Improve vulnerability discovery and assessment across network, cloud, endpoint, application, container, database, and hybrid technology environments.
Develop risk-based prioritization using vulnerability data, threat intelligence, exploitation evidence, asset and business context, and control effectiveness.
Partner with technology owners to mobilize remediation, mitigation, accepted disposition, ownership, and progress measurement.
Evolve vulnerability-management platforms, integrations, data, analytics, automation, and AI-enabled workflows.
Communicate vulnerability trends, material risks, remediation progress, and program outcomes to technical, operational, and leadership audiences.
Mentor engineers and analysts and contribute to technical standards, procedures, documentation, and delivery quality.
Maintain current knowledge of vulnerabilities, exploitation techniques, threat activity, security technologies, and industry practices.
Requirements
8+ years of relevant experience in information security, information technology, systems engineering, or a related field, including substantial vulnerability management, security research, or exposure-management experience.
Bachelor’s degree or equivalent in computer science, information security, or a related discipline.
Experience leading complex technical workstreams across multiple teams and delivering measurable outcomes without direct reporting authority.
Hands-on experience with vulnerability research, technical analysis, security validation, risk-based prioritization, and remediation or mitigation guidance.
Experience assessing vulnerabilities across operating systems, networks, cloud services, applications, endpoints, containers, databases, or hybrid infrastructure.
Experience with vulnerability discovery, assessment, validation, or exposure-management platforms and integrations.
Knowledge of adversarial tactics, exploitation techniques, threat intelligence, and attack frameworks such as MITRE ATT&CK.
Experience using scripting, programming, APIs, or automation to improve security analysis and workflows, including technologies such as Python, SQL, Bash, PowerShell, or JavaScript.
Experience contextualizing security data with asset, service, business, threat, control, and remediation information.
Familiarity with version control, testing, code review, CI/CD, reusable components, and controlled production releases.
Experience communicating complex security conditions and recommendations and mentoring engineers or analysts.
Desired qualifications include TEM or CTEM operating-model experience, continuous or adversarial security validation, exploit research, cloud/container/application/build-pipeline security, security-data platforms such as Snowflake or Domo, and automation, advanced analytics, or AI-enabled security workflows.
Benefits
Flexible remote work arrangement with pay ranges varying by geographic location.
Medical, dental, vision, matching 401(k), paid time off, wellness program, and Sony employee discounts.
May be eligible for a bonus package.
Some travel may be required.
Background checks are conducted at the offer stage for new employees.
Salary: $176k - $263k/yr
PlayStation Global
At PlayStation Global, we focus on creating user-friendly solutions that simplify processes, improve efficiency, and empower teams to succeed.