Your browser does not support javascript! Please enable it, otherwise web will not work for you.

Security Engineer - Vulnerability Management

Home > Python programming jobs

Security Engineer - Vulnerability Management in Others

  • Endor Labs
  • Full time
  • Email
  • Bengaluru, India

Responsibilities

  • Advance Endor Labs’ proprietary vulnerability database and improve AI pipelines for automated vulnerability validation, reachability analysis, and exploit generation.
  • Monitor and manage pipelines that triage, enrich, and prioritize vulnerabilities at scale.
  • Improve the accuracy, coverage, and timeliness of vulnerability data using standards and sources such as CVE, CWE, CVSS, EPSS, PURL, NVD, OSV, GHSA, and VEX.
  • Work with 0-day researchers to turn manual vulnerability discovery workflows into repeatable, production-grade systems.
  • Investigate high-impact vulnerabilities and the broader vulnerability landscape.
  • Author external-facing blog posts, technical write-ups, advisories, and other security communications.
  • Collaborate with internal teams to feed findings into detection and analysis pipelines and improve automated coverage.

Requirements

  • Bachelor’s degree in engineering or a related field.
  • At least 3 years of hands-on professional experience in vulnerability research, vulnerability management, product security, or application security.
  • Extensive knowledge of software vulnerabilities, triage, prioritization, and related standards and technologies, including CVE, CWE, CVSS, EPSS, PURLs, NVD, OSV, VEX, and SBOM formats.
  • Hands-on experience building production-grade enterprise solutions such as CI/CD automation, SAST/SCA findings management, or comparable security tooling.
  • Experience shipping AI or agentic systems to production, including LLM pipelines, agent frameworks, tool use, prompt design, and evaluation design.
  • Ability to measure AI or agentic system output quality and assess where these approaches are effective or ineffective.
  • Proficiency reading and analyzing code in Python, JavaScript/TypeScript, Java, and Go, including reasoning about patches, root causes, and exploitability.
  • Experience producing external security communications such as blog posts, advisories, or public or customer-facing technical reports.
  • Preferred experience writing proof-of-concept exploits or working with fuzzing, static analysis, or automated vulnerability discovery.
  • Preferred contributions to open-source vulnerability databases, scanners, or related tooling such as OSV, osv-scanner, or OpenVEX.
  • Familiarity with SAST, SCA, and DAST tooling and large-scale triage of their output.
  • Understanding of software supply-chain security standards and frameworks such as SLSA and SSDF.
  • Prior public research, CVE credits, or published vulnerability findings is preferred.
  • Security certifications such as OSCP, OSCE, or equivalent are preferred.

Endor Labs

Endor Labs is the AppSec platform built for the AI era. It helps teams find, prioritize, and fix the most critical risks in code, whether written by humans or AI—faster. Endor Labs understands the entire structure of your codebase, from 40 year-old C++ to modern Bazel monorepos. Powered by AI age...

Similar positions

Research Scientist - Machine Learning

  • ISEE
  • Full time
  • USA
  • 09/13/2026
  • Remote

Software Engineer in Test

  • Roadie
  • Full time
  • USA
  • 09/13/2026
  • Salary: Competitive
  • Remote

Principal Software Engineer - Builder Experience

  • Elastic
  • Full time
  • Remote
  • 09/13/2026
  • Salary: €73k-€116k
  • Greece

Principal Software Engineer - Builder Experience

  • Elastic
  • Full time
  • Remote
  • 09/13/2026
  • Salary: zł 369k-zł 584k
  • Poland

Senior Devops Engineer

  • Woliba
  • Full time
  • USA
  • 09/13/2026
  • Remote