1 день назад
Staff Vulnerability Management Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Staff Vulnerability Management Engineer (Cybersecurity): Managing and scaling a pipeline of thousands of novel open source vulnerabilities identified weekly by frontier models and other sources with an accent on responsible disclosure, CVE assignment, and coordinated embargoes. Focus on automating vulnerability measurement and reporting, coordinating with maintainers and standards bodies, and guiding the evolution of AI-driven software supply chain security.
Location: Remote in Canada
Company
delivers hardened, secure, and production-ready builds of open source software for organizations and AI agents.
What you will do
- Own measurement, disclosure, and reporting for a pipeline of thousands of novel vulnerabilities identified weekly by frontier models and other sources.
- Calibrate vulnerability response processes as emerging trends develop and report newly discovered vulnerabilities to upstream projects and maintainers.
- Run the CNA program and assign CVEs where necessary.
- Coordinate internal and external embargoes with customers, engineering teams, and external maintainers.
- Work with the Linux Foundation, CISA, industry bodies, standards groups, and AI model vendors.
- Represent externally and help shape industry standards for software supply chain security.
Requirements
- 7+ years of experience in software security, open source maintenance, or vulnerability disclosure management.
- Strong understanding of responsible disclosure.
- Practical expertise automating pipelines and processes at large scale while reducing human involvement.
- Deep experience with open source communities.
- Experience coordinating with public-sector organizations, industry standards bodies, and working groups.
- Ability to provide technical leadership and influence across teams as an individual contributor.
Nice to have
- Industry thought leadership in vulnerability disclosure management and embargoes.
- Familiarity with Images or other minimal, hardened container base image ecosystems.
- Experience operating a CNA.
- Software engineering experience with Python, Java, JavaScript, Go, or similar languages.
- Background in security research, penetration testing, or bug bounty programs.
Culture & Benefits
- Remote-first culture with team meetups, bi-annual destination summits, and a monthly coworking, phone, and internet stipend.
- Stock options upon hire and promotion, participation in secondary offerings, and a 10-year exercise period.
- 100% company-paid health, vision, and dental insurance for employees and dependents.
- Flexible time off.
- Paid parental leave of 18 weeks for birthing parents and 12 weeks for non-birthing parents.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
Cyber Security Engineer (Vulnerability Management)
4 дня назад
Senior Security Engineer (AI)
150 000 - 190 000CAD
4 дня назад
Senior Security Engineer (Cybersecurity)
175 000 - 217 000$
2 дня назад
Staff Security Engineer (Web3)
180 000 - 264 000$
4 дня назад
Senior Security Operations Engineer (Cybersecurity)
2 дня назад