Назад
Company hidden
обновлено 5 дней назад

Senior Security Research Engineer (Vulnerability Management)

175 500 - 263 300$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Research Engineer (Vulnerability Management): Leading vulnerability research, threat exposure management, and continuous threat exposure management initiatives across network, cloud, endpoint, application, and container environments with an accent on risk-based prioritization, security validation, and remediation support. Focus on developing proofs of concept, improving analytics and AI-enabled workflows, and translating security findings into measurable cross-functional outcomes.

Location: United States, Remote. The role may require some travel.

Base pay: $175,500–$263,300 USD annually for the Seattle example; pay varies by geographic location and hybrid policy.

Company

hirify.global is the entertainment and technology brand of Sony Interactive Entertainment, delivering hardware, network services, and interactive entertainment experiences.

What you will do

  • Lead complex Global Vulnerability Management workstreams supporting Threat Exposure Management and the transition to a Continuous Threat Exposure Management operating model.
  • Translate annual goals into delivery plans, milestones, success measures, dependencies, and repeatable operating practices.
  • Conduct hands-on vulnerability research, technical analysis, security validation, exploitability assessment, and proof-of-concept development.
  • Improve vulnerability discovery and assessment across networks, cloud, endpoints, applications, containers, databases, and hybrid infrastructure.
  • Develop risk-based prioritization using threat intelligence, exploitation evidence, asset context, business impact, and control effectiveness.
  • Partner with security and technology teams to mobilize remediation, communicate material risks, improve platforms and automation, and mentor engineers.

Requirements

  • 8+ years of relevant experience in information security, information technology, systems engineering, vulnerability management, security research, or exposure management.
  • Bachelor’s degree or equivalent in computer science, information security, or a related field.
  • Experience leading complex technical workstreams across multiple teams without direct reporting authority.
  • Hands-on experience with vulnerability research, security validation, risk-based prioritization, remediation guidance, and exposure-management platforms.
  • Knowledge of adversarial tactics, exploitation techniques, threat intelligence, and MITRE ATT&CK.
  • Experience with scripting, programming, APIs, automation, security data analysis, software engineering practices, and communicating technical risk to leadership.

Nice to have

  • Experience evolving vulnerability management toward TEM or CTEM.
  • Experience with continuous security validation, adversarial exposure validation, exploit research, or proof-of-concept development.
  • Experience securing cloud, container, application, or build-pipeline environments.
  • Experience with Snowflake, Domo, or comparable security-data and analytics platforms.
  • Experience applying automation, advanced analytics, or AI-enabled capabilities to security workflows.

Culture & Benefits

  • Remote flexibility with pay ranges that vary by geographic location and working policy.
  • Medical, dental, and vision coverage.
  • Matching 401(k), paid time off, and wellness program.
  • Employee discounts on Sony products and potential eligibility for a bonus package.

Hiring process

  • Background checks are conducted at the offer stage and may include criminal background checks for some roles.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →