Most security assurance work is reactive: a customer asks, a team scrambles, an answer goes out. This role exists to end that cycle. As a Senior Staff Analyst, you’ll own a named portfolio of our most significant customers from a security perspective, and get ahead of what they need — their regulatory environment, their audit calendar, their risk appetite, their control expectations — well enough to have the evidence ready before the request arrives. You’ll lead customer security audits hands-on, sit across from customer security teams as a peer rather than a form-filler, and build account security plans that make the next assessment predictable instead of painful. This is deliberately a hands-on senior individual contributor role. You’ll spend your time in audits, in customer conversations, and in the detail of controls and evidence — not in a management chain. If you’ve got deep SOC 2 and ISO 27001 knowledge, real technical range across cloud architecture, identity and vulnerability management, and the presence to hold a room with a sceptical CISO, this is a portfolio you can genuinely own. Here’s a breakdown of what you’ll do (not all of it, just the important stuff): Own a portfolio of strategic accounts as their dedicated security point of contact, building durable relationships with their security, risk, compliance and procurement teams. Lead customer security audits and assessments hands-on — scoping, preparing evidence, running the sessions, defending control design and driving findings to closure with internal owners. Build and maintain an account security plan for each account: their frameworks and regulators, audit and reassessment cycles, known concerns, open items and the roadmap commitments they care about. Anticipate requirements before they’re raised, tracking regulatory change, industry expectations and each account’s compliance calendar so documentation and evidence are staged in advance. Act
Jobiba hiring network
Vulnerability Management Engineer Jobs
121 active opportunities · Updated for October 2026
Fresh results
15 shown
Explore current vulnerability management engineer jobs. Use filters to narrow by work mode, employment type, experience and date posted.
Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career. About the team In this role, you’ll join Stripe’s Vulnerability Management team, whose mission is to “Surface vulnerabilities at scale across Stripe.” Our vision is to create a culture of continuous excellence in managing vulnerabilities. The bug bounty program is an important pillar of this mission, acting as a critical line of defense in Stripe’s security “immune system.” What you’ll do We seek a highly technical and detail-oriented Security Analyst to join our team, focusing on the front lines of bug bounty triage and researcher engagement. In this role, you’ll be responsible for the end-to-end lifecycle of security vulnerability reports from our bug bounty program. You’ll own the overall effectiveness of Stripe’s bug bounty program with autonomy to implement continuous improvements (e.g., researcher campaigns, scoring transparency). You’ll play a key role in understanding the root cause of vulnerabilities, coordinating timely resolutions, and directly impacting the security posture of Stripe’s products. A core aspect of this role is developing a deep understanding of Stripe and acquired company products, assets, and their configuration to effectively assess and prioritize vulnerabilities. Responsibilities Analyze, assess, reproduce, and triage incoming s
THE OPPORTUNITY We're looking for a Windows Server Administrator to join our team in Little Rock, Arkansas, to help plan, design, build, and support solutions for one of the nation’s largest retail companies. Our ideal candidate enjoys working in a fast-paced, hands-on environment supporting critical infrastructure. In this role, you’ll manage, secure, and optimize Windows-based systems across physical and virtual environments. You’ll have the opportunity to work with various technologies, contribute to modernization efforts, and help strengthen our disaster recovery and automation processes. The ideal candidate is proactive, dependable, and ready to take ownership of their work while collaborating with others. This role offers room to grow, whether through learning new tools, streamlining daily operations, or leading technical initiatives that make a real impact. THE TEAM The Windows Server Team is a close-knit, collaborative group responsible for managing and administering all company Windows servers and domains. We work across multiple IT areas to ensure stability, security, and efficiency. Our team thrives on helping each other, sharing knowledge, and finding more innovative ways to do the job. From hardware setup and server virtualization to Active Directory management and vulnerability remediation, you’ll take ownership of our entire Windows ecosystem. This is a highly collaborative, hands-on role where you will maintain and secure the full stack that keeps our operations running. WHAT YOU WILL DO Configure, deploy, manage, and secure complex Windows Server environments. Collaborate across teams to plan and maintain enterprise-level server architectures. Automate routine tasks to improve reliability and reduce manual work. Participate in disaster recovery planning and testing. Support physical and virtual infrastructure, including patching, upgrades, and migrations. Stay current with Microsoft technologies and industry trends. Docum
The OT Cybersecurity Specialist is responsible for supporting the implementation, monitoring, and management of cybersecurity measures for the organization’s Operational Technology (OT) systems. This role involves securing industrial control systems (ICS), SCADA systems, and other OT assets from cyber threats, conducting vulnerability assessments, monitoring networks for anomalies, and responding to security incidents. The OT Cybersecurity Specialist will work closely with other IT and cybersecurity teams to ensure a robust and secure OT environment. Source: Adani Group | Job ID: 45584
Vice President, AI Vulnerability Operations — O'Fallon, Missouri. Apply via Workday.
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As a Senior Product Manager , you will own GitLab's Secret Detection offering and the Vulnerability Research function that produces the detection content across security products. Secret Detection is one of the highest-signal, highest-volume security capabilities on the platform. Leaked credentials are the most common initial access vector in real breaches, and as AI agents write, commit, and configure more of the software, the surface area for exposed secrets grows faster than the number of humans watching it. You will own the full loop: detect a secret with high precision, tell the customer whether it i
The VAPT Lead will be responsible for leading the vulnerability assessment and penetration testing (VAPT) initiatives across the organization. This role involves managing the entire VAPT process, from planning and scoping assessments to executing and reporting on findings. The VAPT Lead will collaborate with other cybersecurity teams to identify, assess, and mitigate vulnerabilities in the organization’s infrastructure, applications, and network environments. The VAPT Lead is a key player in improving the security posture of the organization by providing in-depth security testing and actionable insights to prevent potential cyber threats. Source: Adani Group | Job ID: 56580
The Engineering Lead Analyst – SonarQube & Code Quality Engineering is a senior-level engineering role responsible for leading static code analysis, automated code quality governance, security vulnerability remediation, and AI-augmented developer enablement across enterprise software delivery pipelines. In this role, you will champion software reliability, maintainability, clean-coding standards, and automated quality gates. You will partner with development teams, system architects, and platform engineering to integrate and manage enterprise-scale code quality platforms (such as SonarQube) both on-premises and in cloud/SaaS environments. Additionally, you will drive modern engineering practices by embedding Behavior-Driven Development (BDD) within your own software delivery and leveraging Agentic AI workers and Model Context Protocol (MCP) architectures to optimize developer experience, streamline code governance, and boost engineering velocity. Key Responsibilities 1. Code Quality & Static Analysis Platform Ownership Lead the architecture, deployment, administration, and continuous enhancement of enterprise Static Application Security Testing (SAST) and Code Quality platforms (e.g., SonarQube , DeepSource, Codacy, Semgrep). Configure, calibrate, and enforce automated Quality Gates, code rulesets, technical debt calculation models, and code-coverage baselines across multi-language enterprise repositories. Oversee version upgrades, patching, high availability, and operational maintenance for on-premises and SaaS/cloud-hosted code quality infrastructure. 2. CI/CD & Pipeline Integration <li style=
Senior Container Security Engineer – CVE Remediation & Image Hardening About the Role We are looking for a hands-on Senior Container Security Engineer to lead vulnerability remediation and image hardening across Linux-based container environments. This role focuses on deep operating system and container security engineering rather than simple vulnerability scanning. You will analyze, remediate, rebuild, harden, and continuously optimize container images used in modern cloud-native platforms. You will work closely with platform engineering, DevOps, infrastructure, and security teams to build automated remediation pipelines, reduce the attack surface, and deliver production-ready hardened images. What You’ll Do - Own end-to-end CVE remediation across Linux-based container images. - Analyze vulnerabilities across OS packages, libraries, runtimes, and dependencies. - Patch, rebuild, validate, and maintain hardened container images at scale. - Reduce attack surface by removing unnecessary packages, binaries, services, and dependencies. - Build and scale automated remediation pipelines for continuous image patching. - Improve image security posture while minimizing operational disruption. - Generate, validate, and maintain SBOMs to support supply chain visibility and compliance. - Integrate remediation workflows into CI/CD and GitOps pipelines. - Optimize image size, startup performance, and operational efficiency. - Research emerging Linux, container, Kubernetes, and software supply chain threats. - Troubleshoot complex dependency, package compatibility, and runtime security issues. - Help define internal standards for hardened images and secure software delivery. What You Bring - 5+ years of experience in Linux systems engineering, platform engineering, DevSecOps, security engineering, or SRE. - Deep understanding of Linux distributions (Debian, Ubuntu, Alpine, RHEL). - Strong hands-on experience with Docker, Kubernetes, and
The Security team is responsible for protecting Asana’s employees, users, and customers. We are a team of security engineers and risk and compliance practitioners who build innovative safeguards to ensure that our data is protected against threats and that we comply with legal, regulatory, and customer requirements. We collaborate closely with teams across the organization to foster a culture of security throughout our product and operations. We’re looking for an Application Security Engineer to join our Security team in Warsaw. You’ll be a foundational member of the security presence in a key engineering hub, partnering directly with IT, infrastructure, and product teams to ensure we design and ship secure software. You will be instrumental in scaling our security practices by conducting security design reviews, threat modeling, and vulnerability assessments across our products and internal applications, eliminating entire classes of vulnerabilities, and championing a security-first mindset. This role is based in our Warsaw office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do, and your recruiter can share more about the in-office requirements. We offer a Contract of Employment (UoP) for our employees in Poland. What you’ll achieve ● Conduct security architecture reviews and threat modeling for new features and services across our product and internal applications, identifying risks early and influencing secure design decisions. ● Perform vulnerability assessments of software and systems, using a range of assessment methodologies to surface and prioritize security weaknesses across our product surface. ● Triage, investigate, and drive remediation of vulnerabilities from our bug bounty program and automated s
About the Team Our Safety Systems team is at the forefront of OpenAI's mission to build and deploy safe AGI, driving our commitment to AI safety and fostering a culture of trust and transparency. Within Safety Systems, the Model Policy team aligns model behavior with desired human values and norms. We co-design policy with models and for models by driving rapid policy taxonomy iteration based on data and defining evaluation criteria for foundational models’ ability to reason about safety. About the Role Frontier AI systems are rapidly expanding what is possible in cybersecurity and software engineering. These capabilities create major defensive opportunities, but they also raise serious dual-use and misuse risks across areas such as malware development, exploit discovery, vulnerability chaining, credential abuse, cyber intrusion, and autonomous offensive operations. In this role, you will help define how OpenAI’s models should behave in high-risk cybersecurity contexts. You will develop policy frameworks, threat models, taxonomies, evaluations, and behavioral specifications that guide model behavior across training, deployment, and monitoring systems. This role sits at the intersection of cybersecurity, AI safety, threat modeling, evaluation science, and policy implementation. You will work closely with research, engineering, safety training, preparedness, and product teams to build policies that are technically grounded, measurable, enforceable, and responsive to real-world cyber risk. Your Responsibilities: Design and maintain model policies for cybersecurity and frontier-risk domains, especially dual-use and high-risk cyber capabilities. Translate cybersecurity threat models into clear behavioral specifications, evaluation criteria, grading guidance, and system-level mitigations. Define practical boundaries between legitimate security research, defensive workflows, and assistance that could materially enable harmful activity. Build policy artifacts that support i
Become a part of our caring community Do you thrive on designing secure, enterprise-scale solutions that protect critical systems, data, and networks? As a Lead Security Architect in Humana, you will play a key role in shaping the security blueprint for the organization by aligning security architecture and infrastructure with enterprise business and technology priorities. In this role, you will partner with EIP and business leaders to assess emerging threats, identify architectural gaps, and design forward-looking security solutions that strengthen Humana's overall security posture. You will also lead security assessments, vulnerability analysis, and product security reviews while helping develop innovative testing approaches and mitigation strategies for evolving risks. This is a high-impact opportunity to influence enterprise architecture, guide secure technology design, and help protect the business through strategic, modern security architecture. The Lead Security Architect engages with relevant EIP stakeholders to identify current and emerging security threats and works to design security architecture elements to mitigate threats as they emerge. Additionally, the role actively works to identify gaps within existing EIP reference architecture and designs updates to impacted security architecture elements to mitigate emerging threats. Performs and oversees efforts to conduct vulnerability testing, risk analysis, and security assessments of relevant enterprise / EIP infrastructure. Ensures EIP and Humana stakeholder security requirements are necessary to protect Humana's business functions and are adequately addressed in all aspects of enterprise architecture. The Lead Security Architect role is aligned to a segment (line of business) to proactively discover security issues during solution design and prevent vulnerabilities during development.
Senior Offensive Cybersecurity Test Analyst Company: The Boeing Company The Boeing Company is seeking a Senior Offensive Cybersecurity Test Analyst to support the Boeing Test & Evaluation (BT&E) cyber test capability. The selected applicant will join a highly technical Test & Evaluation team building an offensive cyber test capability in Berkeley, MO . This position will be providing testing services to Boeing Defense Space & Security (BDS) portfolio. The primary responsibilities will include Product Security (Cyber) test planning, integration, and execution, mission-based risk assessments, vulnerability assessments, and penetration tests. The selected applicant will become a Berkeley team member trained across the broader BT&E Product Security Capability team. Position Responsibilities: Lead execution of penetration tests to identify, exploit, and assess a target system’s vulnerabilities in a threat-representative manner on embedded systems and IP-based networks Subject Matter Expert for emulating advanced cyber adversary (advanced persistent threats) tactics, techniques and procedures (TTPs) Lead controlled attack simulations that test the effectiveness of a blue team and its capabilities to detect, block, and mitigate attacks and breaches</span
Software Systems Engineer (Associate or Experienced) Company: The Boeing Company The Boeing Company has an exciting opportunity for a Software Systems Engineer to join the SATCOM Mission Planning Software Engineering team in Seal Beach, CA. Our teams are currently hiring for a broad range of experience levels including; Associate and Experienced Software Engineers. The Satellite Communication (SATCOM) Mission Planning team is a critical part of the U.S. military’s nuclear command, control, and communications (NC3) network, providing nuclear-survivable connectivity. Our team develops software tools and services for advanced satellite and ground systems. This role offers the opportunity to work in a fast-paced development environment using modern, scalable technology and tools. Our team works in an Agile and CI/CD environment with automated testing, vulnerability scanning, and quality scanning capabilities. Position Responsibilities: Develops and maintains requirements, architecture, algorithms, interfaces, and designs for high-performance APIs between front-end and back-end software services Supports software development activities in an Agile environment using DevSecOps methodologies, including integration of completed software components into a fully functional software system Supports the development of critical features and support the full development lifecycle from design through deployment Builds, architects, and consumes APIs and backend services as part of the platform ecosystem, with an emphasis on automation, testing, and security Conducts code reviews to maintain code quality, enforce best practices, and ensure compliance wit
Software Engineer (Associate or Experienced) Company: The Boeing Company The Boeing Company has an exciting opportunity for a Software Engineer to join the SATCOM Mission Planning Software Engineering team in Colorado Springs, CO. Our teams are currently hiring for a broad range of experience levels including; Associate and Experienced Software Engineers. The Satellite Communication (SATCOM) Mission Planning team is a critical part of the U.S. military’s nuclear command, control, and communications (NC3) network, providing nuclear-survivable connectivity. Our team develops software tools and services for advanced satellite and ground systems. This role offers the opportunity to work in a fast-paced development environment using modern, scalable technology and tools. Our team works in an Agile and CI/CD environment with automated testing, vulnerability scanning, and quality scanning capabilities. Position Responsibilities: Develops and maintains requirements, architecture, algorithms, interfaces, and designs for high-performance APIs between front-end and back-end software services Supports software development activities in an Agile environment using DevSecOps methodologies, including integration of completed software components into a fully functional software system Supports the development of critical features and support the full development lifecycle from design through deployment Builds, architects, and consumes APIs and backend services as part of the platform ecosystem, with an emphasis on automation, testing, and security Conducts code reviews to maintain code quality, enforce best practices, and ensure compliance with establis
Get new vulnerability management engineer jobs by email
Daily job updates · Unsubscribe anytime