Security Engineer - Vulnerability Triage & Automated Remediation
Global Bridge Infotech Inc โ United States ยท Posted ~2 hours ago
๐ Log in to save this job, tailor your resume & track your apply process โ 7 days free, no card needed.
Log in to add to target listDescription
Title: Security Engineer - Vulnerability Triage & Automated Remediation
Location: Remote /Preferred (New York)
POSITION OVERVIEW
The Security Engineer will join an operational security pod acting as the crucial bridge between automated security scanning/remediation systems and product code owners.
The mission of this role is to streamline threat modeling, eliminate triage noise, validate exploitability through reproduction, verify automated/agentic patches, and shepherd open security issues through to verified production resolution.DAY-TO-DAY RESPONSIBILITIES
Document trust boundaries, data flows, and architectural entry points to maintain up-to-date threat profiles for high-priority services.Filter and triage findings from automated source and endpoint scanners, classifying severity and evaluating exception requests.Construct minimal test environments and reproduction harnesses to validate exploitability and eliminate false positives.Supervise and QA code patches generated by automated/agentic remediation tools, running unit and integration tests to check for regressions.Route validated patches to product team code owners and coordinate end-to-end deployment verification within strict SLAs.Conduct code reviews and ensure all fixes comply with secure coding standards (e.g., input validation, memory safety).REQUIRED SKILLS
Software Engineering & Code Reading (3+ yrs): Proficiency in reading and writing code in at least two core languages (C++, Go, Java, Python) with local harness/PoC setup experience.Vulnerability Triage & Classifications (3+ yrs): Practical experience with CWE, CVE, OWASP Top 10, scanner findings evaluation, and queue hygiene.Secure Code Review & QA (3+ yrs): Hands-on expertise evaluating code diffs, input validation, boundary checking, and verifying automated patch efficacy.ADDITIONAL DESIRED SKILLS
Experience with structured threat modeling frameworks (e.g., STRIDE, PASTA) for microservices.Practical knowledge of fuzz testing, sandbox execution, and differential testing frameworks.Experience debugging or prompt-tuning automated/agentic code generation tools.Familiarity with dynamic (DAST) and static (SAST) scanning platforms.CANDIDATE PROFILE
An operational, hands-on Security Engineer with a strong software development background who excels at bridge-building between security automation and product development teams.
The candidate should be highly methodical, possessing strong code analysis skills to spot hallucinated or regression-prone automated fixes and validate real-world exploitability.
We have 141,285 jobs that might be an even better fit for you
DontApply's real value goes far beyond a single job link or company name. Just upload your resume โ in under a minute we'll analyze all 141,285 jobs and tell you exactly which ones you should apply to right now.
Upload My Resume