107 vulnerability management jobs at 83 companies in San Francisco, CA
2w
Save
Mark Applied
Hide
2w
Vulnerability Management Engineer
Pune or Milpitas or Seattle or Princeton or Cape Town or London or Zurich or Singapore or Mexico City or North America or Europe or Africa or Asia
RemoteFull Time
ZensarNational Stock Exchange of India: ZENSARTECH: Global technology firm providing digital transformation and infrastructure services.
4+ YOEBachelor's degree in a related field and 4–10 years of vulnerability management, Windows infrastructure, cybersecurity operations, or endpoint security experience; requires enterprise remediation, risk assessment, and Windows security expertise.
Qualys, Tenable, Rapid7, Microsoft Defender Vulnerability Management, Windows Server, Windows 10/11, Microsoft Defender for Endpoint, SCCM/MECM, Microsoft Intune, Active Directory, Group Policy, Entra ID (Azure AD), DNS, DHCP, CVSS, Common Vulnerabilities and Exposures (CVE), CIS Benchmarks, NIST, ISO 27001, PowerShell, Azure
SoFiNasdaq: SOFI: Mobile-first platform for banking, lending, and investment services.
Deep vulnerability management and security engineering expertise; strong software engineering skills in Python/Go/JavaScript/TypeScript; experience with cloud, containers, SBOMs, and vulnerability tooling; ability to lead technical initiatives and incident response.
Seattle or Palo Alto or Dallas or Bethesda or Washington
$110k-$230k/yrHybridFull Time
GEICO: Provides vehicle and property insurance services to consumers.
8+ YOE8+ years in cybersecurity/security engineering; deep vulnerability management, cloud/containers experience; strong Python/Go/Java scripting, SQL, automation, offensive security, and ability to influence technical stakeholders.
RobloxNYSE: RBLX: Platform for creating and playing user-generated 3D digital experiences.
4+ YOE4+ years in software engineering with a security focus; proficient in Python, Go, Java, or C#; strong problem-solving; track record delivering features and solving operational problems.
15+ YOE5+ Mgmt15+ years in product management leadership, including 5+ years at director or VP level, with cybersecurity SaaS expertise, cloud security knowledge, executive communication, and experience scaling product teams.
RobinhoodNASDAQ: HOOD: Provides a commission-free platform for investing and financial services.
3+ YOE3+ years in security engineering or security automation; Python or Go proficiency; cloud-native infra experience; vulnerability management knowledge; experience with security tooling.
TikTok USDS Joint Venture: Operates and secures TikTok services for U.S. users.
5+ YOETechnical AppSec leadership with team management, manual vulnerability validation, SAST/DAST/SCA orchestration, scripting (Python/Go/Java/JavaScript), and modern cloud-native architecture knowledge.
Carlsbad or Reston or San Jose or San Francisco or New York City
$121k-$191k/yrOnsiteFull Time
ViasatNASDAQ: VSAT: Provides global satellite broadband and secure networking communication services.
5+ YOE5+ years vulnerability management experience (3+ years tactical), expertise with EPSS/CVSS/SSVC/KEV, audit readiness (ISO27001/PCI/CMMC), OS/container/cloud security knowledge, and strong communication for risk decisions.
Santa Clara Family Health Plan: Provides managed health insurance plans for Santa Clara County residents.
2+ YOEBachelor's degree or equivalent; minimum 2 years serving vulnerable members; knowledge of Medicare/Medi-Cal/CMS/DHCS/DMHC; project management, training, auditing, and strong communication and analytical skills; proficiency with Microsoft Office and related tools.
Microsoft Word, Microsoft Excel, Microsoft PowerPoint, Microsoft Visio, Microsoft Project, Microsoft Outlook
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
6+ YOE6+ years software engineering with security focus; proficient in Python; experience with security tooling and CI/CD; strong cross-team collaboration and communication.
Principal / Director, Product Management – Code & Container Security
Mountain View or United States
$240k-$265k/yrHybridFull Time
Harness: AI-powered platform for automating software delivery and DevOps.
7+ YOE7-10 years product management experience in application security/DevSecOps or developer platforms; deep knowledge of SAST, SCA, vulnerability and supply-chain risk, CI/CD, and AI-assisted development; strong communication and stakeholder skills.
5+ YOE5+ years in technical roles (software, product security, release mgmt, or systems engineering). Bachelor’s (or Master’s) in CS/CE/EE or equivalent experience. Expertise in product security, SDL, SAST/DAST, Linux, vulnerability management, network security architecture, and strong cross-functional communication.
PAN-OS, Panorama, Strata Cloud Manager, Secure Development Lifecycle (SDL), SAST, DAST, Linux, Claude Mythos, OpenAI Codex
Zeta GlobalNYSE: ZETA: Provides an AI-powered marketing platform for enterprise customer engagement.
4+ YOE4+ years product management with enterprise AppSec experience, knowledge of SAST/DAST/SCA, CI/CD and vulnerability management, ability to drive risk-based programs and communicate to executives.
Fivetran: Automates data movement into cloud data warehouses.
5+ YOE5+ years in technical program management focused on security engineering, vulnerability management, cloud and application security; requires security domain expertise, scripting, cross-functional collaboration, and SAST/DAST experience.
Bash, Python, JavaScript, BigQuery, Looker, Sigma, Microsoft Azure, AWS, Google Cloud Platform (GCP), Terraform, Docker, Kubernetes, GitHub, Buildkite, SonarQube, Grafana, Prisma, Snyk, Signal Sciences, AI Tools, SAST, DAST, IDS/IPS, OWASP, Application Security Verification Standard (ASVS)
Senior Technical Program Manager, DGX Cloud - Trust Services
Santa Clara or Seattle
$200k-$322k/yrOnsiteFull Time
NVIDIANASDAQ: NVDA: Designs graphics processing units and artificial intelligence hardware.
12+ YOE12+ years TPM experience driving complex infrastructure, trust/security, compliance, or platform programs; deep understanding of firmware/platform integrity, attestation, vulnerability and secrets management; proficiency with Jira and Confluence.
Gusto: Cloud-based payroll and HR software for small businesses.
5+ YOE5+ years leading cross-functional TPM or delivery work in regulated environments; strong knowledge of vulnerability management, security operations, SIEM, detection, identity/JIT access; experience using AI plugins for delivery.
Senior Technical Program Manager, DGX Cloud - Trust Services
Santa Clara or Seattle
$200k-$322k/yrOnsiteFull Time
NVIDIANASDAQ: NVDA: Designs GPU-accelerated computing and artificial intelligence hardware.
12+ YOE12+ years TPM experience delivering complex infrastructure, trust/security, compliance, or platform programs; strong cross-functional leadership; knowledge of attestation, firmware integrity, vulnerability and secrets management; MS or equivalent.