Senior Security Engineer I, Vulnerability Management

Weights & Biases Weights & Biases · Data AI · Bellevue, WA +4 · Technology

This role is for a Senior Security Engineer focused on Vulnerability Management within a cloud infrastructure company. The primary responsibilities include hands-on vulnerability triage, risk assessment, tracking remediation, improving automation for triage and remediation, and supporting incident investigations. The role requires experience with vulnerability management platforms, scripting for automation, and cloud security concepts. While the company is in the AI space, this specific role is focused on security operations and does not involve building or researching AI/ML models.

What you'd actually do

  1. Perform hands-on vulnerability triage and risk assessment using team-defined standards and playbooks
  2. Track remediation progress with owner teams, escalate blockers, and ensure clean issue closure
  3. Support automated triage workflows by validating outputs and improving signal quality
  4. Contribute to automated remediation campaigns (for example EOL cleanup, vulnerable software upgrades, and fix verification)
  5. Support zero-day and embargo response by helping inventory affected assets and tracking owner-team deployment status

Skills

Required

  • vulnerability management
  • security operations
  • application security
  • vulnerability assessment fundamentals (CVSS, exploitability, risk prioritization, remediation tradeoffs)
  • vulnerability management platforms (Wiz, Rapid7, Qualys, Tenable, or equivalent)
  • scripting/automation (Python, Bash, or similar)
  • cloud security concepts (AWS, GCP, Azure)
  • infrastructure vulnerabilities
  • written and verbal communication
  • execution ownership in operational security work

Nice to have

  • security automation/SOAR platforms (Tines, Splunk SOAR, or equivalent)
  • container/Kubernetes vulnerability workflows
  • hardware-adjacent vulnerability domains (GPU/DPU firmware, BMC/IPMI)
  • compliance evidence collection (SOC 2, ISO 27001, FedRAMP, or similar)
  • high-growth or fast-moving infrastructure environments
  • AI-assisted security workflows and human-in-the-loop validation

What the JD emphasized

  • execution-focused role
  • hands-on triage
  • drive remediation follow-through
  • improve day-to-day operational quality
  • meaningful ownership
  • fast learning
  • clear growth path toward senior scope
  • hands-on vulnerability triage
  • risk assessment
  • Track remediation progress
  • escalate blockers
  • ensure clean issue closure
  • automated triage workflows
  • validating outputs
  • improving signal quality
  • automated remediation campaigns
  • zero-day and embargo response
  • inventory affected assets
  • tracking owner-team deployment status
  • incident investigations
  • gathering technical evidence
  • supporting impact analysis
  • on-call rotation
  • critical vulnerability events
  • high-quality documentation
  • runbooks
  • operational updates
  • Identify process gaps
  • practical workflow improvements
  • reduce manual toil
  • 3+ years of relevant experience in vulnerability management, security operations, application security, or related security engineering
  • Strong understanding of vulnerability assessment fundamentals (CVSS, exploitability, risk prioritization, remediation tradeoffs)
  • Hands-on experience with one or more vulnerability management platforms (for example Wiz, Rapid7, Qualys, Tenable, or equivalent)
  • Proficiency in scripting/automation for workflow support (Python, Bash, or similar)
  • Familiarity with cloud security concepts (AWS, GCP, Azure) and common infrastructure vulnerabilities
  • Strong written and verbal communication skills for cross-functional collaboration
  • Demonstrated execution ownership in operational security work
  • security automation/SOAR platforms
  • container/Kubernetes vulnerability workflows
  • hardware-adjacent vulnerability domains (GPU/DPU firmware, BMC/IPMI)
  • compliance evidence collection (SOC 2, ISO 27001, FedRAMP, or similar)
  • high-growth or fast-moving infrastructure environments
  • AI-assisted security workflows and human-in-the-loop validation
  • Solve practical problems
  • improve operational reliability
  • Use automation to reduce repetitive manual work
  • Partner across teams to drive concrete security outcomes
  • How AI and automation can improve vulnerability operations
  • Security challenges in cloud-scale and specialized infrastructure
  • Building strong security judgment through real production problems
  • Risk-based vulnerability prioritization
  • Security operations execution and process quality
  • Automation-assisted vulnerability workflows