Source Job

US 13w maternity 13w paternity

  • Design, build, and operate services powering the Exposure Management platform across the full production lifecycle.
  • Work with large volumes of security data to improve scanning, asset discovery, and vulnerability prioritization.
  • Collaborate with product, threat research, and client-facing teams to turn security requirements into production-ready features.

Python TypeScript AWS Azure

20 jobs similar to Senior Software Engineer, Exposure Management

Jobs ranked by similarity.

India

  • Own security architecture across Azure and AWS, covering tenant design, network segmentation, and workload isolation.
  • Raise the engineering bar with hardened infrastructure-as-code modules, secure defaults, and policy-as-code signals at commit time.
  • Own vulnerability and exposure management end to end, delivering findings as pull requests, not tickets.

One Identity enables organizations to secure, manage, monitor, protect, and analyze information and infrastructure to drive innovation. With a globally distributed team, we build enterprise products at scale and foster a collaborative, improvement-driven culture.

US Unlimited PTO

  • Deploy, configure, and operate Axonius Asset Cloud for risk-based vulnerability management.
  • Build unified asset inventories, prioritization models, and automated remediation workflows.
  • Support security platform operations and automation to drive risk reduction.

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations minimize risk. With over 1,300 employees and strong core values, it serves more than 6,200 customers.

Global 5w PTO

  • Conduct hands-on application security reviews threat modeling and code audits across the entire stack (backend frontend APIs infrastructure).
  • Build and improve security automation for vulnerability management including SAST DAST container scanning and secrets detection.
  • Drive remediation of findings from bug bounty scanners and audits partnering with engineering teams to prioritize and fix.

Close builds a communication-first AI-powered CRM that helps sales teams sell more and faster. With a 120-person 100% remote team they are bootstrapped profitable and focused on eliminating manual data entry for scaling businesses.

US

  • Lead threat modeling and security reviews across Wiz's products and cloud infrastructure, identifying attack surfaces and developing scalable mitigation strategies.
  • Build automation, policy-as-code, and security tooling that enables development teams to 'shift left' and integrate end-to-end security into their workflows.
  • Drive vulnerability management and remediation efforts, prioritizing issues, implementing mitigations, and designing strategic preventative controls in software supply chains from development through production.

Wiz is redefining security for the AI era, enabling teams to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. As one of the fastest-growing startups ever, we are trusted by over 65% of the Fortune 100 and scan over 230 billion files daily, with a culture that values world-class talent and is now powered by Google.

$95,000–$130,000/yr
US

  • Run continuous vulnerability scanning in Tenable and CrowdStrike Falcon to ensure full coverage of cloud assets.
  • Prioritize findings by real-world risk using exploitability, threat intelligence, and asset context, and validate high-priority findings hands-on.
  • Automate scan-to-ticket workflows with Python, push validated fixes through Jira, and help define vulnerability management standards and SLAs.

Revinate is the hotel data activation platform that connects and cleans guest data from every system into Rich Guest Profile data, powered by an AI intelligence layer trained on 17 years of hospitality data. Revinate powers 1.1 billion data points across 12,500+ hotels, driving over $24 billion in direct revenue, and is proud to be a Great Place To Work Certified company.

  • Own end-to-end vulnerability lifecycle, attack surface management, and cloud security posture across AWS, Azure, and OCI.
  • Operate CTEM phases, consolidate exposure data into prioritized views, and track KPIs for stakeholder reporting.
  • Embed security into SDLC, support penetration testing, and translate technical risk clearly for business audiences.

Version 1 is a trusted technology and transformation solutions provider with partnerships including Microsoft, AWS, and Oracle. We're an award-winning, values-driven employer of 3,300+ people and a Great Place to Work in the UK and Ireland.

$170,000–$235,000/yr
US

  • Design and implement backend services for licensing, entitlements, feature access, and usage limits across NodeZero's product and APIs.
  • Build and evolve provisioning, admin experience, MSP/MSSP capabilities, and audit logging for a multi-tenant SaaS platform.
  • Operate production services with monitoring, incident response, and a high bar for design quality and test coverage.

Horizon3 is a fast-growing, remote cybersecurity company that helps organizations proactively find, fix, and verify exploitable attack vectors through its NodeZero autonomous pentesting platform. The team is a fusion of former special operations cyber operators and startup engineers, fostering a culture of respect, collaboration, ownership, and results.

$157,667–$283,801/yr
US

  • Lead security operating reviews, scorecards, dashboards, and executive reporting for the FSD business unit.
  • Coordinate security risks, issues, and metrics with the Global Security Office and business leaders.
  • Track AWS security posture and vendor PoV, turning security data into clear priorities.

Experian is a global data and technology company operating across financial services, healthcare, automotive, and more. We have an amazing team of 25,200 people in 32 countries with an inclusive, purpose-driven culture.

$157,675–$238,500/yr
US

  • Build, deploy, and continuously improve MITRE ATT&CK–aligned detections across cloud, endpoint, identity, email, and application telemetry with clear false-positive thresholds.
  • Own the full detection lifecycle from hypothesis and data validation through deployment, tuning, and retirement.
  • Advance the detection-as-code platform with version control, peer review, automated testing, CI/CD, and improved pipeline reliability and observability.

Samsara is the pioneer of the Connected Operations™ Cloud, helping organizations that depend on physical operations to harness IoT data for actionable insights. They are a recently public company with a high-caliber team, embracing a flexible working model that supports remote and hybrid work.

$108,000–$140,000/yr
US

  • Design, implement, and maintain internal tooling for acquiring and parsing recaptured underground data.
  • Build and deploy cloud infrastructure using Infrastructure as Code technologies.
  • Collaborate with the research team to support targeting and collection of new data sources.

SpyCloud transforms recaptured darknet data to disrupt cybercrime. They have over 250 cybersecurity experts and foster a collaborative, innovative culture.

Europe 16w maternity 16w paternity

  • Own identity, SSO, and device management across Google Workspace and macOS, automating joiner and leaver flows from day one.
  • Secure cloud and SaaS environments by managing IAM, cloud guardrails, and vulnerability management end to end.
  • Bring a security perspective to incidents and audits, using AI-assisted workflows to reduce manual work.

Maze is a user research platform that helps product teams build the right products faster by making user insights accessible. With less than 150 team members and a global remote workforce, Maze fosters a culture of transparency and inclusion.

$214,200–$308,000/yr
US

  • Serve as deputy to the CISO, representing security to executives, customers, and regulators.
  • Lead and grow managers and senior engineers across Security Engineering and Security Operations.
  • Own the security roadmap, including cloud security, detection and response, identity, and platform security.

Abnormal Security uses behavioral AI to protect organizations from sophisticated email and collaboration attacks. Trusted by 5,000 enterprises, the company values security engineering, partnership, and a paved-path approach to reducing risk.

  • Own vulnerability management across code, dependencies, images, and cloud config, automating triage and remediation.
  • Build and expand security gates in CI/CD pipelines, define secure cloud baselines, and drive least privilege identity.
  • Partner with DevOps on paved roads for secure-by-default development and lead incident response.

Aegis AI is a startup founded by ex-Google engineers who built Safe Browsing and reCAPTCHA, focused on stopping adversarial AI attacks. The team is flat, flexible, and fast, with engineers owning decisions and clear KPIs.

North America Unlimited PTO

  • Architect and develop secure backend services for Access Security using AI.
  • Collaborate with cross-functional teams to deliver enterprise-ready identity intelligence.
  • Own end-to-end feature delivery and mentor engineers.

ServiceNow is an AI control tower for business reinvention, uniting AI, data, and workflows to help enterprises work smarter. It serves 85% of the Fortune 500 and fosters an AI-native culture where technology and talent are unstoppable.

US

  • Develop playbooks and address security-related tasks in AWS serverless environments.
  • Drive improvements in security posture, including application, endpoint, and access management.
  • Collaborate with product engineering teams to raise the bar for security in CI/CD, dependency management, and secure design reviews.

Stedi is building a new healthcare clearinghouse and RCM engine, accessible via API. With $142 million in funding and a lean, passionate team, they ship products weekly and prioritize automation and eliminating toil.

US

  • Own and evolve AWS architecture for enterprise workloads, including multi-account foundations and security baselines.
  • Drive operational excellence through monitoring, alerting, incident response, and on-call rotation.
  • Automate infrastructure using Infrastructure as Code (Pulumi/SST) and CI/CD with Bitbucket Pipelines or GitHub Actions.

Praxis is a clinical-stage biopharmaceutical company translating genetic insights into therapies for central nervous system disorders. The company offers a world-class benefits package and values trust, ownership, curiosity, and results.

$120,000–$150,000/yr
US

  • Fix vulnerabilities across the stack by writing pull requests in application repositories and Terraform.
  • Build and tune SIEM detections, mapping coverage to MITRE ATT&CK and reducing false positives.
  • Lead incident response, harden AWS estate, and automate security workflows with code.

Cloudbeds is a hospitality management platform powering hotels across 150 countries, processing billions in bookings annually. The company is a remote-first team of 650+ across 40+ countries, recognized for innovation and an inclusive culture.

US

  • Own and mature preventative security capabilities across cloud, SaaS, endpoint, identity, network, and data environments.
  • Translate broad security objectives into concrete technical requirements, controls, tooling, and implementation plans.
  • Partner across Engineering, Platforms, Product, and business teams to continuously strengthen security posture as we scale.

Backstory is the leading AI answers platform for sales teams, helping modern sales teams ask questions and get the right answer in real time. Backed by top investors like Andreessen Horowitz and ICONIQ Capital, Backstory is based in San Francisco and has been recognized by Gartner, Forrester, and the Forbes AI 50.

$133,000–$209,000/yr
US

  • Design and continuously improve detection and alerting controls to reduce noise and enable rapid response.
  • Build, test, and automate incident response playbooks to increase efficiency across the incident lifecycle.
  • Drive prioritization of alerts using a data-driven triage framework aligned with business impact and threat context.

Sword builds AI to heal billions, pioneering AI Care for healthcare delivery across physical therapy, women’s health, and more. With over 700,000 members and 1,000+ enterprise clients, they have raised $500 million and emphasize a culture of proactive security and AI proficiency.

Canada

  • Provide technical and operational leadership for a Security Operations Center, monitoring threats and driving incident response.
  • Design and develop security tools and platforms to improve detection, response, and operational efficiency.
  • Mentor early-career engineers and contribute to open source security projects and industry conferences.

Jobgether uses AI-powered matching to help candidates find jobs. The company operates a fully distributed, remote-first environment with in-person team events.