Security Vulnerability Engineer
Jobgether United States
Internet Marketplace Platforms · 11-50 employees
About the role
The Security Vulnerability Engineer will lead the design and operation of advanced vulnerability management and threat-detection capabilities across mission-critical environments. Responsibilities include building predictive risk models, managing security telemetry data pipelines, and collaborating cross-functionally to optimize detection performance.
What they look for
Requirements
Candidates must have at least 5 years of professional experience in security engineering or vulnerability management and possess U.S. citizenship. Proficiency in Python, cloud platforms, and machine learning frameworks is required, along with the ability to undergo a U.S. Government background investigation.
Benefits
Full description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Vulnerability Engineer based in United States.
The Security Vulnerability Engineer will lead the design, development, and operation of advanced vulnerability management and threat-detection capabilities across secure, mission-critical environments. This senior technical role combines hands-on expertise in security analytics, detection engineering, predictive risk modeling, and cloud security. You will help identify and prioritize vulnerabilities while developing detection and enrichment systems capable of processing large volumes of security telemetry and threat intelligence. A key focus will be building predictive models from five or more years of historical incident and vulnerability data to generate operationally meaningful risk forecasts. The role also requires strong technical leadership, cross-functional collaboration, and the ability to translate complex security insights into actionable decisions. You will work across detection operations, systems integration, model validation, governance, and continuous performance improvement. This opportunity is well suited to an experienced security engineer who can balance technical depth with strategic judgment and responsible security practices.
\n
Accountabilities:
- Identify, assess, and prioritize vulnerabilities across enterprise systems while developing and tuning detection logic and analytics to meet defined performance, accuracy, and coverage standards.
- Design, develop, and implement threat-detection and enrichment capabilities capable of analyzing large volumes of unstructured security telemetry, logs, and threat-intelligence data.
- Lead security engineering initiatives focused on vulnerability analytics, detection engineering, emerging defensive technologies, and advanced security capabilities.
- Configure data pipelines and security telemetry ingestion processes and implement predictive components using five or more years of historical incident and vulnerability data to generate time- and location-based risk forecasts.
- Integrate vulnerability-management and detection solutions with existing SIEM, ticketing, and operational systems to support reliable data flow and seamless security workflows.
- Collaborate with cross-functional teams and contribute to initiatives involving the STRIDE platform and other operational security environments.
- Validate data integrity, detection performance, model reliability, and system behavior across security tooling, ensuring outputs are accurate and operationally meaningful.
- Evaluate detection and forecasting accuracy by comparing predicted outcomes with observed threat patterns and identifying opportunities for improvement.
- Monitor and continuously optimize detection and vulnerability-analytics performance, with an emphasis on scalability, efficiency, and reducing false positives in cloud environments.
- Leverage security and analytics technologies including SIEM platforms, vulnerability scanners, AWS security services, TensorFlow, PyTorch, and custom detection frameworks.
- Establish and apply responsible governance practices by assessing model and detection risks, potential biases, coverage gaps, and compliance considerations.
- Implement Detection Operations and MLOps practices that automate the deployment, monitoring, maintenance, and lifecycle management of detections, analytics, and predictive models.
Requirements:
- At least 5 years of professional experience in security engineering, vulnerability management, or detection engineering, with experience spanning solution design, evaluation, and production deployment.
- U.S. citizenship is required, along with willingness to undergo a U.S. Government background investigation.
- Hands-on experience with security analytics, threat-detection frameworks, scripting and automation, particularly Python, and major cloud platforms.
- Strong capabilities in advanced security queries, detection engineering, model and detection tuning, analytics, and automation.
- Experience working with large-scale data stores, search or vector databases, and retrieval-based analytical architectures for security applications.
- Familiarity with technologies such as Pinecone, Weaviate, Qdrant, or Chroma is valuable.
- Experience with machine learning and analytics frameworks such as PyTorch, TensorFlow, Keras, Hugging Face, and LangChain is strongly preferred.
- Experience using API-driven tooling and modern analytics architectures to support security use cases is a plus.
- Demonstrated expertise in detection and model evaluation, monitoring, validation, benchmarking, and deployment.
- Strong troubleshooting, analytical, and problem-solving abilities, with the judgment to evaluate technical risks and translate findings into practical security improvements.
- Ability to lead technical initiatives, collaborate across teams, and communicate complex security and analytics concepts effectively.
- Comfortable working in secure, mission-critical environments where accuracy, reliability, responsible technology use, and operational impact are critical.
Benefits:
- Competitive salary paid twice per month.
- Best-in-class medical coverage.
- 100% of medical premiums covered by the employer.
- Company-wide new business incentive programs.
- Contribution incentives for activities such as white papers, blog posts, and internal webinars.
- 3 weeks of PTO to start.
- 11 paid holidays annually.
- 401(k) program with 100% company matching on the first 4%.
- Monthly reimbursement for cell phone and home internet costs.
- Paid maternity and paternity leave.
- Investment in professional training and certifications to expand and deepen technical expertise.
\nHow Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1