Summary
✨ AI‑Generated
Work as an experienced security engineer supporting a high-scale engineering organization. You will map trust boundaries and attack surfaces, triage vulnerabilities, reproduce security issues, validate remediation code, and strengthen secure architectural practices through hands-on technical analysis.
Highlights
Deep involvement in vulnerability research and validation, security architecture, threat modeling, and automated remediation, with substantial technical ownership.
Description
Role: Security Engineer III
Location: San Jose, CA (5 days a week)
Job Summary: We are looking for an experienced Security Engineer to support the Search Engineering team by managing vulnerability lifecycles, validating security issues and automated fixes, and promoting secure architectural practices.
Responsibilities
Document trust boundaries, data flows, attack surfaces, and architectural entry points for high-priority services.
Maintain threat profiles in centralized security repositories.
Review and triage security scanner findings, classify severity, and evaluate exception requests against security policies.
Build minimal test environments and harnesses to reproduce vulnerabilities and validate Proofs of Concept (PoCs).
Distinguish valid vulnerabilities from false positives through technical validation.
Review and validate code patches generated by automated remediation agents.
Execute tests and inspect code changes for regressions and security issues.
Coordinate with product teams and code owners to move validated fixes through code review and production deployment.
Support vulnerability closure and security remediation activities.
Required Skills & Qualifications
8+ years of relevant cybersecurity/application security experience.
Strong understanding of architectural trust boundaries, attack surfaces, data flows, and threat modeling.
Experience with threat modeling frameworks such as STRIDE and PASTA.
Working knowledge of CWE, CVE, OWASP Top 10, vulnerability severity, and SLA mapping.
Proficiency in reading and writing code in at least two of the following: C++, Go, Java, Python.
Experience building security test harnesses and Proofs of Concept (PoCs).
Strong code review skills, including identifying regressions and issues in automated or AI-generated code.
Knowledge of secure coding standards and vulnerability remediation practices.
Preferred Skills
Threat modeling experience for large distributed or microservice architectures.
Experience managing vulnerability queues, automated scanning tools, and compliance exceptions.
Experience with fuzzing, unit testing frameworks, sandbox execution, and cross-boundary debugging.
Experience with prompt tuning for automated code-generation tools, differential testing, and automated patch validation.