Senior Security Engineer, Customer Transparency
Jobgether United States · $191K–$293K/yr
Internet Marketplace Platforms · 11-50 employees
About the role
The Senior Security Engineer will manage vulnerability disclosure programs, including bug bounties and security advisories, while building automation to improve security workflows. They will also act as a technical liaison to customers, translating security needs into scalable engineering solutions and improving overall transparency.
What they look for
Requirements
Candidates must have at least 5 years of experience in product or application security and a bachelor's degree in a technical field. Strong proficiency in vulnerability management, automation, and direct engagement with external stakeholders is required.
Benefits
Full description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Engineer, Customer Transparency based in the United States.
The Senior Security Engineer will join a security organization focused on protecting the software and cloud services that customers rely on. This role sits at the intersection of product security, customer engagement, vulnerability management, and security transparency. You will help customers understand and act on the security posture of their deployments while identifying and closing gaps in the information available to them. The position combines hands-on security engineering with external stakeholder engagement, including customers and security researchers. You will also oversee vulnerability disclosure activities, security advisories, SBOM and vulnerability management, and related security processes. AI-assisted tooling and automation will be used to improve security workflows while maintaining strong judgment around accuracy and signal quality. This is an opportunity to influence both security engineering practices and the way security information is communicated to external stakeholders.
\n
Accountabilities:
- Build and maintain security tooling and automation, leveraging AI where appropriate to streamline security processes and improve operational efficiency.
- Identify security information and visibility gaps affecting customers and partner with Engineering and Product teams to address them.
- Oversee SBOM and vulnerability management programs, ensuring appropriate security information is available to both internal and external stakeholders.
- Collaborate with customers, partners, and customer-facing teams to understand recurring security needs and translate repeated questions into scalable engineering solutions.
- Serve as a technical security resource for customer-facing teams by responding to security inquiries and escalations, maintaining reusable response materials, and engaging directly with customers when appropriate.
- Administer the bug bounty program, including triaging vulnerability reports against SLAs, assessing exploitability and severity, evaluating duplicates and out-of-scope submissions, recommending awards, and maintaining constructive relationships with security researchers.
- Author and publish security advisories and CVE records, including appropriate CWE classifications and CVSS scoring.
- Coordinate vulnerability disclosure timelines, embargoes, and communications across researchers, customers, partners, and external coordinating organizations.
- Partner with Product and Engineering stakeholders to improve customer transparency and strengthen the security capabilities of products and services.
- Use security data, automation, and AI-assisted workflows thoughtfully, distinguishing useful signals from inaccurate or low-value outputs.
- Help establish scalable processes and technical systems that improve security communication, vulnerability response, and customer trust.
Requirements:
- Bachelor’s degree in Computer Science, a related technical discipline, or equivalent practical experience.
- 5+ years of industry experience required, with 7+ years preferred.
- Professional experience in product security, application security, vulnerability research, software engineering with a significant security focus, or a closely related area.
- Experience interacting directly with customers and external security researchers.
- Demonstrated experience applying AI tools to security work, with strong judgment around appropriate use cases, validation, and potential noise or inaccuracies.
- Experience building tools, systems, or data interfaces used by external stakeholders, including customers or support teams.
- Strong experience with modern software development and automation practices, including Git and CI/CD pipelines.
- Ability to assess vulnerability severity, exploitability, business impact, and appropriate remediation or disclosure approaches.
- Familiarity with software composition analysis, SBOM tooling, and third-party dependency vulnerability management is preferred.
- Experience with coordinated vulnerability disclosure, CVE assignment, CVSS, and CWE is advantageous, as is experience with CNA operations.
- Experience running or substantially supporting a bug bounty program or vulnerability disclosure program is a plus.
- Published vulnerability research, credited CVEs, bug bounty findings, open-source security tooling, or conference presentations is advantageous.
- Strong understanding of applied cryptography, including encryption, hashing, and secure key management, is preferred.
- Experience working with enterprise security products and services is beneficial.
- Excellent written and verbal communication skills, with the ability to explain technical security concepts clearly to both technical and non-technical audiences.
- Strong initiative, motivation, ethics, and integrity.
- Collaborative approach with the ability to work effectively across Engineering, Product, Customer Success, and other functions.
- Comfortable operating in a fast-paced, evolving environment and managing multiple priorities.
- Willingness and ability to work remotely within the United States.
Benefits:
- Annual base salary range of $191,000–$293,000 USD.
- Equity awards in addition to base compensation.
- Medical, dental, and vision insurance.
- Family planning benefits.
- Health Savings Account (HSA).
- Flexible Spending Account (FSA).
- Transportation savings account.
- 401(k) retirement savings plan with company match.
- Life, accident, and disability coverage.
- Business travel accident insurance.
- Employee assistance programs.
- Additional employee well-being benefits.
- Five days of volunteer time off annually.
- Fully remote work model within the United States.
- Opportunity to work on security challenges involving enterprise-scale software and cloud environments.
- Collaborative culture focused on respect, diversity, continuous learning, and professional growth.
- Opportunity to work directly with customers and external security researchers while shaping security transparency and vulnerability management practices.
\nHow Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
Similar roles
-
Application Security & IAM Engineer
Onwelo Kielce, Holy Cross Voivodeship, Poland
-
Senior Infrastructure & Network Security Engineer
Coopers Group AG Switzerland
-
Cybersecurity Business Development Manager (100 % remote) (m/f/d)
EWOR GmbH Karlsruhe, Baden-Württemberg, Germany
-
Application Security Engineer
Sitoo Stockholm, Stockholm County, Sweden
-
Junior Cybersecurity Architect - Categoria protetta L.68/99
BIP Consulting Rome, Lazio, Italy · €28K–€34K/yr
-
[EJV] Lead AI Safety & Security Engineer
Bosch Group Ho Chi Minh City, Ho Chi Minh, Vietnam