Remote Staff Security Engineer, Vulnerability Operations

at 6sense

Posted 3 days ago 2 applied

Description:

  • 6sense is seeking a Staff Security Engineer for Vulnerability Operations to lead the end-to-end vulnerability management program across application, infrastructure, and cloud security domains.
  • The role involves driving detection, triage, remediation, and reporting workflows while collaborating with engineering, product, and GRC teams to implement secure-by-design practices.
  • Key responsibilities include owning the vulnerability lifecycle, building automation pipelines for vulnerability detection and response, defining and tracking KPIs/OKRs, collaborating cross-functionally to embed security into SDLC and CI/CD pipelines, optimizing processes for vulnerability triage and remediation, and mentoring junior engineers.

Requirements:

  • Candidates must have 8+ years of experience in security engineering, with a strong focus on vulnerability management.
  • A solid background in Application Security (AppSec), Infrastructure Security (InfraSec), and Cloud Security (CloudSec), preferably with AWS experience, is required.
  • Hands-on experience with Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), container scanning, and Infrastructure as Code (IaC) security is necessary.
  • Familiarity with security frameworks such as NIST, MITRE ATT&CK, and OWASP is essential.
  • Strong scripting and automation skills in languages like Python and Bash are required.
  • Excellent communication and stakeholder management skills are a must.

Benefits:

  • The position offers a base salary range of $210,000 - $316,000, with actual salaries varying based on factors like work location and experience.
  • 6sense provides generous health insurance coverage, life and disability insurance, a 401K employer matching program, paid holidays, self-care days, and paid time off (PTO).
  • Full-time employees can also take advantage of paid parental leave, stock options, and access to learning and development initiatives, including LinkedIn Learning.
  • The company promotes employee well-being through quarterly wellness education sessions and various events celebrating diversity and personal growth.