Назад
Company hidden
1 день назад

Staff Vulnerability Management Engineer (Cybersecurity)

Формат работы
remote (только Canada)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK/US/Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Vulnerability Management Engineer (Cybersecurity): Managing and scaling a pipeline of thousands of novel open source vulnerabilities identified weekly by frontier models and other sources with an accent on responsible disclosure, CVE assignment, and coordinated embargoes. Focus on automating vulnerability measurement and reporting, coordinating with maintainers and standards bodies, and guiding the evolution of AI-driven software supply chain security.

Location: Remote in Canada

Company

hirify.global delivers hardened, secure, and production-ready builds of open source software for organizations and AI agents.

What you will do

  • Own measurement, disclosure, and reporting for a pipeline of thousands of novel vulnerabilities identified weekly by frontier models and other sources.
  • Calibrate vulnerability response processes as emerging trends develop and report newly discovered vulnerabilities to upstream projects and maintainers.
  • Run the CNA program and assign CVEs where necessary.
  • Coordinate internal and external embargoes with customers, engineering teams, and external maintainers.
  • Work with the Linux Foundation, CISA, industry bodies, standards groups, and AI model vendors.
  • Represent hirify.global externally and help shape industry standards for software supply chain security.

Requirements

  • 7+ years of experience in software security, open source maintenance, or vulnerability disclosure management.
  • Strong understanding of responsible disclosure.
  • Practical expertise automating pipelines and processes at large scale while reducing human involvement.
  • Deep experience with open source communities.
  • Experience coordinating with public-sector organizations, industry standards bodies, and working groups.
  • Ability to provide technical leadership and influence across teams as an individual contributor.

Nice to have

  • Industry thought leadership in vulnerability disclosure management and embargoes.
  • Familiarity with hirify.global Images or other minimal, hardened container base image ecosystems.
  • Experience operating a CNA.
  • Software engineering experience with Python, Java, JavaScript, Go, or similar languages.
  • Background in security research, penetration testing, or bug bounty programs.

Culture & Benefits

  • Remote-first culture with team meetups, bi-annual destination summits, and a monthly coworking, phone, and internet stipend.
  • Stock options upon hire and promotion, participation in secondary offerings, and a 10-year exercise period.
  • 100% company-paid health, vision, and dental insurance for employees and dependents.
  • Flexible time off.
  • Paid parental leave of 18 weeks for birthing parents and 12 weeks for non-birthing parents.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →