Назад
Company hidden
обновлено 9 дней назад

Senior Security Engineer (Vulnerability Management)

122 254 - 140 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Engineer (Vulnerability Management/Cybersecurity): Maturing an enterprise vulnerability management program across infrastructure, applications, software, AI systems, and external attack surfaces with an accent on risk prioritization, remediation tracking, and security reporting. Focus on building AI-assisted human-in-the-loop workflows, aligning controls with PCI-DSS, SOC 2, NIST CSF, and ISO 27001, and driving measurable risk reduction across business units.

Location: US-GA-Remote

Base salary: $122,254–$140,000 USD per year

Company

hirify.global provides vertical software and embedded payments technology for small and medium-sized businesses across multiple industries.

What you will do

  • Contribute to and mature the enterprise vulnerability management program, ensuring remediation is completed according to SLAs.
  • Identify and report vulnerabilities across cloud and on-premises infrastructure, applications, software, AI systems, and external attack surfaces.
  • Monitor external attack surface exposure and support risk-based remediation prioritization.
  • Produce vulnerability metrics, trend reports, and risk summaries for security leadership and business stakeholders.
  • Align vulnerability management activities with PCI-DSS, SOC 2, NIST CSF, and ISO 27001 requirements.
  • Develop AI-assisted human-in-the-loop automation and workflows for proactive security initiatives.

Requirements

  • 8+ years of information technology or security experience, including 2–4+ years in vulnerability management, attack surface management, or related security functions.
  • Experience with security platforms such as Wiz, Snyk, Qualys, Nessus, or Microsoft Defender.
  • Knowledge of CVSS, EPSS, risk-based scoring, and application security testing concepts including SAST, DAST, and IAST.
  • Basic scripting or programming experience, or a strong desire to develop this skill.
  • Hands-on experience with AI-assisted security workflows, prompt engineering, agent development, and MCP tooling.
  • CISSP or an equivalent certification, a cybersecurity degree or equivalent experience, and defensive or offensive security training or experience.

Nice to have

  • Experience with Burp Suite, Postman, GitHub, or similar application security tools.
  • Project management knowledge, training, or certifications.
  • Experience in a multi-business-unit or enterprise environment and with process documentation.

Culture & Benefits

  • Fully remote work environment with responsibility for managing multiple concurrent priorities independently.
  • High-ownership work within a small proactive security team.
  • Direct collaboration with security leadership, Security, IT, and business-unit engineering teams.
  • Inclusive workplace committed to diversity of thought, experience, and background.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →