CoreWeave

Senior Security Engineer, Vulnerability Management

CoreWeave
Apply
11 hours ago
Bellevue, WA, USA +2 moreSenior
H1B sponsor

Base Salary

$165k - $242k/yr

Responsibilities

  • Set technical direction for major Vulnerability Management initiatives and identify gaps in security visibility.
  • Lead deployment and integration of security tooling and build automation that aggregates findings from multiple sources.
  • Build and operate LLM-based workflows and agents for vulnerability validation, risk assessment, and remediation guidance.
  • Lead investigations involving scanner findings, bug bounty reports, CVEs, disclosures, and attack paths.
  • Drive remediation across engineering teams, resolve technical blockers, and improve vulnerability-burndown systems and processes.
  • Participate in vulnerability-response on-call rotations and lead investigations and post-mortems for urgent vulnerability events.
  • Mentor engineers through design reviews, code reviews, and hands-on technical problem solving.

Requirements

  • Own a significant technical area within vulnerability management or a related security engineering discipline.
  • Have strong production software development experience in Python, Go, Rust, or a similar language, including testing, deployment, monitoring, and troubleshooting.
  • Design and review systems that process security data and integrate multiple services, including decisions about data models, APIs, performance, and failure handling.
  • Have hands-on experience building and evaluating production LLM-based workflows or agents.
  • Have strong knowledge of Linux, containers, cloud, and Kubernetes, with experience investigating vulnerabilities and evaluating remediation options.
  • Assess vulnerability risk using exposure, exploitability, trust relationships, existing controls, CVSS, EPSS, and known exploitation.
  • Lead technical work across engineering teams, resolve implementation or remediation disagreements, and improve shared systems.
  • Mentor engineers and establish practices that improve code quality, testing, and reliability.
  • Preferred experience includes Wiz, Rapid7, CrowdStrike, Tines, Jira, bug bounty or vulnerability disclosure programs, application security, cloud security, red team, penetration testing, blue team, incident response, asset inventory, attack surface management, automated remediation, attack path analysis, firmware or hardware vulnerabilities, and remediation reporting.

Benefits

  • Base benefits include medical, dental, and vision insurance fully paid by CoreWeave, company-paid life insurance, disability insurance, flexible spending and health savings accounts, tuition reimbursement, ESPP participation, mental wellness benefits, family-forming support, paid parental leave, childcare support, and a 401(k) with employer match.
  • Flexible PTO, catered lunch at office and data center locations, a casual work environment, and opportunities for growth in a hyper-growth company.
  • Benefits listed apply to US-based full-time employees; benefits may vary by location.
  • The position requires access to export-controlled information and may require U.S.-person status or export authorization eligibility.
CoreWeave

About CoreWeave

1,001-5,000 employees

CoreWeave provides a GPU-accelerated cloud for AI training and inference, VFX, and rendering, with bare-metal instances, Kubernetes orchestration, and managed services to scale workloads. It sells on-demand and reserved capacity to AI labs, startups, and enterprises, and offers SaaS tools and hands-on support for deployment. Founded in 2017 and headquartered in New York, it is publicly traded on Nasdaq under the ticker CRWV.

Contact me