Role Overview
Support the Search Engineering team by managing vulnerability lifecycles, ensuring secure architectural practices, and overseeing automated fix validations.
Key Responsibilities :
Threat Modeling & Asset Profiling: Document trust boundaries, data flows, and architectural entry points for high-priority services; maintain up-to-date threat profiles in centralized repositories.
- Vulnerability Triage & Policy Management: Review and filter scanner findings, classify severity, and evaluate exception requests against security policies.
- Reproduction & PoC Validation: Construct minimal test environments/harnesses to validate reported findings and confirm viable vulnerabilities vs. false positives.
- Automated / Agentic Fixer Oversight & QA: Supervise and validate code patches generated by automated remediation agents, executing tests and inspecting diffs for regressions.
- Product Team Coordination & Closure: Route validated patches to code owners and shepherd fixes through code review to production deployment.
Technical Skills- Must-Have Skills:
- Understanding of architectural trust boundaries, attack surfaces, data flows, and threat modeling frameworks (e.g., STRIDE, PASTA).
- Working knowledge of common vulnerability classifications (CWE, CVE, OWASP Top 10) and SLA mapping.
- Proficiency reading and writing code in at least two core languages (C++, Go, Java, Python) and building test harnesses/PoCs.
- Strong code review skills (identifying regressions, hallucinations) and knowledge of secure coding standards.
- Nice-to-Have / Advanced Skills:
- Experience with threat model reviews for large distributed / microservice architectures.
- Experience managing vulnerability queues, automated scanning tools, and compliance exception reviews.
- Practical experience with fuzzing, unit test frameworks, sandbox execution, and cross-boundary debugging.
- Experience prompt-tuning automated code generation tools, differential testing, and patch validation.