Who are we? Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems. We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that. We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft. We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us! As a Manager of Security Engineering, your key responsibilities include: Serve as trusted advisor to team’s leadership and partner teams by clearly articulating business risks associated with security issues Execute the long-term vision for the Security team in alignment with Cohere’s product and business goals. Collaborate closely with leadership to prioritize high-impact initiatives and strategic customer engagements. Vulnerability Management: Develop and implement enterprise-wide vulnerability management processes and tooling, including identification, prioritization, remediation tracking, and reporting, including customer artifacts Static Application Security Testing (SAST): Establish SAST programs, integrate tools into CI/CD pipelines, and analyze results to identify and remediate security flaws in source code Dynamic Application Security Testing (DAST): Implement DAST methodologies, configure scanning tools, and conduct regular assessments of running applications Penetration Testing: Lead and oversee internal and external penetration testing engagements, including web application, API, network and agentic AI platform inclu
Jobiba hiring network
Vulnerability Management Engineer Jobs
121 active opportunities · Updated for October 2026
Fresh results
14 shown
Explore current vulnerability management engineer jobs. Use filters to narrow by work mode, employment type, experience and date posted.
The Security team is responsible for protecting Asana’s employees, users, and customers . We are a team of security engineers and risk and compliance practitioners who build innovative safeguards to ensure that our data is protected against threats and that we comply with legal, regulatory, and customer requirements . We collaborate closely with teams across the organization to foster a culture of security throughout our product and operations . We're looking for a Manager of Offensive Security to lead our Offensive Security function in Warsaw . In this role, you will own and grow a team spanning red team operations, application security, and vulnerability management, driving both the strategic direction and the hands-on execution of our offensive security program . You will work directly with engineering leadership, legal, and senior stakeholders to ensure our security posture is contin uously tested, measured, and improved . This role is based in our Warsaw office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do, and your recruiter can share more about the in-office requirements. We offer a Contract of Employment (UoP) for our employees in Poland. What you’ll achieve Lead, grow, and mentor a team of offensive security engineers across red team, application security, and vulnerability management disciplines while staying actively engaged in day-to-day technical operations . Define team roadmap, OKRs, and priorities in alignment with broader security and engineering strategy . Foster a culture of technical excellence, continuous learning, and psychological safety within the team, partnering with recruiting to scale the team . Plan and execute red team operations and adversary simulation exercises across Asana's infrastructure, products, and corporate environment . Perform clo
Leidos is seeking a detail-oriented Cybersecurity Analyst with expertise in Security Accreditation to support the assessment, authorization, and continuous monitoring of information systems. The successful candidate will ensure systems comply with government and industry cybersecurity requirements while supporting the organization's Risk Management Framework (RMF) processes. Primary Responsibilities: Lead and support the security accreditation process for information systems. Develop, maintain, and review security authorization packages. Conduct security control assessments in accordance with RMF and applicable security standards. Collaborate with system owners, engineers, and stakeholders to implement security controls. Perform security risk assessments and recommend mitigation strategies. Monitor systems for compliance with cybersecurity policies and standards. Maintain Plans of Action and Milestones (POA&Ms) and track remediation activities. Support continuous monitoring activities, including vulnerability management and security reporting. Prepare documentation for Assessment & Authorization (A&A) activities. Participate in internal and external cybersecurity audits. Stay current on cybersecurity threats, regulatory requirements, and best practices. Basic Qualifications: Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience). 3–7 years of experience in cybersecurity, information assurance, or security compliance. Experience implementing or supporting the NIST Risk Management Framework (RMF). Knowledge of: NIST SP 800-37 NIST SP 800-53 NIST SP 800-171 FISMA FedRAMP (preferred) Experience with vulnerability assessment tools such as Tenabl
Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk. Okta Federal, Inc. is seeking a seasoned Classified Systems Architect to join our Technology, Data & Intelligence (TDI) Team. This team is tasked with building and maintaining a robust, compliant, and scalable "High Side" developer platform that empowers our product teams to deliver Okta’s world-class Identity capabilities to the U.S. Government’s most sensitive missions. As part of the TDI Team, this individual will serve as the technical authority for the design, development, and evolution of our development platform for US Classified environments. This position’s mandate is to define the architectural vision for our air-gapped infrastructure, select and validate hardened tooling (e.g., Big Bang, Iron Bank, etc), and bridge the gap between strict DoD compliance requirements and modern DevOps velocity. You will partner closely with stakeholders across TDI, Product Engineering, Vulnerability Management, and Security Compliance to ensure that every component of the system—from the Kubernetes substrate to the application layer—is implemented as planned, secure by design, and optimized for user experience. Strong preference will be given to those with a bias for action and the ability to solve complex "air gap" challenges outside the box. What you’ll be doing Act as the central point for defining and evolving the architecture of Okta Federal’s SIPR/JWICS environments, ensuring alignment with DoD reference designs while tailoring them to Okta’s specific pro
About the team OpenAI’s mission is to build safe artificial general intelligence (AGI) which benefits all of humanity. This long-term undertaking brings the world’s best scientists, engineers, and business professionals into one lab together to accomplish this. In pursuit of this mission, our Go To Market (GTM) team is responsible for helping customers learn how to leverage and deploy our highly capable AI products across their business. The Cybersecurity specialist sales team partners with Account Directors, Technical Success, Marketing, and Partnerships to drive cybersecurity adoption that help bring AI to as many users as possible. About the role Our Sales team has a unique mission to help cybersecurity customers understand the deep impact that highly capable AI models can bring to their businesses, operations, employees, and customers. This role is a mixture of technical understanding, industry expertise, vision, partnership, and value-driven strategy. As an Account Director focused on Cybersecurity, you will own executive-level relationships with leading cybersecurity firms and help them safely and effectively deploy OpenAI’s technology across their organizations. You’ll work with customers to identify and scale high-impact use cases across areas such as security operations, threat intelligence, risk management, incident response, vulnerability management, workforce enablement, customer support, and enterprise knowledge management. You’ll be a key driver of opportunities through the entire sales cycle, from pipeline generation to closure and successful deployment. You’ll work with researchers, engineers, and solution strategists to help customers transform their operations and evolve the cybersecurity industry with AI. This role is based in San Francisco, Seattle or New York. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees. We are open to US-based remote candidates. In this role, you’ll: Support Accou
Information Systems Specialist – Public Sector Location: Remote, United States Level: Entry level Salary: $80,000–$100,000 base Requirements: U.S. citizenship and an active Secret clearance Travel: Occasional travel to customer sites Help secure the software that critical systems depend on RapidFort helps organizations reduce vulnerabilities and attack surface in containerized software. Our platform provides curated container images, runtime-based software reduction, and continuous security validation. We work with commercial customers and U.S. government teams operating in security-sensitive environments. We’re looking for an Information Systems Specialist to join our Public Sector team. This is an opportunity to build your technical career while supporting federal and DoD customers and learning container security and software supply chain technology from the engineers who build our platform. If you’ve developed your technical skills through military service, an internship, a co-op, a help desk, or another structured IT setting, we’d like to hear from you. What You’ll Do Support the day-to-day operation and troubleshooting of information systems used in federal and DoD environments. Work with Linux and Windows systems, networking, user access, and system configuration. Investigate customer issues, document your findings, resolve issues within your scope, and escalate complex problems to senior technical or engineering teams. Assist with installation, configuration, patching, system hardening, and security-related tasks. Maintain clear documentation, system inventories, and configuration records. Support compliance activities by gathering information and following established procedures. Learn RapidFort’s platform and develop practical knowledge of container security, vulnerability management, and the software supply chain. What You Bring 0–2 years of professional IT experience. Relevant military service, internships, co-ops, help desk work, and substantial hands-on
About the Team OpenAI builds powerful AI systems like ChatGPT, the OpenAI API, and enterprise products that serve millions of users across the globe. As we scale, securing our infrastructure, protecting sensitive data, and meeting global compliance standards are essential to our success and societal impact. Security at OpenAI is a cross-cutting function that spans infrastructure, applied engineering, legal, policy, and product. Technical Program Managers (TPMs) play a critical leadership role in aligning teams and delivering execution at scale and this role will be foundational in shaping how we secure OpenAI’s systems, users, and commitments. About the Role We’re seeking a Senior Technical Program Manager to drive cross-functional security, privacy, IT and compliance initiatives at the intersection of infrastructure, product, and policy. You will execute complex programs that reduce internal data access, prevent misuse, and ship security capabilities. You will focus your efforts on the most critical initiatives within Security, crossing the spectrum of insider threat, information security, physical security, and information technology challenges. This role is deeply technical and execution-focused. It requires a structured operator who thrives in ambiguity, partners effectively across boundaries, and applies principled judgment to scale trust, governance, and security across OpenAI’s systems and products. In this role, you will: Drive execution of critical security and compliance programs such as vulnerability management, merger and acquisition security and integration, infrastructure hardening, and datacenter security management. You will need to deeply collaborate on technical architecture and resolve technical problems in partnership with engineering. Partner with IT, Infrastructure, Application, Legal, Privacy, and Security teams to build scalable programs, and deliver critical security outcomes across multiple disciplines, including insider threat, information
Zscaler (NASDAQ: ZS) accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange™️ platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Distributed across 160+ public exchanges globally and thousands of private exchanges at the edge, the SASE-based Zero Trust Exchange is the world’s largest in-line cloud security platform. We believe the future of work is Human + AI and are building an AI-native enterprise where human potential is amplified by machine intelligence to solve the world’s hardest security challenges. Driven by deep customer obsession, we are committed to the mission, outcome, and to each other. We bring these commitments to life through three core behaviors: ownership and collaboration, trust through outcomes and impact, and a challenge culture with ongoing feedback. Ready to make an impact at the company pioneering security transformation in the AI era? Join us at Zscaler. About the Role We are looking for a Product Sales Account Executive to join our Sales and Go-to-Market team. This role can be based in any major city within San Francisco, Rockies or OH Valley area, reporting to the Director, SecOps. You will support a specific region, acting as the primary specialist to drive revenue growth within the security operations product suite, including unified vulnerability management, deception and threat hunting. You will lead the charge in demonstrating the power of cloud transformation to cement our position as a global leader in cloud security. What you’ll do (Role Expectations) Serve as the primary specialist for customers, partners, and internal teams to drive revenue growth across the security operations product portfolio Partner with domain-expert solution engineers to capture customer requirements and craft compelling value propositions that close complex business deals Own the regio
Ready to do the most impactful work of your career? At Coinbase , we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase . Coinbase is looking for a Senior Manager, Security Audit to lead the Internal Audit team's global coverage of information security, cybersecurity, and infrastructure/application security. Reporting to the Global Head of Internal Audit, you'll own the security audit portfolio, spanning identity and access management, threat detection, incident response, cloud security, application security, and crypto-native controls (wallets, cold storage, key management), while managing a small team and carrying your own book of complex audits. What you'll do: Own and lead Coinbase's global security audit portfolio covering IAM, threat detection, incident response, security architecture, cryptography/key management, vulnerability management, application security, and crypto-native security (wallets, cold storage), third-party/outsourced security oversight Partner with Security Engineering, Detection & Response, and AppSec teams as the cybersecurity subject matter expert, providing independent audit perspective and advisory value while maintaining third-line objectivity. Manage and develop a team of security auditors while personally leading high-complexity, high-risk security engagements across multiple jurisdictions. Synthesize complex technical security findings into clear, risk-prioritized reports for executive leadership, the Audit Committee, and the Board. Drive proactive i
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are looking for a highly skilled PSIRT Engineer to lead the vulnerability response program for Replit’s cloud-native AI platform. You will own the lifecycle of security vulnerabilities affecting our products and services—from intake to validation, remediation coordination, and public disclosure. This role requires strong technical ability to reproduce vulnerabilities , deep understanding of web/app/cloud exploit classes, and experience operating bug bounty and coordinated disclosure programs. You will work closely with Engineering, Cloud Security, SecOps, SRE, and IT teams to ensure vulnerabilities are fixed quickly and communicated responsibly. What You’ll Do Vulnerability Intake, Triage & Validation Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels. Independently validate, reproduce, severity-score, and document findings. Identify duplicates and maintain a clean vulnerability records pipeline. Assess relevance and exploitability using OWASP, cloud misconfiguration patterns, and identity/authentication/authorization risks (Oauth, OIDC). Remediation Coordination & SLA Management Work with Engineering, SecOps, IT, SRE, and Cloud Security to confirm product impact and drive remediation. Provide detailed reproduction steps, proof-of-concepts, and technical analyses. Track SLAs, remediation progress, regression testing, and systemic improvements. Support SOC 2, ISO 27001, and pentest evidence needs as part of vulnerability lifecycle governance. Bug Bounty & Vulnerability Disclosure Program Management Design and evolve the bug bounty program, including scope, rules, and reward structures. Man
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As an Intermediate Software Engineer in GitLab's Security section, you'll contribute to the data layer behind our vulnerability and dependency management capabilities. You'll design and develop well-scoped features within the systems that ingest, store, index, and query security report data, including integrations with key third-party systems. With a strong focus on PostgreSQL and scalable backend design, your work will support security features delivered by teams across GitLab. You'll work with clear context and strong support from the Senior Software Engineers and Staff Software Engineers around you. Yo
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As a Staff Software Engineer, you'll help lead two important areas for GitLab Security: the data layer behind our vulnerability and dependency management capabilities, and our move toward services outside the GitLab monolith. You'll design and develop systems that ingest, store, index, and query security report data, including integrations with key third-party systems. With a strong focus on PostgreSQL and scalable backend design, your work will support security features delivered by teams across GitLab. You'll take ownership of large deliverables from early ideas through implementation, working directly
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As a Senior Software Engineer, you'll work across two important areas for GitLab Security: the data layer behind our vulnerability and dependency management capabilities, and our move toward services outside the GitLab monolith. You'll design and develop systems that ingest, store, index, and query security report data, including integrations with key third-party systems. With a strong focus on PostgreSQL and scalable backend design, your work will support security features that teams across GitLab deliver. You'll own significant parts of larger deliverables from design through delivery. You'll shape the
SonicWall is a cybersecurity forerunner with more than 30 years of expertise and is recognized as a leading partner-first company, ensuring our partners and their customers are never alone in the fight against cybercrime. With the ability to build, scale and manage security across the cloud, hybrid and traditional environments in real-time, SonicWall provides relentless security against the most evasive cyberattacks across endless exposure points for increasingly remote, mobile and cloud-enabled users. With its own threat research center, SonicWall can quickly and economically provide purpose-built security solutions to enable any organization—enterprise, government agencies and SMBs—around the world. For more information, visit www.sonicwall.com or follow us on Twitter , LinkedIn , Facebook and Instagram . Responsibilities: Design and develop control‑plane and system services for a firewall platform, operating above the networking dataplane (OSI Layer 3+). Build and maintain management interfaces and APIs , including configuration frameworks, CLI, secure access (SSH), logging, and diagnostics. Implement security services such as authentication (SAML), guest access, SSL/TLS handling, and certificate lifecycle management . Develop embedded services for content filtering , including URL categorization, reputation, and rating systems, along with SNMP/telemetry support. Lead efforts in licensing systems , vulnerability remediation, and secure architecture in collaboration with cross‑functional teams. Requirements: 8+ years of experience in C/C++ systems development for embedded platforms, security appliances, or network operating systems. Strong hands‑on expertise with configuration frameworks, service APIs, CLI development, logging systems, and secure remote access (SSH) . Solid understanding of L3–L7 networking and security concepts , including SSL/TLS, au
Get new vulnerability management engineer jobs by email
Daily job updates · Unsubscribe anytime