Security Engineer - Vulnerability Management New Bengaluru, India

Endor Labs

Bengaluru

On-site

INR 2,400,000 - 4,200,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Endor Labs is seeking a Security Engineer - Vulnerability Management in Bengaluru to advance our vulnerability database and AI pipelines for automated validation, reachability analysis, and exploit generation.

You will triage, enrich, and prioritize vulnerabilities at scale, work with standards like CVE/CVSS, and cooperate with 0-day researchers to build production-grade systems and publish technical write-ups and advisories.

Qualifications

  • 3+ years in vulnerability research, vulnerability management, product security, or application security.
  • Extensive knowledge of CVE, CWE, CVSS, EPSS and SBOM formats.
  • Hands-on experience building production-grade security tooling at enterprise scale.
  • Ability to communicate security findings to technical and non-technical audiences.
  • Experience with AI/agentic systems, LLM pipelines, and automated vulnerability discovery is a plus.

Responsibilities

  • Advance Endor Labs' vulnerability database and AI pipelines for automated validation and analysis.
  • Triage, enrich, and prioritize vulnerabilities at scale with standard sources like CVE, CVSS, NVD.
  • Collaborate with 0-day researchers to scale automated vulnerability discovery into production-grade systems.
  • Investigate high-impact vulnerabilities and author external-facing content (blogs, advisories) for public audiences.
  • Feed findings into detection pipelines and improve automated coverage over time.

Skills

Vulnerability research
Vulnerability management
Product security
Application security
AI/LLM pipelines

Education

Bachelor's degree in engineering or related field

Tools

CI/CD automation
SAST/SCA tooling
Vulnerability data standards

Job description

Security Engineer - Vulnerability Management
Who we are

Our mission is to help developers and AppSec teams spend more time accelerating development and less time dealing with security issues. Watch our 3 min pitch from our Founder & CEO here:https://www.youtube.com/watch?v=B0wmZBcPkFE

Endor Labs has been recognized as a Gartner Cool Vendor, a RSA Innovation Sandbox finalist, and a Black Hat Innovation Spotlight finalist, all in its first year from launch.

The company was founded byVarun Badhwar andDimitri Stiliadis , who have created multiple category-defining cloud security companies. We have raised $70M in Series A funding and assembled a team of the world’s leading static analysis experts and enterprise software veterans to increase developer productivity and open source software adoption.

What you’ll do
  • The primary focus of this position is to help the team further advance Endor Labs'proprietary vulnerability database — extending and improving our existing AI pipelines,
    e.g., in the areas of automated vulnerability validation, reachability analysis, and exploitgeneration.
  • Day-to-day work includes monitoring and managing pipelines that triage, enrich, andprioritize vulnerabilities at scale, working with the standards and data sources the
    ecosystem is built on (CVE, CWE, CVSS, EPSS, PURL, NVD, OSV, GHSA, VEX) andcontinuously improving the accuracy, coverage, and timeliness of our data.
  • You will work hand-in-hand with our world-class 0-day researchers to scale automatedvulnerability discovery — turning manual research workflows into repeatable,
    production-grade systems.
  • You will investigate high-impact vulnerabilities and the vulnerability landscape at large,and author external-facing content — blog posts, technical write-ups, and advisories —
    communicating findings clearly to both technical and non-technical audiences.
  • You will collaborate with internal teams to feed findings into detection and analysispipelines, enrich our vulnerability database, and help improve automated coverage over
    time
What we're looking for
  • Bachelor's degree in engineering or a related field, with at least 3 years of hands-onprofessional experience in vulnerability research, vulnerability management, product security, or application security
  • Extensive knowledge of software vulnerabilities, triage, and prioritization, including deepfamiliarity with the associated standards and technologies (CVE, CWE, CVSS, EPSS, PURLs, NVD, OSV, VEX, SBOM formats)
  • Hands-on experience building production-grade solutions at enterprise scale — e.g.,CI/CD automation, management of SAST/SCA findings, or comparable security tooling deployed across large engineering organizations
  • Demonstrated experience shipping AI/agentic systems to production — LLM pipelines,agent frameworks, tool use, prompt and eval design — with a clear track record of measuring output quality and a sound sense of where these approaches hold up andwhere they don't
  • Experience producing external security communications: blog posts, advisories, ortechnical reports intended for a public or customer-facing audience
Nice to have
  • Experience writing proof-of-concept exploits, or with fuzzing, static analysis, orautomated vulnerability discovery
  • Contributions to open source vulnerability databases, scanners, or related tooling (OSV,osv-scanner, OpenVEX, etc.)
  • Familiarity with SAST, SCA, and DAST tooling and the realities of triaging their output atscale
  • Understanding of software supply chain security standards and frameworks (SLSA,SSDF, etc.)
  • Prior public research, CVE credits, or published vulnerability findings
  • Security certifications such as OSCP, OSCE, or equivalent
  • Strive for excellence in everything we do, prioritizing quality, speed, and impactful outcomes.
  • Engage in first principles thinking to debate ideas, test assumptions, and make decisions.
  • Put data above opinions, seeking truth and clarity in all our endeavors.
  • Embrace a culture of feedback and continuous improvement, assuming good intent in all interactions.
  • Celebrate wins as a team, understanding that our collective success is intertwined with the success of our customers.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer - Vulnerability
Security Engineer - Vulnerability

Sierra Ventures • Bengaluru

On-site
INR 400,000 - 700,000
Senior Product Security Engineer New Bengaluru, India
Senior Product Security Engineer New Bengaluru, India

Endor Labs • Bengaluru

On-site
INR 1,500,000 - 2,800,000
Technical Success Architect
Technical Success Architect

Endor Labs • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Technical Success Architect
Technical Success Architect

Sierra Ventures • Bengaluru

On-site
INR 400,000 - 700,000
Senior Quality Engineer(SDET)
Senior Quality Engineer(SDET)

Sierra Ventures • Bengaluru

On-site
INR 1,800,000 - 3,400,000
Senior Quality Engineer(SDET)
Senior Quality Engineer(SDET)

Endor Labs • Bengaluru

On-site
INR 2,500,000 - 4,000,000
IT and Security Administrator New Bengaluru, India
IT and Security Administrator New Bengaluru, India

Endor Labs • India

On-site
INR 1,200,000 - 1,800,000
Staff Backend Engineer (Golang) Bengaluru, India
Staff Backend Engineer (Golang) Bengaluru, India

Endor Labs • Bengaluru

On-site
INR 4,000,000 - 6,000,000
Senior Backend Engineer (Golang)
Senior Backend Engineer (Golang)

Endor Labs • Bengaluru

On-site
INR 3,000,000 - 5,500,000
IT Engineer
IT Engineer

Sierra Ventures • Bengaluru

On-site
INR 800,000 - 1,200,000