←Jobiba.Me
C
Active1mo ago

Vulnerability Management Engineer

Cloudflare·📍 Hybrid

Employment

FULL TIME

Work mode

Hybrid

Experience

MID LEVEL

Salary

Not disclosed

Salary not disclosed

Check market pay for comparable Vulnerability Management Engineer roles before applying.

Salary →

Role overview

Job description

About Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company. At Cloudflare, we’re not looking for people who wait for a polished roadmap; we

…

What they are looking for

Skills & requirements

Qualification

Bachelor's degree in Computer Science, Information Security, or security certifications in a related field; export laws without sponsorship for an export license; Cloudflare provides reasonable accommodations to qualified individuals with disabilities

Department · Security

C

Hiring company

Cloudflare

Explore this employer's active roles, salary signals and company profile on Jobiba.

Keep exploring

Similar active roles

Fresh roles matched to this title and market.

View all →
S
📍 San Francisco, CA, United States· Full-time
Exact match
Quick readExact title match for your search

Employee Applicant Privacy Notice Who we are: Shape a brighter financial future with us. Together with our members, we’re changing the way people think about and interact with personal finance. We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world. About The role As a Vulnerability Management Engineer, you will support the identification, assessment, prioritization, and remediation of vulnerabilities across applications and infrastructure. Working under the guidance of senior team members, you will assist in understanding how vulnerable dependencies enter an application, identifying remediation options, and engaging with engineering teams to track fixes. You will contribute to the maintenance of internal vulnerability-management tools, such as scripts, documentation, and reporting. The ideal candidate will have a desire to grow their AppSec expertise, will be eager to learn about modern security tooling and automation, and will be comfortable using AI tools like Claude to assist with documentation, investigation, and scripting tasks while following company security and data-handling requirements. What you’ll do Perform regular vulnerability assessments using different tools. Regularly drive remediation and reporting of cataloged vulnerabilities. Assess discovered vulnerabilities and properly prioritize their scope, impact and necessary response actions. Conduct security reviews of our products and production infrastructure. Contribute to vulnerability management, application security and/or offensive/red-team operations. Engage in security audit

PythonJavaAWSCI/CD
R
📍 Foster City, California, United States· Full-time

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are seeking a mid-level Infrastructure Vulnerability Management Engineer with a strong background in Cloud Security, DevSecOps, and Infrastructure-as-Code (IaC). In this role, you will bridge the gap between security, compliance, DevOps, and Platform engineering teams. You will identify infrastructure misconfigurations, secure multi-cloud environments, and manage continuous vulnerability lifecycles across cloud workloads, containers, and data repositories to satisfy strict regulatory compliance frameworks. You will also serve as a technical infrastructure responder during security incidents, deploying real-time cloud or network countermeasures to protect our production ecosystem. What You'll Do Core Responsibilities Infrastructure Scanning & Triage: Perform continuous security scanning across our cloud posture and workloads. Review, validate, and prioritize flaws and misconfigurations based on CVSS scores, real-world exploitability, and infrastructure network exposure. Posture Management & Visibility : Own and optimize Cloud Security Posture Management (CSPM), Kubernetes Security Posture Management (KSPM), and Data Security Posture Management (DSPM) tools to ensure uniform compliance, prevent data leakage, and maintain hardened baselines. Infrastructure-as-Code (IaC) Security: Configure, tune, and embed automated IaC security scanning tools into CI/CD pipelines to identify architectural risks (e.g., overly permissive IAM, public S3 buckets/Cloud Storage) before they are deployed to production. Workload & Container Security: Manage the continuous vulnerability scanning lifecycle for container images, registries, and Virtual Machines (VMs), partnering with SRE and Platform teams to build aut

AWSAzureGCPDocker
R
📍 Foster City, California, United States· Full-time

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are seeking a mid-level AppSec Vulnerability Management Engineer with a strong software development background. In this role, you will bridge the gap between security, compliance, and engineering teams. You will identify application vulnerabilities, maintain software supply chain security, and drive tracking to satisfy strict regulatory compliance frameworks. You will also serve as a technical responder during security incidents, deploying real-time countermeasures to protect our software ecosystem. What You'll Do Core Responsibilities Vulnerability Scanning & Triage: Perform periodic application security scanning activities. Review results and prioritize flaws based on CVSS scores, real-world exploitability, and system exposure. Compliance-Driven Tracking: Track, document, and manage vulnerabilities according to strict compliance SLAs (e.g., SOC 2, ISO 27001, PCI-DSS). Maintain audit-ready evidence of remediation timelines and exception approvals. Executive Reporting & Alerting: Escalate and report critical exposures directly to the CISO and senior leadership. Maintain dashboards and alerting mechanisms that visualize vulnerability status, risk trends, and compliance posture. Software Supply Chain Security: Ownership of the organization's Software Bill of Materials (SBOM). Continually update SBOM inventories to ensure compliance with modern regulatory requirements and dependency tracking. Help Replit mature through various SLSA levels for supply chain security. Remediation Collaboration: Partner with development teams to provide clear mitigation paths. Review, write, and patch code directly when necessary to resolve security flaws. Tooling Integration: Configure and tune automated security te

JavaScriptTypeScriptPythonJava
V
📍 United States· Full-time

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As a Senior Security Engineer at Vanta, you’ll own projects with impact across the business to help us run an efficient and highly effective security team. The security team at Vanta ensures that we are a trustworthy steward of sensitive data. We also contribute subject matter expertise to the product, sales, marketing, support, and engineering functions, given the nature of our business. You’ll join Vanta’s Security organization, which provides essential security operational services, is directly involved in the software development process and building tools to make it easy for developers to ship products securely, sets policies and standards regarding enterprise-wide security requirements, and offers advisory services to enable our business to thrive while effectively managing risk. If you’re someone who has high initiative and enjoys problem solving while having impact at a high-growth company, we would love to hear from you! What you’ll do as a Senior Security Engineer at Vanta: Participate in team exercises to identify potential security risks, including threat modeling and tabletop scenarios Contribute to complex prioritization discussions around which risks are the most important to solve next Plan projects to address the risks we prioritize, and coordinate with cross-functional stakeholders across the company to execute those projects Build maintainable programs to implement operational excellence where ongoing work is needed to achieve our goals (e.g. vulnerability management) Partner with engineering teams to architect secure software, address security concerns, and build a strong security culture Build, customize, a

RestAIGoRust
CA
📍 Bengaluru, India· Full-time

A BOUT TIDE At Tide, we help SMEs save time and money in the running of their businesses by not only offering business accounts and related banking services, but also a comprehensive set of highly usable and connected administrative solutions, from invoicing to accounting. Tide is transforming the small business banking market and now supports over 2 million members globally across the UK, India, Germany and France. Using advanced technology, all solutions are designed with SMEs in mind. With quick onboarding, low fees and innovative features, we thrive on making data driven decisions to serve our mission: to help SMEs save time and money so they can get back to doing what they love. Tide facts: Tide is available for UK, Indian, German and French SMEs Over 2 million members across UK and India Over $300 million raised in funding Over 2,800 Tideans globally Recognised with Great Place to Work certification three years in a row, and among India’s Top 50 Best Workplaces in Banking, Financial Services, and Insurance in 2026 We have offices in Central London, with a member support and technology centre in Sofia, Bulgaria, technology centres in Serbia, Romania, Lithuania and Hyderabad and offices in Gurugram, New Delhi, Berlin, Paris and Luxembourg ABOUT THE TEAM: The Product Security team at Tide is responsible for embedding security across the full product surface, from secure design and threat modelling through to application-layer controls and vulnerability management. Within Product Security, the Remediation Operations function owns the day-to-day engine of Tide's vulnerability management programme: turning a high volume of findings from across our tooling estate into clear, prioritised, actionable work for engineering and IT teams. This role sits at the heart of that function. You will be the connective tissue between security tooling and the teams who fix things, making sure the right vulnerabilities reach the right people with the right context, and that the

AIGoRustSEM
CA
📍 Delhi NCR, India· Full-time

A BOUT TIDE At Tide, we help SMEs save time and money in the running of their businesses by not only offering business accounts and related banking services, but also a comprehensive set of highly usable and connected administrative solutions, from invoicing to accounting. Tide is transforming the small business banking market and now supports over 2 million members globally across the UK, India, Germany and France. Using advanced technology, all solutions are designed with SMEs in mind. With quick onboarding, low fees and innovative features, we thrive on making data driven decisions to serve our mission: to help SMEs save time and money so they can get back to doing what they love. Tide facts: Tide is available for UK, Indian, German and French SMEs Over 2 million members across UK and India Over $300 million raised in funding Over 2,800 Tideans globally Recognised with Great Place to Work certification three years in a row, and among India’s Top 50 Best Workplaces in Banking, Financial Services, and Insurance in 2026 We have offices in Central London, with a member support and technology centre in Sofia, Bulgaria, technology centres in Serbia, Romania, Lithuania and Hyderabad and offices in Gurugram, New Delhi, Berlin, Paris and Luxembourg ABOUT THE TEAM: The Product Security team at Tide is responsible for embedding security across the full product surface, from secure design and threat modelling through to application-layer controls and vulnerability management. Within Product Security, the Remediation Operations function owns the day-to-day engine of Tide's vulnerability management programme: turning a high volume of findings from across our tooling estate into clear, prioritised, actionable work for engineering and IT teams. This role sits at the heart of that function. You will be the connective tissue between security tooling and the teams who fix things, making sure the right vulnerabilities reach the right people with the right context, and that the

AIGoRustSEM

🔔 Get job alerts

New Vulnerability Management Engineer jobs in Hybrid, straight to your inbox.

No spam · Unsubscribe anytime