All jobs

Vulnerability Engineer

Dominodatalab4h ago
Remote IndiaRemoteFull-time
  • Who we are
  • At Domino, we build software that helps the largest, AI-driven organizations build and operate advanced data science and AI solutions at scale. Our platform integrates a streamlined model development environment, MLOps capabilities
  • novel features for collaboration, reuse
  • reproducibility — all of which make data science teams more productive, reduce time to value
  • ensure compliance. Our customers — like Johnson & Johnson, GSK, Bristol Myers, UBS, FINRA and the US Navy — are using our software to solve some of the most important challenges in the world, such as developing new medicines, securing our financial markets
  • protecting our country. Backed by Sequoia Capital, Coatue Management, NVIDIA, Snowflake and other leading investors, we have been in business for a decade but are still a small team operating with the spirit of a startup. Especially in the world of AI today, we believe that the future is still being invented — and we want to be the ones building it. For more information, visit www.domino.ai
  • What we are building
  • Domino's Security team safeguards a platform trusted by some of the most regulated organizations in the world, across financial services, pharma, government
  • defense. Vulnerability Management is where that trust gets tested day to day: finding, triaging
  • closing out risk across our OS, container
  • giving customers a clear, defensible answer when they ask how exposed they are. This role joins that function as it scales, working closely with our Staff Security Engineer to turn a fast-growing vulnerability workload into faster, more consistent risk assessments.
  • What your impact will be
  • In your first year, your impact will be:
  • Faster, more consistent Vulnerability Risk Assessments. You'll own first-pass CVSS scoring and exploitability analysis, closing the SLA gap between finding and answer
  • Validated, trustworthy triage. You'll reproduce and confirm customer-reported and pen-test findings before they reach Engineering, so fix priority reflects real exploitability, not just scanner severity
  • Reliable scanning pipelines. You'll keep SAST/DAST and vulnerability scanning automations running, troubleshooting failures and tuning configs so the data everyone relies on stays clean
  • Real partnership with Engineering. You'll build or run PoC exploits on select CVEs, bringing validated risk, not just findings, into prioritization conversations
  • More capacity for the function. You'll free up our Staff Security Engineer to focus on program-level improvement instead of carrying all of vulnerability management's day-to-day load
  • What we look for in this role
  • Hands-on experience managing vulnerabilities for a large SaaS product, across OS, container, and dependency exposure
  • A track record triaging and tracking CVEs for a SaaS or containerized product: reading scan reports, prioritizing by severity, and following through to resolution
  • Experience reproducing and validating reported vulnerabilities, whether from customer disclosures or pen test findings, not just logging them
  • Time spent with vulnerability scanning tools such as Prisma Cloud/Twistlock, JFrog, or Trivy, including reconciling findings across tools
  • Comfort building or maintaining SAST/DAST pipeline automation, and triaging what the scans turn up
  • Experience partnering with Engineering to get fixes prioritized and shipped, not just reported
  • Background in a highly regulated environment or modern software company, ideally one that moves at startup or scale-up speed
  • Strong scripting ability, Python preferred
  • Working knowledge of CVSS v3.1/v4.0 scoring and the judgment to assess risk, not just report it
  • Exploit development or PoC skills to validate real-world exploitability of CVEs, using tools like Burp Suite
  • Familiarity with OWASP Top 10 and testing methodology
  • Working knowledge of containers and Kubernetes, plus core Linux, AWS, and networking fundamentals
  • Basic understanding of authentication/authorization concepts (tokens, session handling, auth bypass patterns) and API security fundamentals
  • Basic threat modeling: thinking in attack paths, not just isolated severity scores
  • Clear communication, comfortable navigating risk conversations with Engineering and customers, including drafting risk statements a non-technical audience will actually read
  • Comfort operating with ambiguity, since not every finding arrives with a clean severity or fix path

Nice To Have

  • OSWA, OSWE, or a similar offensive security certification (e.g. GWAPT, GPEN)
  • Familiarity with Airflow and Snowflake
  • What we value
  • We value a growth mindset. High-performing creative individuals who dig into problems and see the opportunities for success
  • We believe in individuals who seek truth and speak the truth and can be their whole selves at work
  • We value all of you that believe improving is always possible At Domino Everything is a work in progress – we can do better at everything
  • We emphasize an environment of teaching and learning to equip employees with the tools needed to be successful in their function and the company
  • We strongly believe in the value of growing a diverse team and encourage people of all backgrounds, genders, ethnicities, abilities, and sexual orientations to apply
  • #LI-Remote

Required skills

PythonSnowflakeAirflowAWSKubernetesLinuxSecurity
Posted on JobRush — the end-to-end AI job-search platform.