
Security Engineer - Vulnerability Management
Endor Labs4 hours ago
Bengaluru, IndiaMid Level
H1B Sponsor
Responsibilities
- Advance Endor Labs’ proprietary vulnerability database and improve AI pipelines for automated vulnerability validation, reachability analysis, and exploit generation.
- Monitor and manage pipelines that triage, enrich, and prioritize vulnerabilities at scale.
- Improve the accuracy, coverage, and timeliness of vulnerability data using standards and sources such as CVE, CWE, CVSS, EPSS, PURL, NVD, OSV, GHSA, and VEX.
- Work with 0-day researchers to turn manual vulnerability discovery workflows into repeatable, production-grade systems.
- Investigate high-impact vulnerabilities and the broader vulnerability landscape.
- Author external-facing blog posts, technical write-ups, advisories, and other security communications.
- Collaborate with internal teams to feed findings into detection and analysis pipelines and improve automated coverage.
Requirements
- Bachelor’s degree in engineering or a related field.
- At least 3 years of hands-on professional experience in vulnerability research, vulnerability management, product security, or application security.
- Extensive knowledge of software vulnerabilities, triage, prioritization, and related standards and technologies, including CVE, CWE, CVSS, EPSS, PURLs, NVD, OSV, VEX, and SBOM formats.
- Hands-on experience building production-grade enterprise solutions such as CI/CD automation, SAST/SCA findings management, or comparable security tooling.
- Experience shipping AI or agentic systems to production, including LLM pipelines, agent frameworks, tool use, prompt design, and evaluation design.
- Ability to measure AI or agentic system output quality and assess where these approaches are effective or ineffective.
- Proficiency reading and analyzing code in Python, JavaScript/TypeScript, Java, and Go, including reasoning about patches, root causes, and exploitability.
- Experience producing external security communications such as blog posts, advisories, or public or customer-facing technical reports.
- Preferred experience writing proof-of-concept exploits or working with fuzzing, static analysis, or automated vulnerability discovery.
- Preferred contributions to open-source vulnerability databases, scanners, or related tooling such as OSV, osv-scanner, or OpenVEX.
- Familiarity with SAST, SCA, and DAST tooling and large-scale triage of their output.
- Understanding of software supply-chain security standards and frameworks such as SLSA and SSDF.
- Prior public research, CVE credits, or published vulnerability findings is preferred.
- Security certifications such as OSCP, OSCE, or equivalent are preferred.
Tech Stack
Categories
About Endor Labs
Endor Labs is the AppSec platform built for the AI era. It helps teams find, prioritize, and fix the most critical risks in code, whether written by humans or AI—faster. Endor Labs understands the entire structure of your codebase, from 40 year-old C++ to modern Bazel monorepos. Powered by AI agents and the industry's richest security dataset about open source code, Endor Labs doesn’t just flag issues, it reduces noise, prioritizes what matters most, and proposes intelligent remediations based on the context of your code. Whether you’re an upstart or in the Fortune 500, Endor Labs helps AppSec and development teams eliminate noisy alerts, fix code 6.2x faster, and stay compliant with standards like FedRAMP, PCI, SLSA, and NIST SSDF.