Source Job

Brazil

  • Triage inbound vulnerabilities: validate, classify, and prioritize based on real exploitability and business impact.
  • Perform blast-radius and impact analysis across affected systems and downstream consumers.
  • Own the secrets rotation strategy: inventory affected credentials and sequence rotation safely across production systems.

Vulnerability Management AWS Security Secrets Management PHP Threat Modeling

20 jobs similar to Security Triage & Remediation Lead

Jobs ranked by similarity.

US

  • Manage the vulnerability management program end-to-end, including scanning and remediation.
  • Collaborate with developers on secure architecture, threat modeling, and code dependency reviews.
  • Oversee bug bounty programs, security tools, incident response, and compliance frameworks.

RainFocus provides an industry-disrupting event management platform for Fortune 500 companies like Adobe, Cisco, and IBM. The company is well-funded, rapidly growing, and fosters a culture of innovation, teamwork, and fun.

Brazil

  • Research and remediate prioritized security vulnerabilities in PHP code, including injection, authentication, and deserialization defects.
  • Perform AWS-side remediation and deployment, including configuration hardening, IAM adjustments, and secret rotation.
  • Validate fixes with automated tests and document closure evidence for the client's risk program.

CI&T helps large enterprises transform the potential of AI into real business impact with AI deployment, AI-native execution, and tech-integrated business solutions. With 30 years of experience and 8,000 employees across more than 25 countries, the company fosters a collaborative culture focused on building secure, resilient software.

US 3w PTO

  • Lead the enterprise Vulnerability Management and CDM program, directing scanning and prioritization strategies.
  • Coordinate remediation activities across system owners, engineering teams, and ISSOs to reduce cyber risk.
  • Develop executive metrics, dashboards, and reports to communicate vulnerability posture and operational risk trends.

True Zero Technologies is a veteran-owned small business that focuses on purposeful enablement of people and technology. Recognized as a Best Places to Work in 2023 and 2025, and listed on the Inc. 5000 fastest-growing companies, the company emphasizes a people-first culture and dedication to excellence.

India

  • Manage vulnerability assessments across operating systems, containers, dependencies, and application environments.
  • Perform vulnerability triage, validation, and proof-of-concept testing to determine real-world security impact.
  • Collaborate with engineering teams to communicate risks and drive remediation efforts.

This company provides a large-scale software platform for AI and data science solutions, serving organizations with demanding compliance and risk requirements. It fosters a culture of innovation, transparency, and collaboration, with a growing security function and an inclusive workplace.

US

  • Lead bug bounty program strategy and vulnerability management initiatives.
  • Collaborate with engineering and security teams to drive remediation efforts.
  • Conduct code reviews and develop security tooling to improve efficiency.

This company operates a global technology platform. It values security, collaboration, and continuous learning, with a team dedicated to protecting user privacy and safety.

Canada Unlimited PTO

  • Secure cloud infrastructure, applications, APIs, and AI-driven workflows.
  • Partner with engineering to embed security controls into production.
  • Lead vulnerability management and incident response activities.

Jobgether is an AI-powered job matching platform that connects candidates with hiring companies. The company is a high-growth startup with a remote-first culture, emphasizing transparency, autonomy, and technical craftsmanship.

$140,000–$165,000/yr
US

  • Own cloud security posture across AWS environment using Wiz and AWS-native services.
  • Harden CI/CD pipelines, manage vulnerability intake, prioritization, and remediation.
  • Build automation, instrument telemetry, and operate WAF for cloud and application security.

Beyond Finance helps everyday Americans escape debt through compassionate, individualized care and supportive technology. They are a rapidly growing organization with over 1 million clients served and a culture focused on compliance and ethics.

$116,000–$183,000/yr
US

  • Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement.
  • Lead triage and technical validation of incoming reports across multiple intake channels, driving end-to-end vulnerability remediation.
  • Collaborate with the Security Incident Response Team on active incidents and perform targeted code reviews.

Mozilla Corporation is a non-profit-backed technology company that has shaped the internet for the better over the last 25 years. With over 225 million people using our products monthly, we are a mission-driven organization focused on privacy, open-source software, and reclaiming the internet for people.

$120,000–$140,000/yr
US Unlimited PTO

  • Define and enforce security requirements for software products, features, and components.
  • Design, perform, and maintain security analysis on commercial products throughout the product lifecycle.
  • Collaborate with cross-functional teams to perform vulnerability management and implement mitigation strategies.

symplr is revolutionizing healthcare operations with a platform that drives effective, efficient, and connected workflows. The company is remote-first with employees across the US, India, and the Netherlands, and values teamwork, customer focus, and integrity.

Canada

  • Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features and APIs.
  • Develop and maintain scalable security tools and automation pipelines for vulnerability detection across the SDLC.
  • Contribute to security architecture reviews and support bug bounty programs and incident response.

Lime is a global leader in micromobility on a mission to make transportation shared, affordable, and carbon-free. A Time Magazine 100 Most Influential Company, Lime has powered over a billion rides in 30 countries and is a fast-paced, lean, remote-first team.

$170,000–$231,000/yr
United States Unlimited PTO 18w maternity 12w paternity

  • Manage a novel vulnerabilities pipeline, owning measurement, disclosure, and reporting of thousands of vulnerabilities weekly.
  • Coordinate across the industry with bodies like the Linux Foundation and CISA, and represent Chainguard externally.
  • Guide industry direction and work with AI model vendors to evolve software supply chain security.

Chainguard is the trusted source for open source, delivering hardened, secure, and production-ready builds of open source software. The company is venture-backed by leading investors and serves Fortune 500 enterprises and global industry leaders.

$153,000–$214,000/yr
US Canada

  • Lead end-to-end response to product security incidents, from discovery to disclosure.
  • Own and evolve 1Password's PSIRT function, including severity frameworks and playbooks.
  • Drive coordinated vulnerability disclosure and partner with external security researchers.

1Password is a cybersecurity company providing enterprise password management and Unified Access Management, trusted by over 180,000 businesses. With $400M ARR and a remote-first culture, it values collaboration, transparency, and innovation.

United States

  • Lead complex Global Vulnerability Management workstreams to advance Threat Exposure Management capabilities and transition to a Continuous Threat Exposure Management model.
  • Conduct hands-on vulnerability research, technical analysis, and security validation to eliminate false positives, characterize exploitability, and provide actionable remediation guidance.
  • Partner across Information Security and engineering teams to evolve platforms, integrations, and automation for improved discovery, prioritization, and remediation outcomes.

Sony Interactive Entertainment (SIE) is the company behind the PlayStation brand, delivering innovative gaming hardware and network services to over 100 million people worldwide. As a subsidiary of Sony Group Corporation, SIE is a dynamic and entertainment-focused organization that values innovation, excellence, and employee empowerment.

Brazil

  • Identify and remediate high-impact security risks across applications, infrastructure, and production systems.
  • Integrate security practices into CI/CD pipelines and infrastructure-as-code workflows.
  • Collaborate with engineering teams to embed security into development and delivery workflows.

The company develops software and AI-powered solutions to support critical business workflows. It is a remote-first, fast-moving organization with a culture focused on ownership, transparency, and continuous improvement.

$121,000–$181,600/yr
United States Canada

  • Analyze, assess, reproduce, and triage incoming security vulnerability reports from the bug bounty program.
  • Communicate clearly with security researchers and drive the lifecycle of submissions through to resolution.
  • Understand root causes of vulnerabilities and advise on mitigation strategies to improve security posture.

Stripe is a financial infrastructure platform for businesses, enabling millions of companies to accept payments, grow revenue, and accelerate new business opportunities. As a large, mission-driven company, Stripe fosters a culture of passion, grit, and integrity with diverse perspectives.

$41–$51/hr
US

  • Own the vulnerability management program, prioritizing and driving a culture of ownership across business units.
  • Drive metrics and program review to transparently communicate performance and accountability.
  • Provide expert leadership to highly visible, multi-faceted projects while coordinating across teams and geographies.

We empower organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity of our customers and trusted alliance of elite hackers with our patented data and AI-powered Security Knowledge Platform. We are based in San Francisco and New Hampshire, supported by General Catalyst and others, and we foster a diverse and inclusive culture.

US Unlimited PTO

  • Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features, APIs, mobile applications, and backend services.
  • Develop and maintain scalable security tools and pipelines to automate vulnerability detection, dependency scanning, and security testing across the software development lifecycle.
  • Serve as a product security point of contact for incidents, contributing to investigation, root-cause analysis, and post-incident improvement.

Lime is a global leader in micromobility, on a mission to build a future where transportation is shared, affordable, and carbon-free. A Time Magazine 100 Most Influential Company, Lime has powered more than one billion rides across 30 countries and is a fast-paced, lean, remote-first company.

EMEA

  • You'll lead the VIPR & VMDR function, integrating vulnerability intelligence, detection, and response for customers across APJ/APAC.
  • You'll operate and tune vulnerability detection tools like Tenable, Qualys, and Rapid7, and automate pipelines using Python and REST APIs.
  • You'll build risk dashboards and executive briefings, and collaborate with Customer Success and Security Engineering to improve remediation metrics.

ServiceNow is the AI control tower for business reinvention, bringing together AI, data, and workflows to help 85% of the Fortune 500 work smarter. The company fosters an AI-native culture where technology and talent are unstoppable together.

$80,000–$130,000/yr
US

  • You will own end-to-end compliance audits (SOC 1, SOC 2, HITRUST) and manage compliance automation platforms.
  • You will run the vulnerability management program and remediate security findings across AWS.
  • You will support security incident response, fraud investigations, and third-party risk assessments.

We are transforming post-acute care as the leading digital ordering platform for medical equipment and supplies. We connect major health systems, health plans, and suppliers to help patients get life-saving products at home, with a network of 300,000+ clinicians and 3,000+ supplier locations across all 50 states.

Ireland

  • Investigate and resolve customer technical issues across cloud security posture management, vulnerability scanning, and threat detection in AWS, Azure, and GCP environments.
  • Troubleshoot cloud connector and integration failures, including IAM, network connectivity, and API authentication issues.
  • Design and implement automation leveraging AI agents to improve triage accuracy and resolution efficiency.

Wiz provides an AI-powered cloud security platform that connects code, cloud, and runtime to secure cloud and AI applications, trusted by over 65% of the Fortune 100. As one of the fastest-growing startups, powered by Google, Wiz has a culture that values world-class talent and encourages creative thinking.