{"version":"0.1","company":{"name":"YubHub","url":"https://yubhub.co","jobsUrl":"https://yubhub.co/jobs/skill/security-workflows"},"x-facet":{"type":"skill","slug":"security-workflows","display":"Security Workflows","count":6},"x-feed-size-limit":100,"x-feed-sort":"enriched_at desc","x-feed-notice":"This feed contains at most 100 jobs (the most recently enriched). For the full corpus, use the paginated /stats/by-facet endpoint or /search.","x-generator":"yubhub-xml-generator","x-rights":"Free to redistribute with attribution: \"Data by YubHub (https://yubhub.co)\"","x-schema":"Each entry in `jobs` follows https://schema.org/JobPosting. YubHub-native raw fields carry `x-` prefix.","jobs":[{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_4e6792dc-8f7"},"title":"Sr. Director, Infrastructure, SRE, & Security","description":"<p>We are seeking a Sr. Director, Infrastructure, SRE, &amp; Security to lead our Infrastructure, SRE &amp; Security team in building the cloud and data infrastructure that enables our AI platform.</p>\n<p>As a key member of our Engineering department, you will be responsible for owning the architecture, reliability, and cost efficiency of our cloud infrastructure, driving full IaC coverage and leading Kubernetes operations at scale.</p>\n<p>You will also own data infrastructure operations, cost governance, and security hardening, partnering with Data Product Engineering on modernizing data delivery infrastructure.</p>\n<p>In addition, you will lead security posture management across cloud, application, and identity layers, defining and instrumenting cost-per-unit metrics, implementing per-team budgets with automated alerting, and giving leadership direct visibility into infrastructure efficiency.</p>\n<p>You will operate internal developer platforms with self-service onboarding, CI/CD, and observability infrastructure that improves engineering velocity.</p>\n<p>You will also own incident response, on-call rotations, and post-mortem processes, driving reduction in preventable operational incidents and maintaining high availability SLAs.</p>\n<p>Lastly, you will lead, recruit, and grow a globally distributed team of cloud, data, and security engineers, fostering a culture of ownership and technical excellence.</p>\n<p>What you bring to Komodo Health:</p>\n<ul>\n<li>8+ years in infrastructure, SRE, or platform engineering;</li>\n<li>3+ years leading teams in an AI/ML-intensive environment;</li>\n<li>Hands-on experience with AI workload infrastructure , LLM serving, agent orchestration, GPU compute, or ML pipelines , and the reliability and cost challenges they introduce;</li>\n<li>Deep AWS and production Kubernetes expertise (EKS, autoscaling, multi-cluster management) and strong IaC discipline (Terraform or equivalent);</li>\n<li>Demonstrated track record of driving significant cloud cost reduction through systematic FinOps , team-level budgets, cost-per-unit metrics, and leadership-facing dashboards;</li>\n<li>Practical security and compliance experience , cloud posture management, vulnerability lifecycle, IAM, and SOC 2 or equivalent frameworks; comfort in regulated environments;</li>\n<li>Strong executive communication skills , able to translate infrastructure strategy into business outcomes for CTO, Finance, Legal, and Product stakeholders;</li>\n<li>Active user of AI tools in your own workflow; track record of driving AI-assisted automation adoption within your teams</li>\n</ul>\n<p>AI Use Expectations:</p>\n<ul>\n<li>Use AI coding tools (Copilot, Cursor, Claude Code, or equivalent) to accelerate IaC authoring, runbook generation, and infrastructure automation;</li>\n<li>Leverage AI-assisted observability and incident triage to reduce MTTR and surface patterns across system telemetry;</li>\n<li>Evaluate and adopt AI-native DevOps tooling; set the standard for responsible AI use across the team</li>\n</ul>\n<p>Additional skills and experience we’d prioritize (nice to have):</p>\n<ul>\n<li>Snowflake administration and data infrastructure experience at scale;</li>\n<li>Multi-cloud environment experience (AWS + GCP);</li>\n<li>Healthcare, life sciences, or regulated industry background;</li>\n<li>Experience with security automation or agentic security workflows;</li>\n<li>Familiarity with data pipeline technologies (Spark, Airflow, Temporal);</li>\n<li>Experience supporting multi-tenant SaaS infrastructure</li>\n</ul>\n<p>The pay range for this role is $225,000-$270,000 USD per year, depending on location. This position may be eligible for performance-based bonuses and equity awards.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_4e6792dc-8f7","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Komodo Health","sameAs":"https://www.komodohealth.com/","logo":"https://logos.yubhub.co/komodohealth.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/komodohealth/jobs/8515802002","x-work-arrangement":"remote","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$225,000-$270,000 USD","x-skills-required":["Cloud infrastructure","Kubernetes","IaC","Security engineering","Data infrastructure","FinOps","DevOps","AI native DevOps tooling"],"x-skills-preferred":["Snowflake administration","Multi-cloud environment","Healthcare, life sciences, or regulated industry background","Security automation","Agentic security workflows","Data pipeline technologies","Multi-tenant SaaS infrastructure"],"datePosted":"2026-04-24T16:04:32.207Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"United States"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Healthcare","skills":"Cloud infrastructure, Kubernetes, IaC, Security engineering, Data infrastructure, FinOps, DevOps, AI native DevOps tooling, Snowflake administration, Multi-cloud environment, Healthcare, life sciences, or regulated industry background, Security automation, Agentic security workflows, Data pipeline technologies, Multi-tenant SaaS infrastructure","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":225000,"maxValue":270000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_fc4a0972-622"},"title":"Principal Product Manager, AI Model Security","description":"<p>Microsoft Superintelligence team’s mission is to empower every person and every organization on the planet to achieve more.</p>\n<p>As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.</p>\n<p>This role is part of Microsoft AI’s Superintelligence Team. The MAIST is a startup-like team inside Microsoft AI, created to push the boundaries of AI toward Humanist Superintelligence , ultra-capable systems that remain controllable, safety-aligned, and anchored to human values.</p>\n<p>Our mission is to create AI that amplifies human potential while ensuring humanity remains firmly in control. We aim to deliver breakthroughs that benefit society , advancing science, education, and global well-being.</p>\n<p>We are hiring a Product Manager to own AI model security , the discipline of making our frontier models resilient against adversarial attack and purpose-built for security practitioners.</p>\n<p>This role has a dual mandate: (1) harden our models against the full spectrum of LLM security threats , prompt injection, data exfiltration, jailbreaking, training data extraction, zero-day exploit generation, model poisoning, and agentic workflow exploitation , and (2) partner closely with Microsoft Security product teams (Azure Security, Security Copilot) to ensure our models deliver best-in-class capabilities for real-world security workflows.</p>\n<p>Responsibilities:</p>\n<p>Own the model security roadmap: Define and prioritize the security hardening strategy for our frontier models across the full OWASP LLM threat surface , prompt injection (direct and indirect), data exfiltration, jailbreak resistance, system prompt leakage, training data extraction, and adversarial manipulation of agentic workflows.</p>\n<p>Drive zero-day and exploit defense: Work with researchers to evaluate and mitigate the risk of models being used to generate zero-day exploits, malware, or novel attack vectors.</p>\n<p>Build and scale red-teaming frameworks: Design, run, and iterate adversarial testing programs , both automated and human-driven , to continuously probe model vulnerabilities.</p>\n<p>Establish metrics (e.g., jailbreak success rate, injection bypass rate, exfiltration resistance) and drive measurable improvement over time.</p>\n<p>Partner with Microsoft Security product teams: Work closely with Azure Security and Security Copilot teams to translate their product requirements into model training priorities.</p>\n<p>Ensure our models are purpose-built for threat detection, incident triage, vulnerability assessment, log analysis, and compliance reasoning.</p>\n<p>Define security-specific model evaluations: Build benchmark suites and evaluation frameworks that measure real-world security usefulness , not just academic performance.</p>\n<p>Drive training data strategy to improve domain-specific model quality for security practitioners.</p>\n<p>Shape security policy and launch readiness: Establish clear security criteria for model launches.</p>\n<p>Own the security dimension of go/no-go decisions, with frameworks that balance capability, risk, and deployment context.</p>\n<p>Stay at the frontier: Track the rapidly evolving LLM security landscape , new attack techniques, emerging standards (OWASP, NIST AI RMF), regulatory requirements (EU AI Act), and academic research.</p>\n<p>Translate what you learn into actionable product priorities.</p>\n<p>Influence model training and architecture: Partner with researchers and engineers to embed security considerations into model training, fine-tuning, RLHF, and post-training safeguards.</p>\n<p>Qualifications:</p>\n<p>Bachelor’s Degree AND 5+ years experience in product management, security engineering, or software development OR equivalent experience</p>\n<p>Demonstrated hands-on experience with AI/ML systems , you have personally built, evaluated, or shipped ML-powered products or security tools</p>\n<p>Deep familiarity with LLM security threats: prompt injection, jailbreaking, data exfiltration, adversarial attacks on generative models , through professional experience, red-teaming, or security research</p>\n<p>Experience defining product requirements and driving decisions in partnership with researchers or ML engineers</p>\n<p>Track record of building evaluation systems, security benchmarks, or adversarial testing frameworks , not just consuming them</p>\n<p>Ability to operate autonomously, make decisions with incomplete information, and drive projects from ambiguity to shipped outcomes</p>\n<p>Preferred Qualifications:</p>\n<p>Technical background in computer science, security, or AI/ML , a postgraduate degree is a plus but not required</p>\n<p>Experience in offensive security, penetration testing, or red teaming , ideally applied to AI/ML systems</p>\n<p>Familiarity with security workflows and tooling (SIEM, SOAR, EDR, threat intelligence platforms) and how practitioners use them in production</p>\n<p>Understanding of the model lifecycle (pre-training, fine-tuning, RLHF, deployment, monitoring) and where security interventions are most effective</p>\n<p>Experience working with or within enterprise security organizations (e.g., Microsoft Security, CrowdStrike, Palo Alto Networks, or similar)</p>\n<p>Published research, blog posts, or public contributions in AI security, adversarial ML, or LLM red teaming</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_fc4a0972-622","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Microsoft AI","sameAs":"https://microsoft.ai","logo":"https://logos.yubhub.co/microsoft.ai.png"},"x-apply-url":"https://microsoft.ai/job/principal-product-manager-ai-model-security/","x-work-arrangement":null,"x-experience-level":null,"x-job-type":"full-time","x-salary-range":null,"x-skills-required":["AI/ML systems","LLM security threats","prompt injection","jailbreaking","data exfiltration","adversarial attacks on generative models","product requirements","security engineering","software development","evaluation systems","security benchmarks","adversarial testing frameworks","autonomous decision-making","project management","offensive security","penetration testing","red teaming","security workflows","tooling","SIEM","SOAR","EDR","threat intelligence platforms","model lifecycle","pre-training","fine-tuning","RLHF","deployment","monitoring"],"x-skills-preferred":[],"datePosted":"2026-04-24T12:15:26.485Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Redmond"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"AI/ML systems, LLM security threats, prompt injection, jailbreaking, data exfiltration, adversarial attacks on generative models, product requirements, security engineering, software development, evaluation systems, security benchmarks, adversarial testing frameworks, autonomous decision-making, project management, offensive security, penetration testing, red teaming, security workflows, tooling, SIEM, SOAR, EDR, threat intelligence platforms, model lifecycle, pre-training, fine-tuning, RLHF, deployment, monitoring"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_e38a1075-88d"},"title":"Staff Technical Product Manager","description":"<p>We&#39;re looking for a Staff Technical Product Manager to own critical product areas within Scale&#39;s Global Defense business, serving allied defense and national security customers. As a critical builder, you&#39;ll shape and develop Scale&#39;s global defense products, while being the primary technical expert to our global customers.</p>\n<p>You&#39;ll be hands-on: write specs, prototype solutions, dig into technical architecture with engineers, and make product calls grounded in real technical understanding. You&#39;ll design and ship AI-powered products and tooling for defense and national security workflows, working side-by-side with engineering and ML teams.</p>\n<p>You&#39;ll use customer context to inform what you build , understand allied defense workflows deeply enough to make opinionated product decisions, not just relay requirements. You&#39;ll navigate the unique constraints of defense product development across allied nations , classification environments, accreditation processes, air-gapped deployments , or be ready to learn these fast.</p>\n<p>Ideally, you&#39;d have a builder mentality: you&#39;re energized by going from zero to one, not by managing from a distance. You&#39;ll have 8+ years of experience in software engineering, ML engineering, or a deeply technical product role where you were hands-on with what shipped. You&#39;ll have technical fluency: software engineering or ML background (master&#39;s degree in computer science or equivalent experience).</p>\n<p>Please note that our policy requires a 90-day waiting period before reconsidering candidates for the same role.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_e38a1075-88d","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Scale","sameAs":"https://www.scale.com/","logo":"https://logos.yubhub.co/scale.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/scaleai/jobs/4683446005","x-work-arrangement":"onsite","x-experience-level":"staff","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["software engineering","ML engineering","technical product management","AI systems","defense and national security workflows"],"x-skills-preferred":[],"datePosted":"2026-04-18T16:00:35.253Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"London, UK; New York, NY; San Francisco, CA"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"software engineering, ML engineering, technical product management, AI systems, defense and national security workflows"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_45a87931-4a2"},"title":"Security Engineer - Platform Security","description":"<p>We&#39;re seeking a talented and driven Security Engineer to join our Platform Security team. You will build cutting-edge security solutions to protect our Kubernetes-based infrastructure and advance secure AI-driven systems.</p>\n<p>In this role, you will design and implement AI-powered security tools, proactively address vulnerabilities, and champion secure engineering practices across the organisation.</p>\n<p>Ideal candidates are passionate about impactful innovation, excel at writing clean, efficient code, and thrive in fast-paced environments to support xAI&#39;s mission of creating a trusted and secure global digital platform.</p>\n<p>Responsibilities:</p>\n<ul>\n<li>Design and build AI-driven security tooling and agents using Grok to identify, analyse, and mitigate vulnerabilities in the platform infrastructure and customer-facing application(s)</li>\n</ul>\n<ul>\n<li>Proactively identify security problems to solve and own the design and implementation end-to-end</li>\n</ul>\n<ul>\n<li>Collaborate and be a security champion while driving technical decisions across the organisation</li>\n</ul>\n<p>Basic Qualifications:</p>\n<ul>\n<li>3+ years of experience in fast-paced, high-impact environments, ideally at startups or tech-driven companies.</li>\n</ul>\n<ul>\n<li>Expertise in Python, Rust, or Go, with strong problem-solving skills and a focus on clean, efficient code.</li>\n</ul>\n<ul>\n<li>Certifications like CISA, CRISC, CGEIT, Security+, CASP+, or similar preferred.</li>\n</ul>\n<ul>\n<li>Proven experience building tools or systems from scratch, with a focus on scalable solutions.</li>\n</ul>\n<ul>\n<li>Proficiency in designing scalable backend architectures to support secure systems.</li>\n</ul>\n<ul>\n<li>Familiarity with security testing frameworks (e.g., Burp Suite, OWASP ZAP, SAST/DAST).</li>\n</ul>\n<ul>\n<li>Experience with Docker and Kubernetes for deploying and securing containerized applications.</li>\n</ul>\n<ul>\n<li>Knowledge of software supply chain tools, including SBOM management and dependency scanning.</li>\n</ul>\n<p>Preferred Skills and Experience:</p>\n<ul>\n<li>Experience developing AI-driven security tools or integrating AI into security workflows.</li>\n</ul>\n<ul>\n<li>Familiarity with Kubernetes-based environments and securing cloud-native infrastructure.</li>\n</ul>\n<ul>\n<li>Proven ability to drive technical decisions and influence security practices across teams.</li>\n</ul>\n<ul>\n<li>A passion for challenging the status quo and building transformative security solutions.</li>\n</ul>\n<ul>\n<li>Strong collaboration skills, with experience working in dynamic, cross-functional teams.</li>\n</ul>\n<ul>\n<li>A sense of humour and adaptability to thrive in a fast-paced, mission-driven environment.</li>\n</ul>\n<p>ITAR Requirements:</p>\n<p>To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorisations from the U.S. Department of State. Learn more about the ITAR here.</p>\n<p>Compensation and Benefits:</p>\n<p>$180,000 - $440,000 USD</p>\n<p>Base salary is just one part of our total rewards package at xAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short &amp; long-term disability insurance, life insurance, and various other discounts and perks.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_45a87931-4a2","directApply":true,"hiringOrganization":{"@type":"Organization","name":"xAI","sameAs":"https://www.xai.com/","logo":"https://logos.yubhub.co/xai.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/xai/jobs/4835611007","x-work-arrangement":"onsite","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$180,000 - $440,000 USD","x-skills-required":["Python","Rust","Go","Grok","Docker","Kubernetes","Burp Suite","OWASP ZAP","SAST/DAST","SBOM management","dependency scanning"],"x-skills-preferred":["AI-driven security tools","integrating AI into security workflows","Kubernetes-based environments","securing cloud-native infrastructure","driving technical decisions","influencing security practices","challenging the status quo","transformative security solutions","collaboration skills","dynamic cross-functional teams"],"datePosted":"2026-04-18T15:51:56.952Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Palo Alto, CA"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Python, Rust, Go, Grok, Docker, Kubernetes, Burp Suite, OWASP ZAP, SAST/DAST, SBOM management, dependency scanning, AI-driven security tools, integrating AI into security workflows, Kubernetes-based environments, securing cloud-native infrastructure, driving technical decisions, influencing security practices, challenging the status quo, transformative security solutions, collaboration skills, dynamic cross-functional teams","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":180000,"maxValue":440000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_62900fcd-562"},"title":"Security Engineer - Offensive Security","description":"<p>As an Offensive Security Engineer on the Proactive Threat team at Stripe, you will simulate the tactics, techniques, and procedures (TTPs) of real-world adversaries to uncover security risks across Stripe&#39;s products and infrastructure.</p>\n<p>You&#39;ll conduct hands-on penetration testing, lead red team engagements, and collaborate with blue team counterparts to validate and improve detection and response capabilities. Your work will directly influence how Stripe builds, ships, and secures financial infrastructure used by millions of businesses worldwide.</p>\n<p>Responsibilities:</p>\n<p>Conduct comprehensive penetration tests across web applications, APIs, cloud environments (AWS/GCP/Azure), mobile applications, and internal infrastructure.</p>\n<p>Plan and execute red team engagements that emulate the TTPs of cyber and criminal threat actors targeting financial services, including initial access, lateral movement, persistence, and data exfiltration scenarios.</p>\n<p>Perform assumed-breach and objective-based assessments to test detection and response capabilities in coordination with defensive teams.</p>\n<p>Partner with detection engineering, threat intelligence, and incident response teams to validate security controls, identify coverage gaps, and improve detection fidelity.</p>\n<p>Contribute adversary tradecraft insights to inform detection rule development, threat hunting hypotheses, and incident response playbooks.</p>\n<p>Support incident investigations by providing offensive expertise, log analysis, and root cause analysis when required.</p>\n<p>Design, develop, and maintain custom offensive tools, scripts, and automation frameworks to enhance assessment efficiency and coverage.</p>\n<p>Build internal platforms and workflows that enable scalable, repeatable offensive operations.</p>\n<p>Contribute to internal security tooling repositories and champion engineering best practices within the team.</p>\n<p>Automate repetitive testing tasks, payload generation, and reporting workflows using modern development practices.</p>\n<p>Produce clear, actionable reports that communicate technical findings, business risk, and remediation guidance to both technical and non-technical stakeholders.</p>\n<p>Act as a subject-matter expert and primary point of contact for stakeholder teams engaged in offensive security programs and Stripe-wide security initiatives.</p>\n<p>Lead offensive security projects end-to-end, mentor junior team members, and foster a culture of continuous learning and knowledge sharing.</p>\n<p>Stay current with emerging threats, vulnerabilities, and attack techniques; share research internally and contribute to the broader security community.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_62900fcd-562","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Stripe","sameAs":"https://stripe.com/","logo":"https://logos.yubhub.co/stripe.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/stripe/jobs/7820898","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["Python","Go","Web application security","Cloud platforms (AWS, Azure, or GCP)","Offensive tooling (Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound)","Adversary tradecraft and frameworks (MITRE ATT&CK)","Excellent written and verbal communication skills"],"x-skills-preferred":["Experience conducting offensive security in fintech, financial services, or other highly regulated environments","Background in vulnerability research, exploit development, or CVE discovery","Experience collaborating with threat intelligence, detection engineering, or incident response teams (purple team operations)","Familiarity with big data and log analysis tools (Splunk, Databricks, PySpark, osquery, etc.) for threat hunting or investigative support","Proficiency with AI/LLM-assisted development tools (e.g., Claude Code, Cursor, GitHub Copilot) and experience applying them to offensive security workflows"],"datePosted":"2026-04-18T15:51:01.913Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Ireland"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Python, Go, Web application security, Cloud platforms (AWS, Azure, or GCP), Offensive tooling (Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound), Adversary tradecraft and frameworks (MITRE ATT&CK), Excellent written and verbal communication skills, Experience conducting offensive security in fintech, financial services, or other highly regulated environments, Background in vulnerability research, exploit development, or CVE discovery, Experience collaborating with threat intelligence, detection engineering, or incident response teams (purple team operations), Familiarity with big data and log analysis tools (Splunk, Databricks, PySpark, osquery, etc.) for threat hunting or investigative support, Proficiency with AI/LLM-assisted development tools (e.g., Claude Code, Cursor, GitHub Copilot) and experience applying them to offensive security workflows"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_9e667b9c-eb8"},"title":"Senior Security Engineer II, Vulnerability Management","description":"<p>We are seeking a Senior Security Engineer to build the Vulnerability Management program protecting CoreWeave&#39;s AI infrastructure. You will architect intelligent automation systems that defend the GPU clusters powering breakthrough AI research and enterprise AI applications.</p>\n<p>This role combines technical depth, strategic thinking, and the autonomy to design workflows that will protect infrastructure driving the future of AI.</p>\n<p><strong>Key Responsibilities:</strong></p>\n<ul>\n<li>Build and scale AI-powered triage workflows: evaluate tools (LLM integration, TINES orchestration), architect solutions, and deploy to production</li>\n<li>Drive intelligent, risk-based vulnerability prioritization while simultaneously training AI models,your assessments become the foundation for automation</li>\n<li>Influence automation priorities: recommend which areas of the vulnerability pipeline would most benefit from automation to improve team efficiency</li>\n<li>Design and implement automated detection-to-ticket pipelines: build workflows that generate vulnerability detections, test them, scale across the environment, and auto-create Jira tickets</li>\n<li>Execute remediation campaigns: build automated workflows for EOL product removal, vulnerable software upgrades, and OS migrations at scale</li>\n<li>Manage embargoed vendor disclosures from hardware partners, including embargo verification and zero-day response coordination</li>\n<li>Lead security incident investigations related to high-profile vulnerabilities, coordinating cross-functional response and impact assessment</li>\n<li>Participate in on-call rotation for rapid-response vulnerability analysis during active zero-day events or critical security incidents</li>\n<li>Partner with IT, Infrastructure, and Engineering teams to drive remediation efforts, enforce SLAs, and escalate blockers strategically</li>\n<li>Write daily operations reports documenting vulnerability trends, remediation velocity, and emerging threats for security leadership</li>\n<li>Drive process improvements and workflow automation to improve operational efficiency and reduce manual toil</li>\n</ul>\n<p><strong>Requirements:</strong></p>\n<ul>\n<li>7+ years of relevant experience with demonstrated impact in vulnerability management, application security, platform security, or cloud security engineering</li>\n<li>Bachelor’s or Master’s degree in Computer Science, Computer Engineering, Electrical Engineering, or equivalent practical experience</li>\n<li>Proven hands-on experience building security automation (SOAR workflows, detection pipelines, or vulnerability prioritization frameworks)</li>\n<li>Deep subject matter expertise with vulnerability management best practices: CVSS, EPSS, CISA KEV, exploit intelligence, and compensating controls</li>\n<li>Strong development background with proficiency in Python, Go, or similar languages for building production-grade security tools</li>\n<li>Experience with modern vulnerability management tooling such as Wiz, Semgrep, Rapid7, or similar platforms</li>\n<li>Demonstrated ability to partner with cross-functional teams (IT, SRE, Engineering) to drive remediation without formal authority</li>\n<li>Strong familiarity with common security vulnerabilities and the ability to judge their severity and business impact</li>\n</ul>\n<p><strong>Preferred Qualifications:</strong></p>\n<ul>\n<li>Practical experience building AI/ML-powered security workflows (LLM integration, automated triage, human-in-the-loop validation)</li>\n<li>Experience managing hardware security vulnerabilities (GPU/DPU firmware, BMC/IPMI, specialized compute environments)</li>\n<li>Production experience with security automation platforms such as TINES, Splunk SOAR, or serverless frameworks (AWS Lambda)</li>\n<li>Strong DevOps, DevSecOps, or SRE background with experience in AWS/GCP/Azure cloud services and Infrastructure as Code (Terraform, CloudFormation)</li>\n<li>Deep understanding of container security and Kubernetes (image scanning, admission control, runtime protection, supply chain security)</li>\n<li>Experience supporting customer audits (SOC 2, ISO 27001, FedRAMP) with vulnerability evidence and control validation</li>\n<li>Experience integrating vulnerability management into modern CI/CD pipelines with a &#39;shift-left&#39; mentality</li>\n</ul>\n<p><strong>What We Offer:</strong></p>\n<p>The base salary range for this role is $165,000 to $242,000. The starting salary will be determined based on job-related knowledge, skills, experience, and market location. We strive for both market alignment and internal equity when determining compensation. In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program (all based on eligibility).</p>\n<p>The range we’ve posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and location.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_9e667b9c-eb8","directApply":true,"hiringOrganization":{"@type":"Organization","name":"CoreWeave","sameAs":"https://www.coreweave.com","logo":"https://logos.yubhub.co/coreweave.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/coreweave/jobs/4650290006","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$165,000 to $242,000","x-skills-required":["vulnerability management","application security","platform security","cloud security engineering","Python","Go","security automation","SOAR workflows","detection pipelines","vulnerability prioritization frameworks","CVSS","EPSS","CISA KEV","exploit intelligence","compensating controls","Wiz","Semgrep","Rapid7"],"x-skills-preferred":["AI/ML-powered security workflows","hardware security vulnerabilities","security automation platforms","DevOps","DevSecOps","SRE","container security","Kubernetes","customer audits","CI/CD pipelines"],"datePosted":"2026-04-18T15:48:06.696Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"vulnerability management, application security, platform security, cloud security engineering, Python, Go, security automation, SOAR workflows, detection pipelines, vulnerability prioritization frameworks, CVSS, EPSS, CISA KEV, exploit intelligence, compensating controls, Wiz, Semgrep, Rapid7, AI/ML-powered security workflows, hardware security vulnerabilities, security automation platforms, DevOps, DevSecOps, SRE, container security, Kubernetes, customer audits, CI/CD pipelines","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":165000,"maxValue":242000,"unitText":"YEAR"}}}]}