Vulnerability Engineer
Domino Data Lab
IndiaremotePosted 1 month ago
Skill Required
Vulnerability-EngineeringCybersecuritySecurity-EngineeringApplication-SecuritySecurity-OperationsVulnerability-Management-EngineerVulnerability-Management-EngineeringSecurity-EngineertroubleshootingBurp SuiteEngineeringKubernetesnetworkingautomationSnowflakesecuritybuildingAirflowTestNGPythonLinuxOWASPCloudMachine LearningAWSandAIFulltime
Key highlights
- Role focuses on scaling Vulnerability Management for a platform trusted by highly regulated organizations
- Requires hands-on experience with vulnerability scanning tools (Prisma Cloud/Twistlock, JFrog, Trivy)
- Strong Python scripting ability required
- Preferred: offensive security certifications (OSWA, OSWE, GWAPT, GPEN)
Role overview
At Domino, we build software that helps large, AI-driven organizations develop and operate advanced data science and AI solutions at scale. Our platform integrates model development, MLOps, and collaboration features to enhance productivity, reduce time to value, and ensure compliance for customers like Johnson & Johnson, GSK, and the US Navy. The Security team safeguards this platform, trusted by highly regulated organizations, with a focus on Vulnerability Management—finding, triaging, and mitigating risks across OS, container, and dependency surfaces. This role will scale the vulnerability management function, working closely with the Staff Security Engineer to improve risk assessments, triage, and automation pipelines.
Responsibilities
- Own first-pass CVSS scoring and exploitability analysis to close the SLA gap between finding and answer
- Reproduce and confirm customer-reported and pen-test findings before they reach Engineering to ensure fix priority reflects real exploitability, not just scanner severity
- Keep SAST/DAST and vulnerability scanning automations running, troubleshooting failures and tuning configs to maintain clean data
- Build or run PoC exploits on select CVEs, bringing validated risk into prioritization conversations with Engineering
- Free up the Staff Security Engineer to focus on program-level improvement by handling day-to-day vulnerability management workload
Requirements
- Hands-on experience managing vulnerabilities for a large SaaS product, across OS, container, and dependency exposure
- A track record triaging and tracking CVEs for a SaaS or containerized product: reading scan reports, prioritizing by severity, and following through to resolution
- Experience reproducing and validating reported vulnerabilities, whether from customer disclosures or pen test findings, not just logging them
- Time spent with vulnerability scanning tools such as Prisma Cloud/Twistlock, JFrog, or Trivy, including reconciling findings across tools
- Comfort building or maintaining SAST/DAST pipeline automation, and triaging what the scans turn up
- Experience partnering with Engineering to get fixes prioritized and shipped, not just reported
- Background in a highly regulated environment or modern software company, ideally one that moves at startup or scale-up speed
- Strong scripting ability, Python preferred
- Working knowledge of CVSS v3.1/v4.0 scoring and the judgment to assess risk, not just report it
- Exploit development or PoC skills to validate real-world exploitability of CVEs, using tools like Burp Suite
- Familiarity with OWASP Top 10 and testing methodology
- Working knowledge of containers and Kubernetes, plus core Linux, AWS, and networking fundamentals
- Basic understanding of authentication/authorization concepts (tokens, session handling, auth bypass patterns) and API security fundamentals
- Basic threat modeling: thinking in attack paths, not just isolated severity scores
- Clear communication, comfortable navigating risk conversations with Engineering and customers, including drafting risk statements a non-technical audience will actually read
- Comfort operating with ambiguity, since not every finding arrives with a clean severity or fix path
Nice to have
- OSWA, OSWE, or a similar offensive security certification (e.g., GWAPT, GPEN)
- Familiarity with Airflow and Snowflake
Additional details
- We value a growth mindset. High-performing creative individuals who dig into problems and see the opportunities for success
- We believe in individuals who seek truth and speak the truth and can be their whole selves at work
- We value all of you that believe improving is always possible. At Domino Everything is a work in progress – we can do better at everything
- We emphasize an environment of teaching and learning to equip employees with the tools needed to be successful in their function and the company
- We strongly believe in the value of growing a diverse team and encourage people of all backgrounds, genders, ethnicities, abilities, and sexual orientations to apply
- Backed by Sequoia Capital, Coatue Management, NVIDIA, Snowflake and other leading investors, we have been in business for a decade but are still a small team operating with the spirit of a startup
- Originally posted on Himalayas