Hiring.Camp

Vulnerability Engineer

Domino Data Lab

Location
Remote India
Workplace
Remote
Department
Engineering
Source
CareerPuck

Description

Who we are

At Domino, we build software that helps the largest, AI-driven organizations build and operate advanced data science and AI solutions at scale. Our platform integrates a streamlined model development environment, MLOps capabilities, and novel features for collaboration, reuse, and reproducibility — all of which make data science teams more productive, reduce time to value, and ensure compliance. Our customers — like Johnson & Johnson, GSK, Bristol Myers, UBS, FINRA and the US Navy — are using our software to solve some of the most important challenges in the world, such as developing new medicines, securing our financial markets, or protecting our country. Backed by Sequoia Capital, Coatue Management, NVIDIA, Snowflake and other leading investors, we have been in business for a decade but are still a small team operating with the spirit of a startup. Especially in the world of AI today, we believe that the future is still being invented — and we want to be the ones building it. For more information, visit www.domino.ai

What we are building

Domino's Security team safeguards a platform trusted by some of the most regulated organizations in the world, across financial services, pharma, government, and defense. Vulnerability Management is where that trust gets tested day to day: finding, triaging, and closing out risk across our OS, container, and dependency surface, and giving customers a clear, defensible answer when they ask how exposed they are. This role joins that function as it scales, working closely with our Staff Security Engineer to turn a fast-growing vulnerability workload into faster, more consistent risk assessments.

What your impact will be

In your first year, your impact will be:

  • Faster, more consistent Vulnerability Risk Assessments. You'll own first-pass CVSS scoring and exploitability analysis, closing the SLA gap between finding and answer
  • Validated, trustworthy triage. You'll reproduce and confirm customer-reported and pen-test findings before they reach Engineering, so fix priority reflects real exploitability, not just scanner severity
  • Reliable scanning pipelines. You'll keep SAST/DAST and vulnerability scanning automations running, troubleshooting failures and tuning configs so the data everyone relies on stays clean
  • Real partnership with Engineering. You'll build or run PoC exploits on select CVEs, bringing validated risk, not just findings, into prioritization conversations
  • More capacity for the function. You'll free up our Staff Security Engineer to focus on program-level improvement instead of carrying all of vulnerability management's day-to-day load

What we look for in this role

  • Hands-on experience managing vulnerabilities for a large SaaS product, across OS, container, and dependency exposure
  • A track record triaging and tracking CVEs for a SaaS or containerized product: reading scan reports, prioritizing by severity, and following through to resolution
  • Experience reproducing and validating reported vulnerabilities, whether from customer disclosures or pen test findings, not just logging them
  • Time spent with vulnerability scanning tools such as Prisma Cloud/Twistlock, JFrog, or Trivy, including reconciling findings across tools
  • Comfort building or maintaining SAST/DAST pipeline automation, and triaging what the scans turn up
  • Experience partnering with Engineering to get fixes prioritized and shipped, not just reported
  • Background in a highly regulated environment or modern software company, ideally one that moves at startup or scale-up speed
  • Strong scripting ability, Python preferred
  • Working knowledge of CVSS v3.1/v4.0 scoring and the judgment to assess risk, not just report it
  • Exploit development or PoC skills to validate real-world exploitability of CVEs, using tools like Burp Suite
  • Familiarity with OWASP Top 10 and testing methodology
  • Working knowledge of containers and Kubernetes, plus core Linux, AWS, and networking fundamentals
  • Basic understanding of authentication/authorization concepts (tokens, session handling, auth bypass patterns) and API security fundamentals
  • Basic threat modeling: thinking in attack paths, not just isolated severity scores
  • Clear communication, comfortable navigating risk conversations with Engineering and customers, including drafting risk statements a non-technical audience will actually read
  • Comfort operating with ambiguity, since not every finding arrives with a clean severity or fix path

Nice to have:

  • OSWA, OSWE, or a similar offensive security certification (e.g. GWAPT, GPEN)
  • Familiarity with Airflow and Snowflake

What we value

  • We value a growth mindset. High-performing creative individuals who dig into problems and see the opportunities for success
  • We believe in individuals who seek truth and speak the truth and can be their whole selves at work
  • We value all of you that believe improving is always possible At Domino Everything is a work in progress – we can do better at everything
  • We emphasize an environment of teaching and learning to equip employees with the tools needed to be successful in their function and the company
  • We strongly believe in the value of growing a diverse team and encourage people of all backgrounds, genders, ethnicities, abilities, and sexual orientations to apply

#LI-Remote

Skills

PythonAWSKubernetesLinuxAirflowSnowflakeData ScienceCompliance

Similar Jobs

30

Vulnerability Engineer

Booz Allen Hamilton · USA, HI, Camp H.M. Smith (Halawa Heights Dr), United States of America

1 month ago

Senior Security Vulnerability Engineer

Rockstar Games · Bengaluru, Karnataka, India · Hybrid, Onsite

Today

Senior Security Engineer, Vulnerability Management

1Password · Remote (United States | Canada) · Remote

Yesterday

Senior Information Security Engineer - Vulnerability Management

Wells Fargo · 111443-IND-HYDERABAD-INTL HYD WF CENTRE BLK B8 Twr-4, India

2 days ago

Cybersecurity Vulnerability Engineer

Thales · Ottawa - Palladium, Canada · Remote

2 days ago

Product Security Engineer (Vulnerability Management)

Juara It Solutions · Chennai

1 week ago

Lead InfoSec Engineer, Vulnerability Management

Spgi · US - NY NYC - 55 WATER ST 40 HRS, United States of America · Hybrid

2 weeks ago

Lead Information Security Engineer - Vulnerability Management

Fifththird · Virtual - Ohio, United States of America · Remote

2 weeks ago

Lead InfoSec Engineer, Vulnerability Management

Spgi · US - NY NYC - 55 WATER ST 40 HRS, United States of America · Hybrid

2 weeks ago

Senior Staff Software Engineer, Vulnerability Management

Zocdoc · USA Remote +1 · Remote

3 weeks ago

Security Engineer – Vulnerability Management

Slihrms · IN.TN.Chennai.IndiQube Alpine, Jawaharlal Nehru Road, Block No. 4, SIDCO Industrial Estate.Guindy, India

3 weeks ago

Sr. Security Data Engineer, Vulnerability Risk Management

modernatx · 325 Binney St - Cambridge - USA - MA, United States of America +2 · Remote

4 weeks ago

Cyber Security Engineer (Vulnerability Management & SecOperations)

Solarisbank · Berlin

4 weeks ago

Senior Reverse Engineer/Vulnerability Researcher (Onsite)

Nwis · AL-3443: 3443 Aerobee Road Redstone Arsenal, AL 35898 United States of America · Onsite

1 month ago

Security Engineer, Vulnerability Management and Automation

Figure · San Jose, CA +1 · Onsite

1 month ago

Lead SRE and Vulnerability Engineer

Huntington · Easton Ops Cols C Oh, United States of America · Onsite

1 month ago

Staff Security Engineer – Vulnerability Management

Geico · WA Remote Zone 1, United States of America +3 · Hybrid

1 month ago

Principal Software Reverse Engineer/Vulnerability Researcher (Onsite)

Nwis · FL710: Raytheon SI Government Solutio 1220 North Hwy A1A Suite 123, Indialantic, FL, 32903 USA, United States of America

1 month ago

Cyber Reverse Engineer/Vulnerability Researcher

RTX · US-MD-COLUMBIA-720 ~ 9861 Broken Land Pkwy ~ BBN COLUMBIA, Ste 400, United States of America · Onsite

1 month ago

Security Engineer - Vulnerability & Exposure Management

Roche · Petaling Jaya, Malaysia

2 months ago

Senior Security Engineer, Vulnerability Automation

Jane · Canada · Remote

2 months ago

Staff Software Engineer, Vulnerability Management

Geico · MD Bethesda Office, United States of America +3 · Hybrid

2 months ago

Sr. Security Software Engineer, Vulnerability Management - Slack

Slack · Georgia - Atlanta, United States of America +2 · Onsite

2 months ago

Sr. Security Software Engineer, Vulnerability Management - Slack

Salesforce · Georgia - Atlanta, United States of America +2 · Onsite

2 months ago

Principal Software Reverse Engineer/Vulnerability Researcher

Nwis · FL710: Raytheon SI Government Solutio 1220 North Hwy A1A Suite 123, Indialantic, FL, 32903 USA, United States of America

2 months ago

Compliance and Continuous Monitoring Engineer - Vulnerability Management (Top Secret Clearance)

ShorePoint · Washington, District of Columbia

2 months ago

Security Engineer - Vulnerability Detection (Hybrid)

Crowdstrike · Sunnyvale, United States of America · Remote, Hybrid, Onsite

2 months ago

Product Security Engineer - Vulnerability Management Research and Automation - Cork, Ireland

Qualcomm · Cork, CO,IE, IE

2 months ago

Senior Security Engineer – Vulnerability Management & Penetration Testing

Truveta · Hyderabad, India

3 months ago

Principal Reverse Engineer/Vulnerability Researcher (Onsite)

Nwis · RAL99: NW Remote, Alabama, United States of America · Remote

3 months ago