Senior Security Engineer, Vulnerability Management
Jobgether · United States · $153K–$214K/yr
Internet Marketplace Platforms · 11-50 employees
About the role
You will lead end-to-end product security incident response and manage the PSIRT program, including playbooks and vulnerability disclosure. Additionally, you will collaborate cross-functionally to drive automation and AI-powered workflows to enhance detection and operational efficiency.
What they look for
Requirements
Candidates must have 5+ years of experience in IT, software engineering, or cybersecurity with a focus on product security or vulnerability management. You should possess hands-on experience with incident response, automation, and the ability to code for investigations and scripting.
Benefits
Full description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Engineer, Vulnerability Management based in the United States.
Join a high-impact Product Security team focused on protecting millions of users through industry-leading security practices. In this senior role, you will lead vulnerability management and product security incident response initiatives while helping strengthen security across products, platforms, and infrastructure. You'll collaborate with engineering, legal, communications, and customer-facing teams to coordinate responses to critical security events and continuously improve security operations. This is an excellent opportunity for an experienced security professional who thrives in fast-paced environments, enjoys solving complex technical challenges, and wants to shape modern vulnerability management strategies. You'll remain hands-on while mentoring others, driving automation, and leveraging AI-powered solutions to enhance detection, response, and operational efficiency.
\n
Accountabilities:
- Lead end-to-end response for product security incidents, including identification, triage, investigation, remediation, disclosure, and post-incident review.
- Own and continuously improve the Product Security Incident Response (PSIRT) program, including response playbooks, severity frameworks, escalation procedures, and operational standards.
- Manage coordinated vulnerability disclosure activities by working with external security researchers and bug bounty programs to ensure responsible vulnerability handling.
- Partner cross-functionally with Engineering, Legal, Communications, Customer Success, and other stakeholders to coordinate security incidents and customer communications.
- Develop automation, tooling, and AI-powered workflows that improve incident detection, investigation, response times, and operational efficiency.
- Contribute to customer-facing security advisories, CVE publications, and public incident communications while ensuring accuracy and transparency.
- Conduct post-incident reviews, identify root causes, and implement long-term improvements to products, detection capabilities, and operational processes.
- Mentor security engineers, contribute to the maturity of vulnerability management programs, and participate in an on-call rotation supporting critical security incidents.
Requirements
- 5+ years of experience in IT, software engineering, or cybersecurity with a strong focus on product security or vulnerability management.
- Proven experience leading or participating in security incident response within SaaS, cloud, or product-driven environments.
- Hands-on knowledge of coordinated vulnerability disclosure processes and working with external security researchers.
- Strong understanding of vulnerability assessment methodologies, incident severity frameworks, and security best practices.
- Experience developing incident response playbooks, automation, security tooling, or response frameworks from the ground up.
- Ability to read and write code to support investigations, automation, scripting, or forensic analysis.
- Experience using AI or machine learning technologies to improve security operations, automate workflows, or enhance detection capabilities.
- Excellent analytical, communication, and stakeholder management skills with the ability to make sound decisions under pressure.
- Ability to collaborate across technical and non-technical teams while mentoring colleagues and driving continuous improvement.
- Experience with CVSS, EPSS, SBOMs, supply chain security, compliance frameworks (SOC 2, ISO 27001), or relevant security certifications is considered an advantage.
Benefits
- Annual base salary ranging from $153,000 to $214,000 USD, based on experience and qualifications.
- Comprehensive medical, dental, and health insurance coverage.
- Equity grant and participation in incentive programs.
- 401(k) retirement savings program.
- Generous paid time off and parental leave benefits.
- Remote-first work environment with opportunities for in-person team gatherings and offsites.
- Paid volunteer days and employee recognition programs.
- Complimentary premium account access.
- Professional development opportunities within a collaborative, innovative security organization.
\nHow Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1