Vulnerability Engineer
D
DominoData Science AI
Remote IndiaFull-TimeMiddle
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Required Skills
- AWSPythonKubernetesLinux
Requirements
- Hands-on experience managing vulnerabilities for a large SaaS product across OS, container, and dependency surfaces.
- Proven track record triaging and tracking CVEs, including reading reports and prioritizing resolution.
- Experience reproducing and validating vulnerabilities from disclosures or pen-test findings.
- Proficiency with vulnerability scanning tools such as Prisma Cloud/Twistlock, JFrog, or Trivy.
- Experience building or maintaining SAST/DAST pipeline automation.
- Strong scripting ability, with Python preferred.
- Working knowledge of CVSS v3.1/v4.0 scoring and risk assessment methodologies.
- Exploit development or PoC skills for validation (e.g., using Burp Suite).
- Familiarity with OWASP Top 10 and testing methodology.
- Working knowledge of containers, Kubernetes, Linux, AWS, and networking fundamentals.
- Understanding of authentication/authorization concepts and API security.
- Basic threat modeling and ability to draft clear risk statements for non-technical audiences.
Responsibilities
- Own first-pass CVSS scoring and exploitability analysis to close SLA gaps.
- Reproduce and confirm customer-reported and pen-test findings before engineering handoff.
- Maintain and troubleshoot SAST/DAST and vulnerability scanning automation pipelines.
- Build or run PoC exploits on select CVEs to validate real-world risk.
- Partner with Engineering to get security fixes prioritized and deployed.
- Free up capacity for the Staff Security Engineer by managing day-to-day vulnerability operations.
View Full Description & ApplyYou'll be redirected to the employer's site