Required Skills: Threat Modeling, Trust boundaries, Data flows, Attack surfaces, Architectural entry points, STRIDE, PASTA, Vulnerability Management, Vulnerability triage, Scanner findings, Severity classification, SLA mapping, Security-policy exceptions, Vulnerability reproduction, PoC validation, Building test environments, test harnesses, C++, Go, Java, Python, CWE, CVE, OWASP Top 10, Secure coding standards, Patch validation, Regression detection,
Job Description
-
Role Overview Support the Search Engineering team by managing vulnerability lifecycles, ensuring secure architectural practices, and overseeing automated fix validations. Key Responsibilities :Threat Modelling & Asset Profiling: Document trust boundaries, data flows, and architectural entry points for high-priority services; maintain up-to-date threat profiles in centralized repositories.
-
Vulnerability Triage & Policy Management: Review and filter scanner findings, classify severity, and evaluate exception requests against security policies. Reproduction & PoC Validation: Construct minimal test environments/harnesses to validate reported findings and confirm viable vulnerabilities vs. false positives.
-
Automated / Agentic Fixer Oversight & QA: Supervise and validate code patches generated by automated remediation agents, executing tests and inspecting diffs for regressions.
-
Product Team Coordination & Closure: Route validated patches to code owners and shepherd fixes through code review to production deployment.
-
Technical Skills Must-Have Skills: Understanding of architectural trust boundaries, attack surfaces, data flows, and threat modelling frameworks (e.g., STRIDE, PASTA).Working knowledge of common vulnerability classifications (CWE, CVE, OWASP Top 10) and SLA mapping.
-
Proficiency reading and writing code in at least two core languages (C++, Go, Java, Python) and building test harnesses/PoCs.
-
Strong code review skills (identifying regressions, hallucinations) and knowledge of secure coding standards.
-
Nice-to-Have / Advanced Skills: Experience with threat model reviews for large distributed / microservice architectures.
-
Experience managing vulnerability queues, automated scanning tools, and compliance exception reviews.
-
Practical experience with fuzzing, unit test frameworks, sandbox execution, and cross-boundary debugging.
-
Experience prompt-tuning automated code generation tools, differential testing, and patch validation.
Key Responsibilities:
Threat Modelling & Asset Profiling
Document trust boundaries and data flows
Identify architectural entry points
Maintain threat profiles for high-priority services, Vulnerability Triage
Review security scanner findings, Filter and classify vulnerabilities by severity
Evaluate security-policy exception requests, Reproduction & PoC Validation
Build minimal test environments/harnesses
Reproduce reported vulnerabilities
Distinguish genuine vulnerabilities from false positives
Automated/Agentic Fixer QA
Review patches produced by automated remediation agents
Inspect code diffs, Execute tests, Identify regressions or incorrect/hallucinated fixes
Product-Team Coordination, Route validated fixes to code owners
Support code-review processes
Track fixes through production deployment