Title: Product Security Engineer - Vulnerability Management
About the Role:
As a Product Security Engineer focused on vulnerability management, you will play a critical role in strengthening the security posture of our software systems by owning the end‑to‑end vulnerability lifecycle, from identification and assessment through remediation and reporting. This role is well suited for a hands‑on security professional with strong experience in vulnerability tracking, risk‑based prioritization, and cross‑functional execution in fast‑paced environments.
Your primary focus will be managing the intake and triage of vulnerabilities across internal and third‑party software components. You will work closely with engineering teams to assess severity, impact, and exposure, prioritize remediation efforts based on risk, and drive timely resolution in alignment with organizational security policies, SLAs, and compliance requirements. You will also engage in the design, development, and maintenance of infrastructure and systems for scaling up such activities.
You will work extensively with the vulnerability management infrastructure, including scanning tools, ticketing systems, and reporting dashboards that provide visibility into remediation progress and risk trends. This includes leveraging commercial platforms and custom‑built tooling to automate vulnerability tracking, analysis, and reporting, with a strong emphasis on scaling these workflows through automation and AI‑assisted capabilities.
You will enable rapid and effective remediation by working directly with developers to recommend practical fixes, mitigations, and secure implementation patterns that can be readily adopted across teams.
A core responsibility of the role is ensuring that vulnerability assessment and remediation prioritization are driven by real‑world risk. You will perform applicability and exploitability analysis to determine true product impact and ensure informed, risk‑based decision‑making rather than reliance on severity scores alone.
You will collaborate closely with development, infrastructure, and incident response teams to ensure vulnerabilities are not only resolved but also prevented through improved processes, secure coding practices, and architectural guidance. You will also monitor external threat intelligence sources, including CVE disclosures, vendor advisories, and zero‑day reports, to identify relevant exposures and coordinate appropriate response actions.
This is a hands‑on, operationally focused role that combines deep technical expertise with strong execution and collaboration. You will play a key role in driving consistent, scalable, and accountable vulnerability remediation practices across the organization.
Required Qualifications