← Все вакансии/Senior/jobgether
SeniorRemoteCanada

Security Developer

J
jobgether
Уровень
Senior
Формат
Remote
О роли

Описание вакансии

About the company

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Developer, Vulnerability Management based in Canada.

This is a high-impact security engineering role focused on transforming vulnerability management from a manual, reactive process into an automated, intelligent platform.

Responsibilities
  • Own and evolve a custom vulnerability management platform, building integrations, automations, workflows, and data pipelines that operate across the security lifecycle.
  • Build automation across the vulnerability management lifecycle, including triage, ticket routing, SLA tracking, ownership resolution, remediation follow-up, and vulnerability closure.
  • Develop and maintain integrations with vulnerability scanners and security tools, transforming raw scanner output into enriched, actionable findings and tickets.
  • Expand the platform beyond existing team workflows by integrating vulnerability management into engineering processes and making security workflows easier for development teams to adopt.
  • Build and maintain queries, dashboards, reports, and data workflows that provide security teams and leadership with clear visibility into vulnerability posture and remediation progress.
  • Work with AI-assisted development tools and automation platforms to reduce manual effort and improve the speed and consistency of security operations.
  • Contribute to the integration of vulnerability management with a cyber reasoning system, supporting future workflows where validated findings can be tested in a sandbox and translated into potential fixes or pull requests.
  • Assess vulnerabilities across application and infrastructure layers, helping teams distinguish genuine security risks from inaccurate or low-value findings.
  • Support risk assessment and prioritization by considering real-world attack surface, exposure, architecture, traffic flows, and business context rather than relying solely on vulnerability scores.
  • Partner with developers to explain findings, resolve disagreements, troubleshoot unsuccessful remediation attempts, and translate security requirements into practical solutions.
  • Collaborate with teams responsible for CI/CD, deployment, threat intelligence, bug bounty, responsible disclosure, and compliance to strengthen the broader vulnerability management ecosystem.
  • Stay current with emerging threats, vulnerability research, exploitation techniques, and the evolving role of AI in security, incorporating relevant developments into platform strategy and prioritization.
Requirements
  • 4+ years of hands-on experience in vulnerability management, security engineering, or a closely related field, including scanner integration, vulnerability triage, remediation tracking, and security workflow development.
  • Strong understanding of the software development lifecycle, with the ability to identify where vulnerabilities are introduced and assess whether security findings accurately represent real risks.
  • Production experience with AWS and practical knowledge of modern cloud infrastructure and security practices.
  • Strong automation-first mindset, with a proven track record of building solutions that replace or significantly reduce manual processes.
  • Deep familiarity with vulnerability management tooling such as Tenable, Semgrep, Rapid7, or comparable platforms, including experience building API-based integrations.
  • Strong understanding of application and infrastructure vulnerabilities, including vulnerability classes such as XSS and CSRF, as well as code, package, library, container, and infrastructure vulnerabilities.
  • Hands-on exposure to SAST, DAST, SCA, OWASP fundamentals, and knowledge of where different security scanners fit within CI, production, and network environments.
  • Experience with GitHub Actions, ArgoCD, Kubernetes, AMIs, container images, and container registries such as ECR or comparable technologies.
  • Understanding of attack surface and exposure management, with the ability to evaluate actual security exposure and business risk when making prioritization or risk-acceptance decisions.
  • Strong communication and stakeholder-management skills, particularly when working with developers and technical teams who may challenge or disagree with security findings.
  • Understanding of how vulnerability management connects with CI/CD and deployment pipelines, threat intelligence, bug bounty or responsible disclosure programs, and compliance controls.
  • Familiarity with vulnerability scoring and prioritization frameworks such as CVSS, EPSS, and SSVC is beneficial.
  • Active experience using AI-assisted development tools such as Claude Code, Cursor, Copilot, or similar solutions, with the judgment to use AI effectively while validating its output.
  • Experience with security orchestration platforms such as Tracecat, Tines, XSOAR, or comparable tools is a plus.
  • Experience with bug bounty or responsible disclosure programs is a plus.
Стек и навыки

С чем работаем