Staff Vulnerability Management Engineer

United States Digital Space LLC

Seattle, San Francisco (WA, CA)

Hybrid

USD 180,000 - 240,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

United States Digital Space LLC is seeking a Staff Vulnerability Management Engineer to lead complex vulnerability initiatives across applications, cloud, and infrastructure. You will design scalable triage/automation, build risk-based prioritization models, and improve end-to-end vulnerability workflows with SBOM, SAST/SCA, and CI/CD integration.

The role requires hands-on engineering, mentorship, and collaboration with Engineering, Legal, and Compliance.

Qualifications

  • Bachelor’s degree or equivalent practical experience.
  • Deep expertise in vulnerability management and modern infrastructure.
  • Strong programming/scripting in Python, Go, Java or similar.
  • Knowledge of CVSS, EPSS, KEV and risk-based prioritization.

Responsibilities

  • Lead high‑complexity vulnerability management initiatives across program areas.
  • Design scalable triage and prioritization automation with integrations.
  • Develop risk-based prioritization models using CVSS, EPSS, KEV, threat intel.
  • Engineer workflows across cloud, containers, SCA, SBOMs, and software supply chain.
  • Own or advance SBOM inventory and CI/CD integration of scans.
  • Provide executive‑level risk insights and dashboards.
  • Lead root‑cause analysis for high‑impact incidents and improve tooling.
  • Mentor engineers and drive secure development practices.

Skills

Vulnerability management
Python
Go
JavaScript/TypeScript
Cloud & distributed systems
Security engineering
SRE collaboration
Cross-functional leadership

Education

Bachelor’s degree in CS, Cybersecurity, Engineering, or related field

Tools

Wiz
Semgrep
Snyk
Socket
Rapid7
Tenable
Checkmarx

Job description

Employee Applicant Privacy NoticeWho we are:

Shape a brighter financial future with us.

Together with our members, we’re changing the way people think about and interact with personal finance.

We’re a next‑generation financial services company and national bank using innovative, mobile‑first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world.The role

We are seeking a Staff Vulnerability Management Engineer to lead the most complex technical work in the company’s Vulnerability Management program. You will design and build scalable systems that identify, enrich, prioritize, route, and track vulnerabilities across applications, cloud and infrastructure, containers, software supply chains, and specialized hardware or firmware surfaces. This is a hands‑on engineering role with broad technical influence: you will write production code, make architecture decisions, establish vulnerability management standards, and improve how teams understand and reduce vulnerability risk.

You will partner with Engineering, Infrastructure, SRE, Compliance, Legal, and business stakeholders to accelerate remediation while protecting engineering velocity and customer trust. You will also serve as a senior technical responder for embargoed disclosures and zero‑day events, lead root‑cause analysis for high‑impact vulnerability incidents, and mentor engineers. The ideal candidate combines deep vulnerability management expertise with strong software engineering judgment, systems thinking, and a bias for durable, measurable outcomes.

What you’ll do
  • Lead high‑complexity vulnerability management initiatives and make architecture decisions for assigned program areas, from detection and assessment through ticket routing, remediation, exception handling, and closure validation.
  • Design, build, and productionize scalable triage and prioritization automation, including scanner and asset integrations, enrichment pipelines, decision logic, deduplication, ownership resolution, service‑level tracking, observability, and failure recovery.
  • Develop risk‑based prioritization models that combine CVSS, EPSS, CISA Known Exploited Vulnerabilities, threat intelligence, asset criticality, exposure, compensating controls, business context, and compliance obligations.
  • Engineer and improve vulnerability workflows across application security, cloud and infrastructure, containers and Kubernetes, open‑source dependencies, secrets, software supply chain, and hardware‑adjacent surfaces such as GPU, DPU/BlueField, BMC, and firmware.
  • Own or materially advance software supply chain capabilities, including SBOM inventory, dependency visibility, SLSA‑aligned controls, and integration of SAST, SCA, secret scanning, and container scanning into CI/CD.
  • Act as a senior technical responder for critical vulnerabilities, embargoed disclosures, and zero‑day events; coordinate technical assessment, containment, mitigation, patch deployment, validation, and executive communication with service owners and incident response teams.
  • Partner directly with development and platform teams to define practical remediation paths and, when appropriate, review or contribute secure changes in Python, Go, JavaScript/TypeScript, or infrastructure code.
  • Define technical standards for vulnerability severity, remediation service levels, exceptions, evidence, and closure criteria; ensure workflows support audit‑ready reporting for applicable regulatory and compliance frameworks.
  • Produce actionable metrics, dashboards, and risk insights for technical and executive audiences, with clear accountability, trend analysis, compliance posture, and execution risks.
  • Lead root‑cause analysis for high‑impact vulnerability incidents and convert lessons learned into durable improvements to tooling, architecture, controls, and operating practices.
  • Evaluate and responsibly apply AI/ML and LLM‑assisted techniques to security triage and decision support, with human‑in‑the‑loop validation, measurable quality controls, and safe failure modes.
  • Build AI‑assisted remediation workflows that partner with engineering teams to proactively identify, validate, and apply security patches, with appropriate testing, human oversight, rollback mechanisms, and measurable risk reduction.
  • Communicate complex security tradeoffs and program risks clearly to stakeholders across Engineering, Product, Operations, Legal, Compliance, and executive leadership.
What you’ll need
  • Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or a related field, or equivalent practical experience.
  • Deep expertise in vulnerability management, security engineering, and modern infrastructure, including cloud, containers, and distributed systems.
  • Strong programming or scripting skills in Python, Go, Java, or similar languages, with experience building automation at scale.
  • Deep knowledge of vulnerability management methods and standards, including CVSS, EPSS, CISA KEV, threat intelligence integration, asset and exposure context, remediation SLAs, exception governance, and risk‑based prioritization.
  • Hands‑on experience with modern vulnerability and application security tooling such as Wiz, Semgrep, Snyk, Socket, Rapid7, Tenable, Checkmarx, or equivalent platforms, plus experience tuning SAST, SCA, secret scanning, container, or cloud findings.
  • Experience designing end‑to‑end workflows that integrate scanners, asset inventories or CMDBs, ticketing systems, CI/CD platforms, data stores, dashboards, and alerting systems.
  • Working knowledge of cloud‑native and software supply chain environments, including AWS, GCP, or Azure; Kubernetes and containers; build systems and package managers; SBOMs; and Infrastructure as Code.
  • Demonstrated ability to lead cross‑functional technical initiatives, influence without direct authority, make sound decisions amid ambiguity, and drive work from concept through production operation and measurable outcomes.
  • Experience mentoring senior and developing engineers and raising engineering quality through design reviews, code reviews, standards, and incident leadership.
  • Strong written and verbal communication, business judgment, and the ability to explain how security choices affect engineering velocity, regulatory obligations, customer trust, and business risk.
Nice to have
  • Experience managing security partnerships with hardware or software vendors, including embargoed disclosures, coordinated vulnerability disclosure, and pre‑release remediation collaboration.
  • Production experience with security orchestration platforms such as Tines and serverless frameworks such as AWS Lambda or Google Cloud Functions.
  • Experience scaling vulnerability management in a high‑growth, cloud‑native environment or operating within FedRAMP, PCI SS, SOC 2, ISO 27001, NIST, or comparable regulated environments.
Compensation and Benefits

The base pay range for this role is listed below. Final base pay offer will be determined based on individual factors such as th

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer - Vulnerability Management
Cybersecurity Engineer - Vulnerability Management

Janestreet • New York (NY)

On-site
USD 100,000 - 130,000
Lead Vulnerability Management Engineer
Lead Vulnerability Management Engineer

United States Digital Space LLC • United States

Hybrid
USD 180,000 - 240,000
Equity eligible
Comprehensive benefits package
401(k) plan
Manager, Vulnerability Management
Manager, Vulnerability Management

Vanguard • Malvern

On-site
USD 170,000 - 230,000
Corporate Vice President - Head of Enterprise Vulnerability Management
Corporate Vice President - Head of Enterprise Vulnerability Management

New York Life • New York (NY)

On-site
USD 147,000 - 211,000
Senior Security Manager - Vulnerability Management
Senior Security Manager - Vulnerability Management

Alter Domus • Chicago (IL)

On-site
USD 140,000 - 190,000
Manager, Vulnerability Management
Manager, Vulnerability Management

Optimum • Norwalk (CT)

On-site
USD 133,000 - 220,000
Vulnerability Automation Engineer
Vulnerability Automation Engineer

Lumindigital • United States

On-site
USD 140,000 - 190,000
Medical insurance
Dental insurance
Vision insurance
+7
Sr Security Architect Vulnerability Management
Sr Security Architect Vulnerability Management

Francisco Partners • United States

On-site
USD 140,000 - 190,000
Senior Vulnerability Analyst
Senior Vulnerability Analyst

PRI Global • O’Fallon (MO)

On-site
USD 110,000 - 160,000
Security Controls Engineer
Security Controls Engineer

AVG • Tempe (AZ)

On-site
USD 110,000 - 160,000