Senior Security Research Engineer
$175,500–$263,300 year
On-siteCalifornia, United States
Job Summary
Lead complex Global Vulnerability Management workstreams to advance Threat Exposure Management capability and transition toward a Continuous Threat Exposure Management operating model. Translate annual goals into defined delivery plans, milestones, and success measures while monitoring progress and adjusting execution. Conduct hands-on vulnerability research and technical analysis to confirm security conditions, characterize exploitability, and provide actionable remediation guidance. Improve discovery and assessment across network, cloud, endpoint, application, and container environments using risk-based prioritization and threat intelligence. Partner with engineering and security teams to mobilize remediation, clarify ownership, and measure outcomes through accepted disposition or mitigation. Evolve GVM platforms, integrations, and automation to improve coverage and operational scale. Mentor engineers, contribute to technical standards, and communicate trends and risks to technical, operational, and leadership audiences. Some travel may be required.
Required Qualifications
- 8+ years of relevant experience in information security, information technology, systems engineering, or a related field, including substantial experience in vulnerability management, security research, or exposure management
- Bachelor's degree or equivalent in computer science, information security, or a related discipline
- Experience leading complex technical workstreams across multiple teams, translating objectives into delivery plans, and achieving measurable outcomes without relying on direct reporting authority
- Hands-on experience with vulnerability research, technical analysis, security validation, risk-based prioritization, and remediation or mitigation guidance
- Experience assessing vulnerabilities across several technology domains, such as operating systems, networks, cloud services, applications, endpoints, containers, databases, or hybrid infrastructure
- Experience with vulnerability discovery, assessment, validation, or exposure-management platforms and their supporting integrations
- Knowledge of adversarial tactics, exploitation techniques, threat intelligence, and attack frameworks such as MITRE ATT&CK, with the ability to apply that information to vulnerability prioritization
- Experience using scripting, programming, APIs, or automation to improve security analysis and operational workflows. Relevant technologies may include Python, SQL, Bash, PowerShell, JavaScript, or comparable languages
- Experience analyzing and contextualizing security data to connect technical findings with asset, service, business, threat, control, and remediation information
- Familiarity with software engineering practices such as version control, testing, code review, CI/CD, reusable components, and controlled production releases
- Ability to communicate complex security conditions, priorities, tradeoffs, and recommendations clearly to technical, operational, and leadership audiences
- Experience mentoring engineers or analysts and influencing technical practices across teams
- Some travel may be required
Desired Qualifications
- Experience helping evolve a traditional vulnerability-management function toward a TEM or CTEM operating model
- Experience with continuous security validation, adversarial exposure validation, exploit research, or proof-of-concept development
- Experience securing cloud, container, application, or build-pipeline environments and integrating security capabilities into engineering workflows
- Experience with security-data and analytics platforms such as Snowflake, Domo, or comparable technologies
- Experience applying automation, advanced analytics, or AI-enabled capabilities to vulnerability analysis, prioritization, validation, or remediation workflows
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.