Jobiba hiring network

Senior Security Risk Management Framework Engineer Jobs

7,292 active opportunities · Updated for October 2026

Fresh results

15 shown

Explore current senior security risk management framework engineer jobs. Use filters to narrow by work mode, employment type, experience and date posted.

DC
15 days ago

Role Overview You are a senior product leader who wants to shape how AI transforms IT and cyber risk management at scale. In this role, you will own one of the most strategic product areas in a global GRC SaaS platform, defining how organisations identify, assess, and act on cyber risk — and how CISOs and boards get the clarity they need when it matters most. You will set and drive the product vision, roadmap, and outcomes for IT & Cyber Risk on a multi-solution platform used by enterprises worldwide. You will partner closely with engineering, design, data science, and senior leaders to build AI-native capabilities that automate risk detection, prioritisation, and reporting. Your work will have high executive visibility, real strategic weight, and direct impact on how customers manage governance, risk, and compliance. Here’s a breakdown of what you’ll do (not all of it, just the important stuff) Lead the end-to-end product strategy and roadmap for IT & Cyber Risk, aligning to company objectives and broader platform direction. Design and deliver AI-powered features (LLMs, agents, ML models) that automate risk identification, assessment, and reporting for enterprise security and risk teams. Partner with engineering, data science, and design to define technical approaches, ship high-quality releases across web, mobile, and API, and iterate using product analytics. Develop deep market and customer insight by engaging regularly with CISOs, security leaders, and risk managers, and turn those insights into clear product bets. Define, track, and communicate product KPIs, AI performance metrics, and north star outcomes to senior stakeholders, including business cases for major investments. Work cross-functionally with Sales, Customer Success, Professional Services, and Marketing to ensure successful launches and adoption of new IT & Cyber Risk capabilities. These are the essentials you’ll need to get an interview 7+ years of product management experience, includi

awsgitagile
View job →
R
Roblox
📍 San Mateo• Full-time• From $243.3K/yr
1mo ago

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Senior Enterprise Security Engineer, you will play a critical role in executing Roblox’s Enterprise Security Strategy. You will design, deploy, and manage security solutions to protect Roblox’s corporate infrastructure and ensure secure, compliant operations across the organization. Working closely with Corporate Engineering and Trust & Safety teams, you will translate business requirements into robust security implementations that enable secure productivity while mitigating risk. You will be reporting directly to the Senior Manager of Enterprise Security Engineering. You'll partner with security professionals across the Information Security organization, and work cross-functionally with teams throughout Roblox to drive security initiatives that scale with our business. You will: Evaluate and implement security technologies and vendor solutions to ensure alignment with enterprise security requirements, compliance standards, and overall risk management strategy Lead and drive initiatives across core security domains, including Endpoint Security, SaaS Security, Identity & Access Management (IAM), Agentic AI Governance, and Supply Chain Security. Collaborate closely with IT, engin

awsgitai
View job →
AG
1mo ago

The Business Unit Cyber Lead will be responsible for leading and managing the cybersecurity strategy, execution, and risk management efforts within a specific business unit. This role serves as the primary point of contact for all cybersecurity-related matters within the business unit, ensuring that security risks are effectively identified, mitigated, and managed. The Business Unit Cyber Lead will work closely with business leaders, IT teams, and the enterprise cybersecurity function to ensure that cybersecurity initiatives are aligned with business objectives and effectively executed to protect the organization’s digital assets. Source: Adani Group | Job ID: 55798

Our vision is to transform how the world uses information to enrich life for all . Micron Technology is a world leader in innovating memory and storage solutions that accelerate the transformation of information into intelligence, inspiring the world to learn, communicate and advance faster than ever. As the Logistics Security Program Manager for EMEA, this role is an essential part of Micron’s Global Security team. The person leads the management and continuous refinement of the company’s important logistics security efforts across the EMEA area. This position serves as the regional authority, advancing risk-focused security methods that protect high-value shipments, improve supply chain durability, and lower transportation security risks in intricate multimodal logistics networks. As a senior individual contributor, the Logistics Security Program Manager takes charge of regional program initiatives on their own. They apply solid judgment to shifting threat conditions and collaborate with colleagues across functions and external partners to produce security results. The position involves balancing security, operational efficiency, and business continuity while transforming regional risks into scalable, practical controls that advance cargo visibility, shipment protection, and incident readiness. Responsibilities: Act as the EMEA logistics security authority, guiding the creation and implementation of risk-focused security programs for valuable and sensitive shipments involving carriers, freight forwarders, and logistics providers. Develop, apply, and manage shipment security controls, including tracking, telematics, geofencing, chain of custody, tamper detection, monitoring, critical issue handling, recovery processes, and carrier compliance requirements. Conduct carrier, route, l

aisupply chainlogistics
View job →
G
Gitlab
📍 United States• Full-time• Remote• From $203.2K/yr
1mo ago

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As the Senior Director, Internal Audit you'll report to the Vice President, Internal Audit, and help strengthen GitLab's Internal Audit function. You'll turn an established audit methodology into consistent, practical ways of working, guide audit quality and execution, and help prepare and implement a risk-based audit plan that addresses GitLab's strategic, business, and compliance objectives. You'll also support the Internal Audit strategy and roadmap, lead the facilitation of our enterprise risk management program, and build trusted relationships with business partners across GitLab. What you’ll d

REMOTEgitrestai
View job →

Senior Security Engineer, Vulnerability Management Here at Datadog, we think about vulnerability management a little differently. We embrace open source software, recognize our role in the software supply chain, and see attackers weaponizing vulnerabilities faster than ever. We are looking for a Senior Security Engineer who can combine vulnerability-management judgment with hands-on engineering to help us scale and improve our vulnerability lifecycle across Datadog’s multi-cloud products and services. In this role, you will turn ambiguous security problems into clear solutions, and work with engineering teams to address root causes and develop technical controls that reduce vulnerabilities earlier in the SDLC. You’ll use AI and automation to help scale the overall vulnerability lifecycle across Datadog. You will use data and sound technical judgment to prioritize risk, and partner with security, product, platform, and compliance teams to bring scalable solutions into practice. At Datadog, we place value in our office culture - the relationships and collaboration it builds, and the creativity it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can create a work-life harmony that best fits them. What You’ll Do Work across the vulnerability lifecycle from detection and impact assessment through risk-based prioritization, remediation, and verification. Use AI and automation to build tools, services, and workflows that make security ideas concrete, validate them quickly, and create alignment for scalable implementation. Reduce engineering toil through a “PRs, not tickets” approach, using automation to enrich findings, identify ownership, recommend or deliver fixes, and track outcomes. Analyze recurring vulnerabilities and remediation failures to identify root causes and opportunities to prevent issues earlier in the SDLC. Partner with SDLC Security, Product Security, platform teams, and engineering teams to balance technical constraints, busin

pythonjavaai
View job →

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. We believe that security should be monitored and verified continuously, including the security of your supply chain. The Vendor Risk Management (VRM) product was designed to provide software buyers with tools to evaluate the security of their vendors by inventorying vendors, prioritizing risks, automating security reviews and remediating findings. VRM or Third party Risk Management (TPRM) presents a massive opportunity for Vanta - representing a market of $5-$10B in ARR and a CAGR of 10.8% driven by secular tailwinds in the industry that requires more focussed and deeper scrutiny of the company’s supply chain. As a Senior Software Engineer with full stack focus, you’ll be responsible for driving complex projects across our technical stack and mentor our talented engineering team. Your past experience will be leveraged to accelerate the evolution of our Vendor Risk Management product and help software buyers continuously and comprehensively monitor risks across their vendor supply chain. Our business has found incredible product-market fit and has monetized effectively since the day we signed our first customer. We’re growing at a blistering pace, which presents career-defining opportunities for engineers to accelerate their growth and to contribute to a rapidly-scaling company. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. We’d love for you to join us! Visit our Vanta Engineering Blog to learn more about what our team is working on! What you’ll do as a Senior Software Engineer at Vanta: Lead complex, ambiguous projects end-to-end, partnering wit

typescriptrestgraphql
View job →

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. The Vendor Monitoring Data team focuses on gathering external data and conducting risk analysis as part of Vanta's Vendor Risk Management (VRM) product. Our work provides comprehensive insights that help customers mitigate third-party risks effectively. As a Senior Fullstack Engineer, you'll drive complex projects across our technical stack while mentoring our talented engineering team. This role offers a unique opportunity to delve into a hyper-focused subject area: external attack surface scanning. You'll tackle unique technical challenges and contribute directly to Vanta's impact by helping customers continuously and comprehensively monitor risks across their vendor supply chain. Our business has found incredible product-market fit and has monetized effectively since the day we signed our first customer. We're growing at a blistering pace, which presents career-defining opportunities for engineers to accelerate their growth and contribute to a rapidly-scaling company. Visit our Vanta Engineering Blog to learn more about what our team is working on! What you’ll do as a Senior Fullstack Engineer, Vendor risk management at Vanta: Identify, scope, and lead large technical projects, laying the groundwork for core products to evolve and scale into highly performant, reliable, and customizable systems Make effective tradeoffs that consider business priorities, user experience, and a sustainable technical foundation Engineer sophisticated monitoring and alerting systems to guarantee the reliability, speed, and integrity of our security data pipeline. Collaborate with security researchers to rapidly deploy new scanning techniques and

typescriptrestai
View job →

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. Senior Software Engineer, Trust (TPRM) - Job Description As a Senior Software Engineer on Vanta's Trust TPRM team, you'll build the full-stack product experiences and underlying data infrastructure that help enterprises manage vendor risk at scale — working across teams focused on vendor lifecycle management and vendor monitoring. Vanta's Trust TPRM (Third-Party Risk Management) team is building the products that make vendor risk management seamless for security and procurement teams. From vendor onboarding and lifecycle management to continuous monitoring and procurement integrations, we're creating the platform that helps Vanta customers understand, track, and mitigate third-party risk — a fast-growing, business-critical capability for modern enterprises. As a Senior Software Engineer, you'll contribute as a core member of either the Vendor Lifecycle or Vendor Monitoring Experience team. You'll design and ship full-stack features that directly shape how customers manage vendor relationships, collaborate with product and design partners, and bring real engineering ownership to a product area that's growing quickly within Vanta. What you’ll do as a Senior Software Engineer at Vanta: Design, build, and maintain full-stack features across the TPRM product surface, including vendor onboarding, lifecycle management, and monitoring workflows Contribute to the vendor data model and core platform abstractions that power TPRM products Write clean, well-tested code and actively participate in code reviews; uphold engineering quality standards Engage in architecture discussions and contribute to technical decision-making within your team

typescriptreactnode.js
View job →
E
15 days ago

Everpure (NYSE: P) has evolved from storage pioneer to data platform, closing fiscal 2026 with $3.7 billion in revenue, its first billion-dollar quarter, and accelerating growth into FY27. Our strategic agenda spans the companies defining the next era of technology - hyperscalers, AI labs, the AI hardware supply chain, data platform providers, and the broader AI ecosystem. This type of work—work that changes the world—is what the tech industry was founded on. So, if you're ready to seize the endless opportunities and leave your mark, come join us. THE ROLE As a Senior Security Operations Engineer – Attack Surface Management , you will help engineer, operate, and continuously improve our enterprise Attack Surface and Vulnerability Management capabilities. You will focus on discovering and understanding our attack surface, identifying vulnerabilities and exposures, prioritizing them based on real-world risk, and driving remediation across our global environment. The role spans Attack Surface Management, Vulnerability Management, Zero Trust, Secrets and Credential Security, SSPM, Deception, Detection Engineering and Security Automation. We are looking for engineers with strong ASM/Vulnerability Management fundamentals and deeper expertise in one or more adjacent security domains. WHAT YOU’LL DO Engineer and improve enterprise Attack Surface and Vulnerability Management across cloud, infrastructure, endpoints, applications, and internet-facing environments. Discover and correlate assets across security platforms and identify unknown, unmanaged, stale, and externally exposed assets. Drive risk-based vulnerability prioritization using asset criticality, exposure, exploitability, known exploitation, threat intelligence, and compensating controls. Establish remediation workflows and SLAs and partner with asset owners to drive measurable risk reduction. Operate and troubleshoot Zscaler ZIA/ZPA, including SSL inspection, access policies, connectivity, and Zero Trust controls.

pythonawsazure
View job →
E
15 days ago

Everpure (NYSE: P) has evolved from storage pioneer to data platform, closing fiscal 2026 with $3.7 billion in revenue, its first billion-dollar quarter, and accelerating growth into FY27. Our strategic agenda spans the companies defining the next era of technology - hyperscalers, AI labs, the AI hardware supply chain, data platform providers, and the broader AI ecosystem. This type of work—work that changes the world—is what the tech industry was founded on. So, if you're ready to seize the endless opportunities and leave your mark, come join us. THE ROLE As a hands-on senior leader for our India SecOps team, you will shape and safeguard Everpure’s security posture at the intersection of detection engineering, threat hunting, attack surface management, and incident response. Positioned as a strategic cornerstone in Bangalore, you will empower an elite engineering team, optimize critical SecOps pipelines, and partner cross-functionally across global engineering and infrastructure groups. By driving execution excellence and high team morale, you ensure our enterprise platform and global telemetry remain resilient against evolving threats. WHAT YOU'LL DO Scale & Lead SecOps Operations: Architect, mentor, and grow the India SecOps team to foster an environment of high morale, technical excellence, and rapid execution across detection engineering and incident response. Proactively Manage & Remediate Attack Surface: Own end-to-end Attack Surface Management (ASM) across cloud environments, SaaS applications, endpoints, and secrets management to measurably minimize enterprise exposure and mitigate risk. Optimize Telemetry & Incident Response: Mature SIEM and SOAR automation pipelines to drastically reduce mean time to detect, contain, and respond (MTTD/MTTC/MTTR) while continuously elevating alert fidelity and signal confidence. Drive Cross-Functional Alignment & RCA Postmortems: Lead continuous validation through purple-teaming and incident postmortems alo

awsazureci/cd
View job →

WPP is the trusted growth partner for the world’s leading brands. We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. For more information, visit WPP.com. Why we're hiring: The Senior Security Incident Responder is a lead technical authority for incident response execution, responsible for handling the most complex, high-impact, and business-critical security incidents across WPP. The role does not have line management responsibility; people management remains with the Security Incident Management Lead. What you'll be doing: KEY RESPONSIBILITIES Advanced Incident Detection, Analysis & Response - Lead investigations for high-severity and complex security incidents. - Perform deep technical analysis using SIEM, SOAR, EDR/XDR, identity, email, and cloud telemetry. - Execute and oversee containment, eradication, and recovery actions. - Act as technical incident commander when delegated. Escalation Handling & Stakeholder Coordination - Serve as the primary escalation point for complex incidents. - Coordinate with Legal, Privacy, Risk, Technology Operations, and agency teams. - Provide clear technical updates to senior stakeholders. Forensics, Evidence Handling & Assurance - Lead forensic evidence collection, preservation, and analysis. - Ensure d

recruitment
View job →
V
Vanta
📍 United States• Full-time
1mo ago

At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As a Senior Security Engineer at Vanta, you’ll own projects with impact across the business to help us run an efficient and highly effective security team. The security team at Vanta ensures that we are a trustworthy steward of sensitive data. We also contribute subject matter expertise to the product, sales, marketing, support, and engineering functions, given the nature of our business. You’ll join Vanta’s Security organization, which provides essential security operational services, is directly involved in the software development process and building tools to make it easy for developers to ship products securely, sets policies and standards regarding enterprise-wide security requirements, and offers advisory services to enable our business to thrive while effectively managing risk. If you’re someone who has high initiative and enjoys problem solving while having impact at a high-growth company, we would love to hear from you! What you’ll do as a Senior Security Engineer at Vanta: Participate in team exercises to identify potential security risks, including threat modeling and tabletop scenarios Contribute to complex prioritization discussions around which risks are the most important to solve next Plan projects to address the risks we prioritize, and coordinate with cross-functional stakeholders across the company to execute those projects Build maintainable programs to implement operational excellence where ongoing work is needed to achieve our goals (e.g. vulnerability management) Partner with engineering teams to architect secure software, address security concerns, and build a strong security culture Build, customize, a

restaigo
View job →
A
9 days ago

Job Requisition ID # 26WD100179 Position Overview The Trust Risk Manager leads the Trust Risk Program at Autodesk and manages a multidisciplinary organization that includes Third-Party Risk Management as well as senior risk professionals. T rust Risk at Autodesk is an established team and program . W e are looking for a leader with the lived experience of operationalizing a risk program that is Trusted by leaders and executives to drive risk-based decisions in the areas of Trust – Security, Privacy, Trusted AI, and Resilience. This individual will report directly to the Director of Trust Governance, Risk, and Compliance. The successful candidate will bring deep expertise in at least one Trust risk domain and sufficient breadth across security, privacy, trusted AI, resilience, and third-party risk to integrate specialist perspectives into an enterprise risk view. Operationalizing risk management and working with executive stakeholders is as much of an art as it is science . Th e Trust Risk Manager needs to have lived, practical experience to g

REMOTEawsai
View job →
DU
DoorDash USA
📍 San Francisco• Full-time
15 days ago

About the Team DoorDash’s Internal Audit team provides independent assurance that the company’s risk management, governance, and internal control processes are operating effectively. We are a small team that is looking to expand and bring on motivated professionals. We don’t think of ourselves as a typical audit function - we are obsessively focused on risks to the organizations which reflects in the type of projects we support and execute. DoorDash is rapidly growing - we are expanding in multiple geos and launching new products. This exciting growth allows us to drive creative analysis, strategy, and solutions. Our focus areas include financial, operational, regulatory, security, IT, and more. About the Role We are seeking a Senior Director, IT Internal Audit to lead the strategy, execution and evolution of DoorDash’s global IT audit function. In this highly visible role, you will help shape the technology risk management practices across DoorDash - you will oversee a broad portfolio of audits, including IT SOX, cybersecurity, data governance, AI governance, and operational technology. You will report directly to the Chief Audit Executive and serve as a strategic advisor to DoorDash’s technology, security, and engineering leaders. You will bring deep technical audit expertise, exceptional leadership skills, and a passion for innovation to build and lead a world-class IT audit organization that scales with the business. This role demands someone who can balance strategy with execution (and isn’t afraid to roll up their sleeves) — a leader who can anticipate emerging technology risks, foster strong cross-functional partnerships, translate complex technical concepts into meaningful business insights, and be ready to operate at the lowest level of detail. You will partner with teams across Security, Platform Engineering, Data Engineering, Privacy Legal, AI, Product, and Compliance to strengthen our risk posture and drive a data-driven approach

awsgitrest
View job →
🔔

Get new senior security risk management framework engineer jobs by email

Daily job updates · Unsubscribe anytime