigation strategies.

symplr is revolutionizing healthcare operations with a platform that drives effective, efficient, and connected workflows. The company is remote-first with employees across the US, India, and the Netherlands, and values teamwork, customer focus, and integrity.

$155,000–$160,000/yr
US

  • Oversee daily vulnerability identification, triage, and reporting across AWS cloud assets and AI/LLM application stacks.
  • Leverage ACAS (Tenable.sc) and AWS security tools to evaluate threat vectors and ensure compliance with DISA STIG benchmarks.
  • Translate complex technical findings into actionable remediation guidance and executive briefings for government stakeholders.

Dark Wolf is a cybersecurity firm specializing in vulnerability management and cloud security for federal and DoD systems. The company maintains a collaborative, mission-focused culture with a team of cybersecurity professionals.

Ireland

  • Investigate and resolve customer technical issues across cloud security posture management, vulnerability scanning, and threat detection in AWS, Azure, and GCP environments.
  • Troubleshoot cloud connector and integration failures, including IAM, network connectivity, and API authentication issues.
  • Design and implement automation leveraging AI agents to improve triage accuracy and resolution efficiency.

Wiz provides an AI-powered cloud security platform that connects code, cloud, and runtime to secure cloud and AI applications, trusted by over 65% of the Fortune 100. As one of the fastest-growing startups, powered by Google, Wiz has a culture that values world-class talent and encourages creative thinking.

$116,000–$183,000/yr
US

  • Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement.
  • Lead triage and technical validation of incoming reports across multiple intake channels, driving end-to-end vulnerability remediation.
  • Collaborate with the Security Incident Response Team on active incidents and perform targeted code reviews.

Mozilla Corporation is a non-profit-backed technology company that has shaped the internet for the better over the last 25 years. With over 225 million people using our products monthly, we are a mission-driven organization focused on privacy, open-source software, and reclaiming the internet for people.

$170,000–$170,000/yr
US

  • Identify novel vulnerabilities in industrial products and control systems through strategic acquisition and rigorous analysis.
  • Develop detection signatures (Suricata, YARA, internal analytics) and partner with product engineering to close gaps in the Dragos Platform's vulnerability detection.
  • Serve as a trusted internal resource to threat intelligence and incident response teams, assessing in-the-wild exploits and integrating findings into broader threat intelligence.

Dragos is the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services to protect critical infrastructure. The company is a remote-first, mission-driven team across North America, Europe, the Middle East, and APAC, built on authenticity, transparency, and trust.

US

  • Manage the vulnerability management program end-to-end, including scanning and remediation.
  • Collaborate with developers on secure architecture, threat modeling, and code dependency reviews.
  • Oversee bug bounty programs, security tools, incident response, and compliance frameworks.

RainFocus provides an industry-disrupting event management platform for Fortune 500 companies like Adobe, Cisco, and IBM. The company is well-funded, rapidly growing, and fosters a culture of innovation, teamwork, and fun.

Global

  • Own production security across a multi-cloud footprint (AWS, GCP, Azure, Vercel) and secure multi-tenant SaaS, dedicated VPC, and air-gapped deployments.
  • Secure the Hermes Agent platform with sandboxing, kernel-level isolation, and agent identity controls, and lead SOC 2 compliance.
  • Harden identity management, vulnerability management, incident response, and secure software development lifecycle practices.

Nous Research builds open-source AI language models and agents, including Hermes Agent, used by consumers and Fortune 500 enterprises across various deployment environments. The company is a fast-growing startup with a high-velocity, open-source-native engineering culture that values security and pragmatism.

Canada

  • Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features and APIs.
  • Develop and maintain scalable security tools and automation pipelines for vulnerability detection across the SDLC.
  • Contribute to security architecture reviews and support bug bounty programs and incident response.

Lime is a global leader in micromobility on a mission to make transportation shared, affordable, and carbon-free. A Time Magazine 100 Most Influential Company, Lime has powered over a billion rides in 30 countries and is a fast-paced, lean, remote-first team.

UK Unlimited PTO 18w maternity 12w paternity

  • Provide vision, mentorship, and strategic leadership for a diverse engineering team building secure open source libraries at scale.
  • Guide technical direction and product strategy spanning language ecosystems, dependency management, security hardening, tooling, automation, and services.
  • Set policies, quality standards, and continuous improvement while balancing security, performance, stability, and customer value.

Chainguard provides hardened, secure, and production-ready builds of open source software. It is venture-backed by leading investors and serves Fortune 500 enterprises and global industry leaders.