Security Engineer (Vulnerability Engineering)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Security Engineer (Vulnerability Engineering): Designing and owning the vulnerability engineering pipeline to automate the flow from threat intelligence to actionable remediation with an accent on AI-powered tooling and automated PR generation. Focus on reducing developer friction, eliminating false positives, and building scalable security automation.
Location: Remote across Canada, the US, and the UK
Salary: $128,000 – $200,000 per year
Company
is a high-growth SaaS company providing business and practice management tools for healthcare clinics.
What you will do
- Design, build, and own the vulnerability engineering pipeline from threat intelligence ingestion to automated PR generation.
- Drive the adoption of AI within the security team by experimenting with and sharing AI-powered tooling.
- Partner with development teams to provide validated security findings as a service, reducing remediation friction.
- Coordinate and track the resolution of complex, multi-team vulnerability findings.
- Contribute to the on-call rotation and enhance incident response runbooks and post-incident reviews.
Requirements
- Depth in security engineering with a track record of shipping automation or internal security tooling.
- Hands-on experience with Python and CI/CD security integrations, particularly GitHub Actions.
- Applied knowledge of web and API vulnerability classes and familiarity with SAST, SCA, DAST, and ASPM tooling.
- Ability to influence cross-functional teams without authority and high emotional intelligence.
- Experience acting as a force multiplier through mentoring and setting technical direction.
- Must be based in Canada, the US, or the UK.
Nice to have
- Experience with mobile application vulnerabilities.
Culture & Benefits
- Remote-first environment with a team spanning Canada, the US, and the UK.
- Transparent, growth-based compensation model with regular career development conversations.
- Comprehensive benefits package.
- Culture of curiosity and experimentation, especially with AI-assisted workflows.
- Focus on delivering "delight" and solving real problems collaboratively.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →