← Back to job listings
SA
Senior Security Software Engineer (Vulnerability Management, Slack)
Salesforce · Georgia, United States
About The Role
Join Slack as a Senior Security Software Engineer on the Vulnerability Management team. In this high-impact role, you will build and maintain systems to detect, track, and remediate security vulnerabilities across the organization. You will drive technical strategy, work closely with security engineers, product teams, and infrastructure partners, and help raise the bar for software development. The position offers a range of benefits, including medical care, life insurance, retirement savings, and paid time off.
- Contribuer à l'architecture technique des outils de gestion des vulnérabilités, y compris les systèmes qui automatisent l'identification, la priorisation, le suivi et la remédiation des vulnérabilités.
- Concevoir et développer des solutions d'ingénierie de haute qualité et évolutives, en équilibrant la maintenabilité à long terme avec les besoins pratiques d'une organisation de sécurité en évolution rapide.
- Collaborer avec des parties prenantes interfonctionnelles, y compris l'infrastructure, l'ingénierie de plateforme et les équipes de sécurité des produits, pour identifier les opportunités d'intégrer l'automatisation de la sécurité plus profondément dans le cycle de vie du développement.
- Comfort working with CI/CD pipelines, version control workflows, and modern software delivery practices
- Experience building or maintaining integrations with security tooling such as vulnerability scanners, SIEM systems, or similar platforms
- Solid understanding of vulnerability management concepts, including how vulnerabilities are discovered, classified, prioritized, and remediated in enterprise environments
- 6+ years of industry software engineering experience, with a meaningful portion of that spent in security engineering, platform engineering, or infrastructure-adjacent domains
- Deep proficiency in Python, with a strong track record of writing production-grade, tested, maintainable code in complex systems
- Experience working across teams and communicating technical concepts clearly to both engineers and non-technical stakeholders
- Strong judgment in the face of ambiguity, and a track record of asking the right questions before building rather than after
- Demonstrated experience owning and delivering end-to-end engineering projects, from early-stage design through production deployment and ongoing operation
- Hands-on experience with vulnerability management tooling such as Wiz, Tenable/Nessus, Twistlock, or similar products, particularly in cloud or containerized environments
- Familiarity with compliance frameworks relevant to government or regulated environments, such as FedRAMP or DoD IL5/IL6
- Background in building automated remediation workflows, such as automated PR generation for dependency vulnerabilities or patch orchestration across diverse package ecosystems
- Experience working with large-scale vulnerability aggregation systems or homegrown data pipelines that normalize findings across multiple scanners
- Experience with cloud environments (AWS, Azure, GCP) and containerized workloads at scale
- Contributions to the security or software community through open-source projects, published research, conference talks, or similar
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring