5 hours ago
Base Salary
$191k - $293k/yr
Responsibilities
- Build and maintain security tooling, using AI where appropriate to streamline security processes.
- Identify customer visibility gaps in Tanium deployments and partner with Engineering and Product teams to resolve them.
- Oversee SBOM and vulnerability management programs and provide visibility to internal and external stakeholders.
- Collaborate with customers, partners, and customer-facing teams to turn recurring security questions into engineering solutions.
- Answer security inquiries and escalations, maintain reusable responses, and interact directly with customers when needed.
- Administer the bug bounty program by triaging reports, assessing exploitability and severity, adjudicating duplicates and out-of-scope submissions, recommending awards, and supporting researcher relationships.
- Author and publish security advisories and CVE records, including CWE classification and CVSS scoring.
- Coordinate vulnerability disclosure timing and embargoes with researchers, customers, partners, and external coordinating bodies.
Requirements
- Bachelor’s degree in Computer Science or another relevant field, or equivalent experience.
- At least 5 years of industry experience; 7 or more years preferred.
- Experience with product security, application security, vulnerability research, or software engineering with a substantial security focus.
- Experience interacting with customers and external security researchers.
- Experience applying AI tooling to security work and evaluating its usefulness and noise.
- Experience building tools or data interfaces used by external stakeholders, support teams, or customers.
- Experience with modern software engineering and automation tools such as Git and CI/CD pipelines.
- Experience assessing vulnerability severity, exploitability, and business impact.
- Familiarity with SCA/SBOM tooling and third-party dependency vulnerability management is preferred.
- Experience with coordinated vulnerability disclosure, CVE assignment, CVSS, CWE, CNA operations, bug bounty programs, or vulnerability disclosure programs is preferred.
- Published vulnerability research, credited CVEs, bug bounty findings, open-source security tooling, or conference talks are preferred.
- Working knowledge of Tanium products and services is preferred.
- Strong understanding of applied cryptography, including encryption, hashing, and secure key management, is preferred.
Benefits
- Annual base salary range of $191,000 to $293,000, plus equity awards.
- Medical, dental, vision, family planning, health savings, flexible spending, and transportation savings benefits.
- 401(k) retirement savings plan with company match, life, accident, disability, business travel accident, and employee assistance coverage.
- Other well-being benefits and five days of volunteer time off annually.
- Full-time position with compensation adjusted based on factors including location, education, skills, training, and experience.
About Tanium
Tanium builds an enterprise platform for unified endpoint management and security, combining real-time asset discovery, patching, vulnerability management, and EDR for IT and security teams. It sells subscriptions and services to large organizations that need fleet-wide visibility and control across Windows, macOS, Linux, and cloud endpoints. Founded in 2007 and headquartered in Bellevue, Washington, the privately held company reports securing over 32 million endpoints globally.
