Jobs Companies Endor Labs Security Engineer - Vulnerability Management

À propos de ce poste Security Engineer - Vulnerability Management chez Endor Labs

Endor Labs · Sur site · Bengaluru, India

Who we are

Our mission is to help developers and AppSec teams spend more time accelerating development and less time dealing with security issues. Watch our 3 min pitch from our Founder & CEO here: https://www.youtube.com/watch?v=B0wmZBcPkFE

Endor Labs has been recognized as a Gartner Cool Vendor, a RSA Innovation Sandbox finalist, and a Black Hat Innovation Spotlight finalist, all in its first year from launch.

The company was founded by Varun Badhwar and Dimitri Stiliadis, who have created multiple category-defining cloud security companies. We have raised $70M in Series A funding and assembled a team of the world’s leading static analysis experts and enterprise software veterans to increase developer productivity and open source software adoption.

What you’ll do

  • The primary focus of this position is to help the team further advance Endor Labs'proprietary vulnerability database — extending and improving our existing AI pipelines,
    e.g., in the areas of automated vulnerability validation, reachability analysis, and exploit generation.
  • Day-to-day work includes monitoring and managing pipelines that triage, enrich, and prioritize vulnerabilities at scale, working with the standards and data sources the
    ecosystem is built on (CVE, CWE, CVSS, EPSS, PURL, NVD, OSV, GHSA, VEX) and continuously improving the accuracy, coverage, and timeliness of our data.
  • You will work hand-in-hand with our world-class 0-day researchers to scale automated vulnerability discovery — turning manual research workflows into repeatable,
    production-grade systems.
  • You will investigate high-impact vulnerabilities and the vulnerability landscape at large, and author external-facing content — blog posts, technical write-ups, and advisories —
    communicating findings clearly to both technical and non-technical audiences.
  • You will collaborate with internal teams to feed findings into detection and analysis pipelines, enrich our vulnerability database, and help improve automated coverage over
    time

What we're looking for 

  • Bachelor's degree in engineering or a related field, with at least 3 years of hands-on professional experience in vulnerability research, vulnerability management, product
    security, or application security
  • Extensive knowledge of software vulnerabilities, triage, and prioritization, including deep familiarity with the associated standards and technologies (CVE, CWE, CVSS, EPSS,
    PURLs, NVD, OSV, VEX, SBOM formats)
  • Hands-on experience building production-grade solutions at enterprise scale — e.g., CI/CD automation, management of SAST/SCA findings, or comparable security tooling
    deployed across large engineering organizations
  • Demonstrated experience shipping AI/agentic systems to production — LLM pipelines, agent frameworks, tool use, prompt and eval design — with a clear track record of
    measuring output quality and a sound sense of where these approaches hold up and where they don't
  • Proficiency in reading and analyzing code across multiple languages (Python, JavaScript/TypeScript, Java, Go), and comfort reasoning about patches, root causes,
    and exploitability
  • Experience producing external security communications: blog posts, advisories, or technical reports intended for a public or customer-facing audience

Nice to have

  • Experience writing proof-of-concept exploits, or with fuzzing, static analysis, or automated vulnerability discovery
  • Contributions to open source vulnerability databases, scanners, or related tooling (OSV, osv-scanner, OpenVEX, etc.)
  • Familiarity with SAST, SCA, and DAST tooling and the realities of triaging their output at scale
  • Understanding of software supply chain security standards and frameworks (SLSA, SSDF, etc.)
  • Prior public research, CVE credits, or published vulnerability findings
  • Security certifications such as OSCP, OSCE, or equivalent

At Endor Labs, we:

  • Strive for excellence in everything we do, prioritizing quality, speed, and impactful outcomes.
  • Engage in first principles thinking to debate ideas, test assumptions, and make decisions.
  • Put data above opinions, seeking truth and clarity in all our endeavors.
  • Embrace a culture of feedback and continuous improvement, assuming good intent in all interactions.
  • Celebrate wins as a team, understanding that our collective success is intertwined with the success of our customers.
Prêt à postuler chez Endor Labs ?
Postuler chez Endor Labs

Emplois similaires

CA
Security Engineer 3 - Vulnerability Management
Careers at Tide
⚡ Postuler tôt India, Bengaluru Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 4 j
Cognite - AI for Industry
Principal Information Security Engineer (AI Product/Cyber Security + SecOps)
Cognite - AI for Industry
⚡ Postuler tôt India (Bengaluru) Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 4 j
Okta
Staff Software Engineer, Security
Okta
⚡ Postuler tôt Bengaluru, India Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 6 j
Endor Labs
Senior Product Security Engineer
Endor Labs
⚡ Postuler tôt Bengaluru, India Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 1 sem.
Netskope
Staff Engineer DevOps, Data Security (DLP)
Netskope
⚡ Postuler tôt Bengaluru, Karnataka, India Hybride
● Nouveau 👁 Vu ✓ Postulé il y a 1 sem.
Okta
Staff Site Reliability Engineer, Security- GCP
Okta
⚡ Postuler tôt Bengaluru, India Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 1 sem.
Point72
Network Security Engineer
Point72
⚡ Postuler tôt Bengaluru, India Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 1 sem.
Harness
Senior Security Engineer - Customer Engineering
Harness
⚡ Postuler tôt Bengaluru, Karnataka, India Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 2 sem.
NETGEAR
Engineer IV, Product Security
NETGEAR
⚡ Postuler tôt Bengaluru, India Hybride
● Nouveau 👁 Vu ✓ Postulé il y a 2 sem.

Inscrivez-vous pour des suggestions adaptées aux emplois que vous ouvrez et aux recherches que vous enregistrez.

Plus d’emplois chez Endor Labs

Voir tous les emplois chez Endor Labs →

Postuler maintenant
🤖

Doucement — un instant

JobsRadar a été conçu pour de vraies personnes qui traversent une période difficile dans leur recherche d’emploi — pas pour des requêtes automatisées. Vous cliquez beaucoup trop vite et vous êtes maintenant temporairement bloqué.

Revenez plus tard. Si vous cherchez réellement un emploi, nous sommes de votre côté — agissez simplement comme un être humain.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Prenez une longueur d’avance dans votre recherche d’emploi.

Rejoignez notre canal Telegram pour ce qui vous aide à décrocher le poste — références salariales, le pouls hebdomadaire du marché et les annonces de nouveautés. Pas de spam, que du signal.

Rejoindre le canal — c’est gratuit