Domino Data Lab logo
Domino Data LabPosted 3 weeks ago

Vulnerability Engineer

RemoteIndia

Full TimeMid LevelMediumTECH

Job Summary

Own first-pass CVSS scoring and exploitability analysis to close the SLA gap between finding and answering risk. Reproduce and confirm customer-reported and pen-test findings before they reach Engineering, ensuring fix priority reflects real exploitability. Maintain SAST/DAST and vulnerability scanning automations, troubleshooting failures and tuning configs so data stays clean. Build or run PoC exploits on select CVEs to bring validated risk into prioritization conversations with Engineering. Free up the Staff Security Engineer to focus on program-level improvement by handling day-to-day vulnerability management load.

Required Qualifications

  • Hands-on experience managing vulnerabilities for a large SaaS product, across OS, container, and dependency exposure
  • A track record triaging and tracking CVEs for a SaaS or containerized product: reading scan reports, prioritizing by severity, and following through to resolution
  • Experience reproducing and validating reported vulnerabilities, whether from customer disclosures or pen test findings, not just logging them
  • Time spent with vulnerability scanning tools such as Prisma Cloud/Twistlock, JFrog, or Trivy, including reconciling findings across tools
  • Comfort building or maintaining SAST/DAST pipeline automation, and triaging what the scans turn up
  • Experience partnering with Engineering to get fixes prioritized and shipped, not just reported
  • Background in a highly regulated environment or modern software company, ideally one that moves at startup or scale-up speed
  • Strong scripting ability, Python preferred
  • Working knowledge of CVSS v3.1/v4.0 scoring and the judgment to assess risk, not just report it
  • Exploit development or PoC skills to validate real-world exploitability of CVEs, using tools like Burp Suite
  • Familiarity with OWASP Top 10 and testing methodology
  • Working knowledge of containers and Kubernetes, plus core Linux, AWS, and networking fundamentals
  • Basic understanding of authentication/authorization concepts (tokens, session handling, auth bypass patterns) and API security fundamentals
  • Basic threat modeling: thinking in attack paths, not just isolated severity scores
  • Clear communication, comfortable navigating risk conversations with Engineering and customers, including drafting risk statements a non-technical audience will actually read
  • Comfort operating with ambiguity, since not every finding arrives with a clean severity or fix path

Desired Qualifications

  • OSWA, OSWE, or a similar offensive security certification (e.g. GWAPT, GPEN)
  • Familiarity with Airflow and Snowflake

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce