Senior Vulnerability Engineer

Stelle nicht auf LinkedIn

🕒 vor 3 Monaten

🗣️🇺🇸🇬🇧 Englisch erforderlich

Jetzt Bewerben
Ähnliche Remote-Jobs finden

📊 Überprüfen Sie Ihre Lebenslauf-Bewertung für diese Stelle

Verbessern Sie Ihre Chancen auf ein Vorstellungsgespräch, indem Sie Ihre Lebenslauf-Bewertung vor der Bewerbung überprüfen.

Logo of Keeper Security, Inc.

Keeper Security, Inc.

501 - 1000 Mitarbeiter

Gegründet 2011

🔒 Cybersecurity

☁️ SaaS

🏢 Unternehmen

💰 Private Equity Round - Keeper Security im 2023-05

Cybersecurity • SaaS • Enterprise

Keeper Security, Inc. ist ein Cybersecurity-Unternehmen, das cloud-basierte, Zero-Trust Privileged Access Management (PAM) und Passwortmanagement-Lösungen anbietet. Die KeeperPAM-Plattform, der Secrets Manager, der Endpoint Privilege Manager und verwandte Produkte sichern Anmeldeinformationen, Sitzungen und den Fernzugriff für Unternehmen, MSPs und Organisationen des öffentlichen Sektors durch End-to-End-Verschlüsselung und eine Zero-Knowledge-Architektur. Keeper agiert hauptsächlich als SaaS-Anbieter, legt großen Wert auf strenge Compliance (FedRAMP, ISO, SOC 2, FIPS, PCI DSS, HIPAA) und konzentriert sich darauf, Datenverletzungen zu verhindern und privilegierten Zugriff in groß angelegten Umgebungen zu verwalten.

Beschreibung

• Design and implement scalable vulnerability scanning and asset discovery solutions across multi-cloud and SaaS environments • Engineer and maintain integrations between vulnerability management tools and internal systems, including CI/CD platforms, ticketing systems, and source control tools • Automate vulnerability ingestion, enrichment, prioritization, and remediation workflows using APIs and scripting • Develop risk-based prioritization models by correlating vulnerability data with threat intelligence and exploit activity • Build and maintain pipelines to integrate vulnerability scanning into CI/CD processes • Create dashboards and analytics to track vulnerability exposure, remediation SLAs, and risk trends • Continuously improve coverage and accuracy of asset inventory and scanning capabilities • Monitor and respond to zero-day vulnerabilities, CISA KEV bulletins, and active exploit campaigns • Partner with Engineering and DevOps teams to troubleshoot and remediate vulnerabilities in applications and infrastructure • Contribute to secure architecture and hardening efforts across cloud and application environments • Support compliance requirements, including FedRAMP, StateRAMP, SOC 2, ISO 27001, and NIST SP 800-53, through technical implementation and evidence generation • Document systems, workflows, and automation for repeatability and scale • Support the execution of red team exercises, penetration tests, and bug bounty programs in alignment with real-world threat scenarios • Coordinate and validate findings from internal and external testing activities, ensuring accuracy, severity calibration, and reproducibility • Integrate offensive security findings into vulnerability management workflows to drive prioritized remediation • Partner with external vendors and researchers to triage submissions and improve signal quality in bug bounty programs • Continuously improve testing methodologies, coverage, and tooling to reflect evolving attack techniques • Correlate red team, penetration testing, and bug bounty findings with vulnerability data to identify systemic weaknesses

🎯 Anforderungen

• 5–8+ years of experience in vulnerability management, security engineering, or related technical roles • Strong hands-on experience with vulnerability scanning tools, CVE/CVSS scoring, and exploit analysis • Experience building automation using Python, PowerShell, or similar scripting languages • Experience working with APIs and integrating security tools into engineering workflows • Strong understanding of cloud platforms, including AWS, GCP, and Azure, as well as modern application architectures • Experience embedding security into CI/CD pipelines and developer workflows • Ability to troubleshoot vulnerabilities across system, network, and application layers • Hands-on experience with penetration testing, red teaming, or bug bounty programs, including triage and validation of findings • Working knowledge of compliance frameworks such as NIST SP 800-53, CIS Controls, ISO 27001, and SOC 2

🏖️ Vorteile

• Medical, Dental & Vision (inclusive of domestic partnerships) • Employer Paid Life Insurance & Employee/Spouse/Child Supplemental life • Voluntary Short/Long Term Disability Insurance • 401K (Roth/Traditional) • A generous PTO plan that celebrates your commitment and seniority (including paid Bereavement/Jury Duty, etc) • Above market annual bonuses

Jetzt Bewerben

Ähnliche Jobs

🕒 vor 3 Monaten

Deepgram

51 - 200

💼 Beratung

🏥 Gesundheitswesen

📦 Logistik

Founding engineer building the Data Intelligence tools at Deepgram transforming unstructured audio into insights. Collaborating with teams on advanced AI models while focusing on automation.

🇺🇸 Vereinigte Staaten – Remote

💵 $165.000 - $230.000 / Jahr

💰 €47.000.000 Series B im 2022-11

⏰ Vollzeit

🟠 Senior

👷🏻‍♀️ Ingenieur

🦅 H1B-Visum-Sponsor

info

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 3 Monaten

Hanson Professional Services Inc.

501 - 1000

💼 Beratung

🏥 Gesundheitswesen

📦 Logistik

Power Controls Engineer at Hanson, focusing on the design and implementation of power control systems. Collaborating with engineering teams on electric power infrastructure projects.

🇺🇸 Vereinigte Staaten – Remote

💵 $105.000 - $160.000 / Jahr

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👷🏻‍♀️ Ingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 3 Monaten

Wood

10.000+ Mitarbeiter

💼 Beratung

🏗️ Bauwesen

📦 Logistik

Intermediate Mechanical Engineer specializing in HVAC design and analysis within life sciences industry. Focused on construction drawings, specifications, and equipment assessments for manufacturing plants.

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 3 Monaten

Salas O'Brien

1001 - 5000

💼 Beratung

🏗️ Bauwesen

🏥 Gesundheitswesen

Structural Project Engineer for Axiom developing structural designs and calculations for various projects. Collaborating with teams to ensure project execution and maintaining quality standards in engineering solutions.

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👷🏻‍♀️ Ingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 3 Monaten

Atlas Technica

201 - 500

🔒 Cybersecurity

💸 Finanzen

Project Engineer delivering IT management and security solutions for hedge funds and investment firms. Collaborating with teams to enhance client infrastructures and support technical projects.

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🟠 Senior

👷🏻‍♀️ Ingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

Azure

Cloud

Cyber Security

DNS

Firewalls

Switching

TCP/IP