52 vulnerability engineer jobs at 44 companies in Fairfield, CA
5d
Save
Mark Applied
Hide
5d
Staff Vulnerability Management Engineer
Seattle or San Francisco
$144k-$248k/yrOnsiteFull Time
SoFiNasdaq: SOFI: Mobile-first platform for banking, lending, and investment services.
Deep vulnerability management and security engineering expertise; strong software engineering skills in Python/Go/JavaScript/TypeScript; experience with cloud, containers, SBOMs, and vulnerability tooling; ability to lead technical initiatives and incident response.
Sutter Health: Operates an integrated network of hospitals and medical clinics.
9+ YOEDevelop and operate enterprise vulnerability management platform; design data pipelines; integrate with ITSM; build risk-based prioritization and executive reporting. Requires ~9 years relevant experience and bachelor\u0002s or equivalent.
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
6+ YOE6+ years software engineering with security focus; proficient in Python; experience with security tooling and CI/CD; strong cross-team collaboration and communication.
Boston or Chicago or Los Angeles or New York or San Francisco or Toronto or Vancouver or Vancouver
$145k-$175k/yrRemoteFull Time
Later: Provides software for social media scheduling and influencer marketing.
5+ YOE5+ years security engineering experience; strong application, cloud, and infrastructure security; SOC 2 and compliance experience; vulnerability management, IaC and CI/CD security; strong communication and software engineering skills.
OWASP, NIST, CIS Controls, SOC 2, ISO 27001, AWS Security Hub, Azure Security Center, GCP Security Command Center, SIEM, SOAR, Terraform, CloudFormation, C#, CI/CD
Serval: AI platform for automating IT and enterprise service workflows.
10+ YOE10+ years in cybersecurity with deep expertise in application security, secure SDLC, vulnerability management, secure cloud-native architecture, leadership experience, and strong software engineering skills.
LanceDB: Vector database for multimodal AI search and retrieval.
8+ YOE8+ years as a software engineer with experience on large-scale data platforms, building encryption/auth/authZ, cloud/CSP security, vulnerability management (CVE), strong communication and data-driven decision making.
MetaNASDAQ: META: Develops social networking platforms and virtual reality technologies.
10+ YOE10+ years security experience, BS/MS in CS/Engineering or equivalent, experience leading cross-functional programs, expertise in threat modelling, vulnerability management, AWS, and infrastructure hardening.
Decagon: Conversational AI platform for automated customer support.
3+ YOE3+ years application security experience, expertise in secure SDLC, threat modeling, secure code review, vulnerability assessment, SAST/DAST/IAST and CI/CD integration, and working with engineering teams to remediate findings.
SAST, DAST, IAST, CI/CD, Semgrep, CodeQL, Cursor Bug Bot, XBOW, Google Cloud, OWASP Top 10
San Francisco or Palo Alto or Toronto or Los Angeles
OnsiteFull Time
HeyGen: Generate professional AI videos using digital avatars and voices.
Hands-on Python and AWS experience, cloud and application security, vulnerability management, IAM and secrets management, familiarity with SOC 2/ISO 27001, strong communication and threat modeling skills.
Python, AWS, Drata, Infisical, Bugcrowd, SOC 2, ISO 27001
Andreessen Horowitz: Provides venture capital and support to technology startups.
5+ YOE5+ years security engineering with automation and tool-building, strong Python or similar, hands-on LLM/AI API experience, broad cloud security/detection/identity/vulnerability knowledge, and ability to communicate technical security concepts to non-technical audiences.
Rippling: Unified platform managing workforce HR, IT, and finance operations
5+ YOE5+ years in product security, experience securing web applications, code review and CI/CD security tooling, fluency in Python, React, Django Rest Framework, and experience leading cross-team vulnerability mitigations.
Anthropic: Developing safe and reliable artificial intelligence systems.
Hands-on application and infrastructure security experience, production-quality coding in Python/Go/Rust/TypeScript, threat-modeling, vulnerability ID, clear communication, and ability to assess unfamiliar codebases under time pressure.