Назад
Company hidden
обновлено 11 дней назад

Senior Security Research Engineer

175 500 - 263 300$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Research Engineer (Threat Exposure Management): Advancing vulnerability management and Continuous Threat Exposure Management across network, cloud, endpoint, application, container, and hybrid environments with an accent on vulnerability research, security validation, risk-based prioritization, and remediation mobilization. Focus on developing proofs of concept, integrating automation and AI-enabled workflows, and translating security findings into measurable remediation outcomes across multiple teams.

Location: Flexible remote role with pay ranges varying by geographic location; Seattle is provided as an example location.

Salary: $175,500–$263,300 USD annually, with geographic variation. The role may also be eligible for a bonus package.

Company

hirify.global develops PlayStation hardware, network services, and entertainment experiences for more than 100 million people.

What you will do

  • Lead complex vulnerability management workstreams supporting the transition to a Threat Exposure Management and Continuous Threat Exposure Management operating model.
  • Translate annual goals into delivery plans, milestones, success measures, dependencies, and repeatable operating practices.
  • Conduct hands-on vulnerability research, technical analysis, security validation, exploitability assessment, and proof-of-concept development.
  • Improve vulnerability discovery and assessment across network, cloud, endpoint, application, container, database, and hybrid infrastructure environments.
  • Develop risk-based prioritization using threat intelligence, exploitation evidence, asset and business context, control effectiveness, and remediation considerations.
  • Partner with security and technology teams to mobilize remediation, improve platforms and integrations, communicate material risks, and mentor engineers.

Requirements

  • 8+ years of relevant information security, information technology, systems engineering, vulnerability management, security research, or exposure management experience.
  • Bachelor’s degree or equivalent in computer science, information security, or a related discipline.
  • Experience leading complex technical workstreams across multiple teams and delivering measurable outcomes without direct reporting authority.
  • Hands-on experience with vulnerability research, technical analysis, security validation, risk-based prioritization, and remediation or mitigation guidance.
  • Experience with vulnerability platforms, security data, scripting, programming, APIs, or automation; relevant technologies include Python, SQL, Bash, PowerShell, and JavaScript.
  • Knowledge of adversarial tactics, exploitation techniques, threat intelligence, MITRE ATT&CK, software engineering practices, and technical security communication.

Nice to have

  • Experience evolving vulnerability management toward TEM or CTEM operating models.
  • Experience with continuous security validation, adversarial exposure validation, exploit research, or proof-of-concept development.
  • Experience securing cloud, container, application, or build-pipeline environments.
  • Experience with Snowflake, Domo, comparable security-data platforms, advanced analytics, or AI-enabled security workflows.

Culture & Benefits

  • Medical, dental, and vision coverage.
  • Matching 401(k) and paid time off.
  • Wellness program and employee discounts on Sony products.
  • Flexible remote work policy with geographic pay variation.
  • Background checks are conducted at the offer stage.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →