Security Engineer (Vulnerability Management and Automation)
Figure · San Jose, United States
About The Role
Join Figure, a leading company in the financial technology sector, as a Security Engineer focused on vulnerability management and automation. In this role, you will design, implement, and manage vulnerability discovery and remediation across enterprise and cloud environments. You will develop systems and tools to improve the security posture of Figure's infrastructure, build and manage automation for vulnerability management, and identify, triage, and remediate vulnerabilities and misconfigurations. You will also design and implement security controls, provide security guidance company-wide, and contribute to the team's operational duties. The ideal candidate will have strong software engineering skills, excellent communication skills, and solid knowledge of operating system internals and enterprise security domains.
- Design, implement, and manage vulnerability discovery and remediation across enterprise and Cloud environments.
- Develop systems and tools to improve the security posture of Figure’s enterprise infrastructure, touching domains such as client platform, corporate networks, as well as SaaS infrastructure.
- Build and manage automation for vulnerability management, and help Figure prioritize and address vulnerabilities across the infrastructure.
- Strong software engineering (beyond scripting or automation) skills in C/C++, Rust, Golang, Python or similar
- Excellent verbal and written communication skills, with high attention to detail
- Solid knowledge of operating system internals, and experience with several of the following areas: Identity and Access, OS Hardening (macOS, Windows, Linux, ChromeOS), SaaS Security or Assurance and Validation
- Experience in several of the following Enterprise Security Domains: Zero Trust/Beyond Corp, Endpoint Security, Cloud Security, Data Loss Prevention, Cryptography and PKI, SaaS Security
- Experience developing and deploying services in multi-cloud environments, preferably one of the following Azure, AWS or Google Cloud Platform
- Strong understanding of federated authentication/authorization technologies (e.g., SAML, SCIM, OPA, OIDC)
- Experience in common tools and processes of adjacent security domains, esp. Detection and Response
- Strong understanding of network security mechanisms, including mTLS, 802.1X, SSH, DNSSEC, Certificate transparency, VPN, and others
- 6+ years of experience as an Enterprise/Cloud focused Security Engineer
- Bachelor of Science in Computer Science, Engineering, Information Systems, or equivalent years of experience in a related technical field
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring