Required Skills: architectural trust boundaries, attack surfaces, data flows, threat modeling frameworks, STRIDE, PASTA, CWE, CVE, OWASP Top 10, SLA mapping, C++, Go, Java, Python, test harnesses, PoCs, identifying regressions, hallucinations, secure coding standards, threat model reviews for large distributed architectures, microservice architectures. managing vulnerability queues, automated scanning tools, compliance exception reviews, fuzzing, unit test frameworks, sandbox execution, cross-boundary debugging, prompt-tuning automated code generation tools, differential testing, patch validation
Job Description
Support the Search Engineering team by managing vulnerability lifecycles, ensuring secure architectural practices, and overseeing automated fix validations.
Key Responsibilities:
Threat Modeling & Asset Profiling: Document trust boundaries, data flows, and architectural entry points for high-priority services; maintain up-to-date threat profiles in centralized repositories.
Vulnerability Triage & Policy Management: Review and filter scanner findings, classify severity, and evaluate exception requests against security policies.
Reproduction & PoC Validation: Construct minimal test environments/harnesses to validate reported findings and confirm viable vulnerabilities vs. false positives.
Automated / Agentic Fixer Oversight & QA: Supervise and validate code patches generated by automated remediation agents, executing tests and inspecting diffs for regressions.
Product Team Coordination & Closure: Route validated patches to code owners and shepherd fixes through code review to production deployment.