Vulnerability Engineer

D
DominoData Science AI
Remote IndiaFull-TimeMiddle
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Required Skills
AWSPythonKubernetesLinux

Requirements

  • Hands-on experience managing vulnerabilities for a large SaaS product across OS, container, and dependency surfaces.
  • Proven track record triaging and tracking CVEs, including reading reports and prioritizing resolution.
  • Experience reproducing and validating vulnerabilities from disclosures or pen-test findings.
  • Proficiency with vulnerability scanning tools such as Prisma Cloud/Twistlock, JFrog, or Trivy.
  • Experience building or maintaining SAST/DAST pipeline automation.
  • Strong scripting ability, with Python preferred.
  • Working knowledge of CVSS v3.1/v4.0 scoring and risk assessment methodologies.
  • Exploit development or PoC skills for validation (e.g., using Burp Suite).
  • Familiarity with OWASP Top 10 and testing methodology.
  • Working knowledge of containers, Kubernetes, Linux, AWS, and networking fundamentals.
  • Understanding of authentication/authorization concepts and API security.
  • Basic threat modeling and ability to draft clear risk statements for non-technical audiences.

Responsibilities

  • Own first-pass CVSS scoring and exploitability analysis to close SLA gaps.
  • Reproduce and confirm customer-reported and pen-test findings before engineering handoff.
  • Maintain and troubleshoot SAST/DAST and vulnerability scanning automation pipelines.
  • Build or run PoC exploits on select CVEs to validate real-world risk.
  • Partner with Engineering to get security fixes prioritized and deployed.
  • Free up capacity for the Staff Security Engineer by managing day-to-day vulnerability operations.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now