The BasicsTanium is looking for a security engineer to join the Vulnerability Research team within the R&D Security organization, which protects the software and cloud services our customers depend on.
Tanium's customers secure some of the most consequential networks in the world and they extend us a great deal of trust. The Vulnerability Research team is responsible for hunting for previously-unknown vulnerabilities in our software and driving them to remediation before attackers can exploit them.
In this role, you will continuously raise the bar for attackers, making vulnerabilities in Tanium software harder and more expensive to find. Tanium is leveraging frontier models and developing agentic security workflows to scale and accelerate the find-and-fix loop. You will apply your deep security expertise to decide what to hunt for and streamline the vulnerability discovery, triage, and remediation processes.
What you'll do- Decide which attack surfaces and bug classes to go after and build the capability needed to discover new vulnerabilities
- Triage newly discovered vulnerabilities quickly and accurately, ranking them by exploitability and actual impact
- Make remediation easy for engineering by providing high-quality patch guidance and working pull requests in addition to the vulnerability reports
- Maintain a threat model of Tanium software and services and use it to direct future vulnerability research projects
- Drive vulnerability research with frontier AI capabilities by evaluating what is possible using in-house and third-party tooling and building agentic workflows around what works
- Build and maintain reliable tooling to support vulnerability research efforts including AI skills, fuzzing harnesses and static and dynamic analyzers
- Shorten the time from detection to remediation by driving down false positive rate and improving finding quality
- Perform source code review and targeted security assessment of high-risk components
We're looking for someone withEducation- Bachelor's Degree in Computer Science, or other relevant degree or equivalent experience
Experience- 5+ years industry experience, 7+ preferred
- Strong understanding of web and native application security
- Experience with hands-on vulnerability research via source code review, manual application penetration testing, or fuzzing
- Expertise in determining the severity and exploitability of a vulnerability and its impact to the business
- Able to read and write code in at least one of: Go, C++, TypeScript/JavaScript, or Python
- Experience with the process of developing, building, and shipping secure code
Nice to have:- Experience applying frontier models to vulnerability research, and an informed view of where AI accelerates outcomes and where it manufactures noise
- Experience with reachability or exploitability analysis to separate real findings from theoretical ones at scale
- Experience with native code security (C/C++) in privileged or agent-based software
- Experience with cloud platforms (AWS or Azure preferred)
- Published vulnerability research, credited CVEs, bounty findings, open-source security tooling, or conference talks
- Strong understanding of applied cryptography, including encryption, hashing, and secure key management
What you'll get The annual base salary range for this full-time position is $191,000 to $293,000. This range is an estimate for what Tanium will pay a new hire. The actual annual base salary offered may be adjusted based on a variety of factors, including but not limited to, location, education, skills, training, and experience.
In addition to an annual base salary, team members will receive equity awards and a generous benefits package consisting of medical, dental and vision plan, family planning benefits, health savings account, flexible spending account, transportation savings account, 401(k) retirement savings plan with company match, life, accident and disability coverage, business travel accident insurance, employee assistance programs, disability insurance, and other well-being benefits.