Назад
Company hidden
2 дня назад

Senior Product Security Engineer (Cybersecurity)

225 000 - 300 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Product Security Engineer (Wiz/Tenable/AWS): Operating and evolving vulnerability management across cloud, infrastructure, endpoints, and applications with an accent on risk scoring, finding normalization, ownership mapping, and remediation coordination. Focus on reducing High/Critical vulnerabilities, automating triage and reporting workflows, and maintaining reliable security posture data for engineering, security, and compliance stakeholders.

Location: New York, New York, United States; onsite

Salary: $225,000–$300,000 per year, including base salary and new-hire equity in Restricted Stock Units.

Company

hirify.global provides a secure identity platform designed to make physical and digital experiences safer and easier.

What you will do

  • Operate and evolve the vulnerability management program across cloud, infrastructure, endpoints, and applications.
  • Monitor and triage findings from Wiz, Tenable, GHAS, and other security scanners.
  • Normalize, deduplicate, and map findings to assets, teams, services, and owners in the centralized vulnerability management platform.
  • Manage risk scoring, severity models, SLAs, backlog trends, and reporting for high-risk assets and teams.
  • Partner with engineering teams to clarify findings, define remediation plans, ship fixes, and validate closure in source tools.
  • Improve connectors, data-quality checks, scorecards, runbooks, and repeatable vulnerability management workflows.

Requirements

  • 6+ years of experience in security engineering or product security, ideally in a cloud-first or SaaS environment.
  • Hands-on experience with a vulnerability or exposure management platform such as Wiz, Tenable, Rapid7, GHAS, or a similar tool.
  • Understanding of end-to-end vulnerability management workflows, including scanning, triage, risk scoring, ticketing, validation, and reporting.
  • Working knowledge of modern cloud and infrastructure patterns, including AWS, services, hosts, containers, and repositories.
  • Strong written and verbal communication skills for explaining vulnerabilities, risk trade-offs, and SLAs to technical and non-technical stakeholders.
  • Experience supporting regulated environments such as FedRAMP, PCI, or SOC 2 and preparing vulnerability evidence for audits.

Culture & Benefits

  • Bright offices with open-plan workspaces, conference rooms, and casual co-working areas.
  • Catered lunches and stocked kitchens.
  • Learning and development stipends and reimbursement programs.
  • Comprehensive healthcare, family-building benefits, flexible time off, and an annual wellness stipend.
  • OneMedical memberships, hirify.global Plus membership, and a 401(k) retirement plan with employer match.
  • Additional refresh equity grants may be available under the ongoing compensation program.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →