Start Your Search Here

push notification bell

Would you like to receive notifications about jobs in San Francisco?

push notification bell

You have blocked notifications

Oops! You have blocked notifications. Click here for more info

You have blocked notifications, please check your browser settings.

push notification bell

You're currently subscribed to job notifications

Want to change your notifications for job alerts?

push notification bell

Subscribe to notifications

You will no longer receive notifications

Job Search

RIT Solutions

San Francisco / Global

Security Engineer

Job Description

Security Engineer - Vulnerability Triage & Automated RemediationThe Security Engineer will join an operational security pod acting as the crucial bridge between automated security scanning/remediation systems and product code owners. The mission of this role is to streamline threat modeling, eliminate triage noise, validate exploitability through reproduction, verify automated/agentic patches, and shepherd open security issues through to verified production resolution.DAY-TO-DAY RESPONSIBILITIESDocument trust boundaries, data flows, and architectural entry points to maintain up-to-date threat profiles for high-priority services.Filter and triage findings from automated source and endpoint scanners, classifying severity and evaluating exception requests.Construct minimal test environments and reproduction harnesses to validate exploitability and eliminate false positives.Supervise and QA code patches generated by automated/agentic remediation tools, running unit and integration tests to check for regressions.Route validated patches to product team code owners and coordinate end-to-end deployment verification within strict SLAs.Conduct code reviews and ensure all fixes comply with secure coding standards (e.g., input validation, memory safety).REQUIRED SKILLSThreat Modeling • Understanding of architectural trust boundaries, attack surfaces, and data flows. • Familiarity with structured threat modeling frameworks (e.g., STRIDE, PASTA).Triage & Policy Management • Working knowledge of common vulnerability classifications (CWE, CVE, OWASP Top 10). • Ability to interpret vulnerability scoring matrices and map findings to strict remediation SLAs.Vulnerability Reproduction • Proficiency in reading and writing code in at least two core languages (C++, Go, Java, Python). • Ability to set up local test harnesses, mock dependencies, and build minimal PoCs.Automated / Agentic Fixer QA • High attention to detail during code reviews (spotting hallucinations, regressions, off-by-one errors). • Understanding of secure coding standards (input validation, boundary checking, safe memory access).CANDIDATE PROFILEAn operational, hands-on Security Engineer with a strong software development background who excels at bridge-building between security automation and product development teams. The candidate should be highly methodical, possessing strong code analysis skills to spot hallucinated or regression-prone automated fixes and validate real-world exploitability.Job ResponsibilitiesMap trust boundaries, data flows, and architectural entry points to maintain standardized threat profiles.Triage findings from automated static and endpoint security scanners, classifying severity and managing exceptions.Build minimal reproduction harnesses and test environments to confirm exploitability and eliminate false positives.Review, test, and QA automated code patches generated by AI/agentic remediation engines, preventing regressions and ensuring compliance with secure coding standards.
Apply Now

Similar Opportunities

View all jobs

Get Job Alerts

Don't miss the perfect fit. Get Daily curated job alerts.

Job Title or Keyword(s)
Location