
Senior Security Research Engineer
PlayStation Global5 hours ago
Base Salary
$176k - $263k/yr
Responsibilities
- Lead Global Vulnerability Management workstreams advancing Threat Exposure Management and Continuous Threat Exposure Management capabilities.
- Translate annual goals into delivery plans, milestones, dependencies, success measures, and repeatable operating practices.
- Conduct hands-on vulnerability research, technical analysis, security validation, exploitability assessment, and proof-of-concept development.
- Improve vulnerability discovery and assessment across network, cloud, endpoint, application, container, database, and hybrid technology environments.
- Develop risk-based prioritization using vulnerability data, threat intelligence, exploitation evidence, asset and business context, and control effectiveness.
- Partner with technology owners to mobilize remediation, mitigation, accepted disposition, ownership, and progress measurement.
- Evolve vulnerability-management platforms, integrations, data, analytics, automation, and AI-enabled workflows.
- Communicate vulnerability trends, material risks, remediation progress, and program outcomes to technical, operational, and leadership audiences.
- Mentor engineers and analysts and contribute to technical standards, procedures, documentation, and delivery quality.
- Maintain current knowledge of vulnerabilities, exploitation techniques, threat activity, security technologies, and industry practices.
Requirements
- 8+ years of relevant experience in information security, information technology, systems engineering, or a related field, including substantial vulnerability management, security research, or exposure-management experience.
- Bachelor’s degree or equivalent in computer science, information security, or a related discipline.
- Experience leading complex technical workstreams across multiple teams and delivering measurable outcomes without direct reporting authority.
- Hands-on experience with vulnerability research, technical analysis, security validation, risk-based prioritization, and remediation or mitigation guidance.
- Experience assessing vulnerabilities across operating systems, networks, cloud services, applications, endpoints, containers, databases, or hybrid infrastructure.
- Experience with vulnerability discovery, assessment, validation, or exposure-management platforms and integrations.
- Knowledge of adversarial tactics, exploitation techniques, threat intelligence, and attack frameworks such as MITRE ATT&CK.
- Experience using scripting, programming, APIs, or automation to improve security analysis and workflows, including technologies such as Python, SQL, Bash, PowerShell, or JavaScript.
- Experience contextualizing security data with asset, service, business, threat, control, and remediation information.
- Familiarity with version control, testing, code review, CI/CD, reusable components, and controlled production releases.
- Experience communicating complex security conditions and recommendations and mentoring engineers or analysts.
- Desired qualifications include TEM or CTEM operating-model experience, continuous or adversarial security validation, exploit research, cloud/container/application/build-pipeline security, security-data platforms such as Snowflake or Domo, and automation, advanced analytics, or AI-enabled security workflows.
Benefits
- Flexible remote work arrangement with pay ranges varying by geographic location.
- Medical, dental, vision, matching 401(k), paid time off, wellness program, and Sony employee discounts.
- May be eligible for a bonus package.
- Some travel may be required.
- Background checks are conducted at the offer stage for new employees.