Reporting to the Director of Global Vulnerability Management, you will serve as a Senior Security Research Engineer and technical lead within SIE’s Global Vulnerability Management team
You will lead complex work that advances our Threat Exposure Management capability and supports our transition to a Continuous Threat Exposure Management operating model, while remaining directly engaged in vulnerability research, analysis, security validation, prioritization, and remediation support
You will partner across Information Security, engineering, technology, and business teams to improve how SIE discovers, prioritizes, validates, and mobilizes action on security risks. You will translate annual TEM goals into defined workstreams, delivery plans, success measures, and repeatable operating practices that improve visibility, decision-making, remediation outcomes, and program scale
Lead complex Global Vulnerability Management workstreams that advance SIE’s Threat Exposure Management capability and transition toward a Continuous Threat Exposure Management operating model across discovery, prioritization, validation, and mobilization
Translate annual TEM goals into defined delivery plans, milestones, success measures, dependencies, and repeatable operating practices. Monitor progress, identify barriers, and adjust execution to improve outcomes
Lead hands-on vulnerability research and technical analysis to confirm security conditions, eliminate false positives, characterize exploitability and business impact, and provide actionable remediation or mitigation guidance
Improve the discovery and assessment of vulnerabilities across SIE network, cloud, endpoint, application, container, and other technology environments
Develop risk-based prioritization using vulnerability and threat intelligence, exploitation evidence, asset and business context, control effectiveness, and remediation considerations
Lead security validation activities and develop proofs of concept when appropriate to distinguish material risk, evaluate defensive controls, and support informed decisions
Partner with Information Security teams and technology owners to mobilize remediation, clarify ownership, establish effective handoffs, resolve barriers, and measure progress through remediation, mitigation, or accepted disposition
Evolve GVM platforms, integrations, data, analytics, automation, and AI-enabled workflows to improve coverage, data quality, consistency, decision speed, and operational scale
Communicate vulnerability trends, material risks, remediation progress, and program outcomes to technical, operational, and leadership audiences through clear reports and recommendations
Mentor engineers and partner teams, contribute to technical standards and procedures, and improve the quality of vulnerability analysis, validation, documentation, and delivery
Maintain current knowledge of relevant vulnerabilities, exploitation techniques, threat activity, security technologies, and industry practices
Some travel may be required
Experience using scripting, programming, APIs, or automation to improve security analysis and operational workflows. Relevant technologies may include Python, SQL, Bash, PowerShell, JavaScript, or comparable languages
Knowledge of adversarial tactics, exploitation techniques, threat intelligence, and attack frameworks such as MITRE ATT&CK, with the ability to apply that information to vulnerability prioritization
8+ years of relevant experience in information security, information technology, systems engineering, or a related field, including substantial experience in vulnerability management, security research, or exposure management
Experience mentoring engineers or analysts and influencing technical practices across teams
Experience leading complex technical workstreams across multiple teams, translating objectives into delivery plans, and achieving measurable outcomes without relying on direct reporting authority
Experience with vulnerability discovery, assessment, validation, or exposure-management platforms and their supporting integrations
Hands-on experience with vulnerability research, technical analysis, security validation, risk-based prioritization, and remediation or mitigation guidance
Bachelor’s degree or equivalent in computer science, information security, or a related discipline
Experience assessing vulnerabilities across several technology domains, such as operating systems, networks, cloud services, applications, endpoints, containers, databases, or hybrid infrastructure
Ability to communicate complex security conditions, priorities, tradeoffs, and recommendations clearly to technical, operational, and leadership audiences
Experience analyzing and contextualizing security data to connect technical findings with asset, service, business, threat, control, and remediation information
Familiarity with software engineering practices such as version control, testing, code review, CI/CD, reusable components, and controlled production releases
Experience helping evolve a traditional vulnerability-management function toward a TEM or CTEM operating model
Experience with continuous security validation, adversarial exposure validation, exploit research, or proof-of-concept development
Experience securing cloud, container, application, or build-pipeline environments and integrating security capabilities into engineering workflows
Experience with security-data and analytics platforms such as Snowflake, Domo, or comparable technologies
Experience applying automation, advanced analytics, or AI-enabled capabilities to vulnerability analysis, prioritization, validation, or remediation workflows