Keeper Security

Senior Vulnerability Engineer

Keeper Security$120K — $150K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-8+ years in vulnerability management or cybersecurity roles
  • Proficient with vulnerability scanning tools and CVE/CVSS scoring
  • Skilled in automation using Python or PowerShell
  • Experienced in integrating security tools via APIs
  • Strong knowledge of cloud platforms (AWS, GCP, Azure)
  • Ability to troubleshoot vulnerabilities across various layers
  • Hands-on experience with red teaming or bug bounty methodologies

Responsibilities

  • Design and implement scalable vulnerability scanning solutions
  • Engineer integrations for vulnerability management tools
  • Automate vulnerability workflows using APIs
  • Develop risk-based models correlating vulnerability data
  • Build pipelines for CI/CD vulnerability scanning
  • Create dashboards for tracking vulnerability metrics
  • Monitor and respond to zero-day vulnerabilities
  • Support red team exercises and pentesting initiatives

Benefits

  • Medical, Dental & Vision coverage
  • Employer Paid Life Insurance
  • Voluntary Short/Long Term Disability Insurance
  • 401K options (Roth/Traditional)
  • Generous PTO plan including Bereavement and Jury Duty leave
  • Above market annual bonuses
Full Job Description
Description

Keeper Security is hiring an experienced Senior Vulnerability Engineer to design, build, and scale enterprise vulnerability management capabilities across our cloud, application, and corporate environments. This is a 100% remote position, with an opportunity to work a hybrid schedule for candidates based in the El Dorado Hills, CA or Chicago, IL metro area.

About the Job

As a Senior Vulnerability Engineer, you will design, build, and scale systems for vulnerability discovery, prioritization, and remediation across Keeper's cloud, application, and corporate environments. Partnering closely with Engineering, DevOps, IT, and Security teams, you will automate vulnerability detection and response, integrate security into CI/CD pipelines, and operationalize risk-based remediation at scale. This is a highly technical, hands-on role focused on improving visibility, accelerating remediation, and strengthening Keeper's overall security posture. You will also support offensive security initiatives, including penetration testing, red teaming, and bug bounty programs, ensuring findings are actionable and embedded into engineering workflows.

Responsibilities
  • Design and implement scalable vulnerability scanning and asset discovery solutions across multi-cloud and SaaS environments
  • Engineer and maintain integrations between vulnerability management tools and internal systems, including CI/CD platforms, ticketing systems, and source control tools
  • Automate vulnerability ingestion, enrichment, prioritization, and remediation workflows using APIs and scripting
  • Develop risk-based prioritization models by correlating vulnerability data with threat intelligence and exploit activity
  • Build and maintain pipelines to integrate vulnerability scanning into CI/CD processes
  • Create dashboards and analytics to track vulnerability exposure, remediation SLAs, and risk trends
  • Continuously improve coverage and accuracy of asset inventory and scanning capabilities
  • Monitor and respond to zero-day vulnerabilities, CISA KEV bulletins, and active exploit campaigns
  • Partner with Engineering and DevOps teams to troubleshoot and remediate vulnerabilities in applications and infrastructure
  • Contribute to secure architecture and hardening efforts across cloud and application environments
  • Support compliance requirements, including FedRAMP, StateRAMP, SOC 2, ISO 27001, and NIST SP 800-53, through technical implementation and evidence generation
  • Document systems, workflows, and automation for repeatability and scale
  • Support the execution of red team exercises, penetration tests, and bug bounty programs in alignment with real-world threat scenarios
  • Coordinate and validate findings from internal and external testing activities, ensuring accuracy, severity calibration, and reproducibility
  • Integrate offensive security findings into vulnerability management workflows to drive prioritized remediation
  • Partner with external vendors and researchers to triage submissions and improve signal quality in bug bounty programs
  • Continuously improve testing methodologies, coverage, and tooling to reflect evolving attack techniques
  • Correlate red team, penetration testing, and bug bounty findings with vulnerability data to identify systemic weaknesses

Requirements
  • 5-8+ years of experience in vulnerability management, security engineering, or related technical roles
  • Strong hands-on experience with vulnerability scanning tools, CVE/CVSS scoring, and exploit analysis
  • Experience building automation using Python, PowerShell, or similar scripting languages
  • Experience working with APIs and integrating security tools into engineering workflows
  • Strong understanding of cloud platforms, including AWS, GCP, and Azure, as well as modern application architectures
  • Experience embedding security into CI/CD pipelines and developer workflows
  • Ability to troubleshoot vulnerabilities across system, network, and application layers
  • Hands-on experience with penetration testing, red teaming, or bug bounty programs, including triage and validation of findings
  • Working knowledge of compliance frameworks such as NIST SP 800-53, CIS Controls, ISO 27001, and SOC 2

Preferred Qualifications
  • Certifications such as OSCP, GIAC, CISSP, or similar
  • Experience with data analytics and visualization tools such as Splunk or Elastic
  • Background in offensive security, red teaming, or exploit development
  • Experience working with bug bounty platforms and external researcher communities
  • Experience with asset inventory platforms, CMDBs, or cloud-native security tooling
  • Experience building internal security tools or security platforms
  • Bachelor's degree in Cybersecurity, Computer Science, or a related field, or equivalent practical experience

Benefits
  • Medical, Dental & Vision (inclusive of domestic partnerships)
  • Employer Paid Life Insurance & Employee/Spouse/Child Supplemental life
  • Voluntary Short/Long Term Disability Insurance
  • 401K (Roth/Traditional)
  • A generous PTO plan that celebrates your commitment and seniority (including paid Bereavement/Jury Duty, etc)
  • Above market annual bonuses

Classification: Exempt

About Keeper Security

Keeper Security is a cybersecurity company that provides password management and digital vault solutions for businesses and individuals. The company's products include Keeper Business, which is designed for small and medium-sized businesses, and Keeper Enterprise, which is designed for larger organizations. Keeper Security was founded in 2011 and is headquartered in Chicago, Illinois.
Learn more about Keeper Security
Size
200 employees
Industry
Founded
2011

Similar Jobs

More Jobs at Keeper Security

More Information Technology Jobs

Find similar Senior Vulnerability Engineer jobs: