Vulnerability Operations Engineer @CentralSquare Technologies
All Others
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted YDay

[Hiring] Vulnerability Operations Engineer @CentralSquare Technologies

YDay - CentralSquare Technologies is hiring a remote Vulnerability Operations Engineer. πŸ’Έ Salary: unspecified πŸ“Location: USA

Role Description

CentralSquare is seeking a Vulnerability Operations (VulnOps) Engineer to join our Security team. This is an individual contributor role purpose-built for the post-AI era of vulnerability discovery - where AI models can now find and exploit flaws at machine speed, and reactive patch cycles are no longer sufficient. This role is not an advisory function. The VulnOps Engineer owns the full pipeline from discovery through fix delivery utilizing AI-powered scanning.

  • Proactive Vulnerability Discovery
    • Operate and continuously improve an AI-powered scanning pipeline across CentralSquare's infrastructure components.
    • Use Kiro and Orca to conduct ongoing vulnerability assessments.
    • Apply reachability analysis to distinguish genuinely exploitable vulnerabilities from theoretical findings, reducing alert fatigue and focusing remediation effort where risk is real.
    • Monitor threat intelligence feeds, CVE disclosures, and coordinated disclosure programs (including Project Glasswing patch releases) to identify newly disclosed vulnerabilities affecting CentralSquare's software supply chain.
  • Fix Development and Delivery
    • Develop and validate fixes and/or configuration changes using AI coding agents such as Claude Code, verifying resolution without regressions before submission.
    • Collaborate with application and infrastructure teams, providing technical context and responding to questions about proposed changes.
  • SLA Ownership and Reporting
    • Own the end-to-end SLA lifecycle for all open findings, maintaining real-time tracking of detection, fix submission, and remediation status in the vulnerability management system.
    • Proactively escalate findings approaching SLA breach with remediation options and risk context.
    • Produce regular reporting on SLA adherence, remediation velocity, and open risk posture for the security leadership team.
  • Toolchain and Pipeline Maintenance
    • Own the configuration, tuning, and operational health of VulnOps tooling including Orca, Claude Code, and Azure DevOps security integrations.
    • Evaluate and recommend new tools and capabilities as the AI security tooling landscape evolves.
  • Cross-Functional Collaboration
    • Work closely with application engineering, DevOps, and infrastructure teams to ensure fix delivery and implementation is efficient and minimally disruptive to production environments.
    • Provide security guidance to engineering teams in the context of AI-accelerated vulnerability discovery.
    • Partner with the Risk and Compliance team to ensure vulnerability data and SLA metrics align with audit and regulatory reporting requirements (NIST CSF, PCI DSS, CJIS).
    • Perform other duties as assigned.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, or Information Technology, or equivalent professional experience.
  • 5–7 years of professional experience in vulnerability management, or a security engineering role.
  • Demonstrated hands-on experience using AI coding agents (Claude Code or equivalent) to find, evaluate, and generate fixes for vulnerabilities.

Requirements

  • Experience with cloud security posture management; direct experience with Orca preferred.
  • Strong understanding of reachability analysis and the ability to apply it to distinguish exploitable findings from theoretical risk.
  • Familiarity with dependency and supply chain security concepts, including SBOM generation and management.
  • Working knowledge of common vulnerability classes (injection, memory corruption, authentication flaws, insecure deserialization, etc.) and their remediation patterns.
  • Understanding of security frameworks including NIST CSF and CIS Controls.

Benefits

  • Competitive compensation and a benefits package designed to support your life inside and outside of work.
  • Tuition reimbursement.
  • Parental leave.
  • Paid volunteer hours.
  • Unlimited PTO.
  • Flexible work environment.

CJIS Clearance

A required part of the onboarding process for this role involves obtaining CJIS (Criminal Justice Information Services) clearanceβ€”a critical credential for safeguarding public safety data. At CentralSquare, we’ll stand with you every step of the way to secure this clearance should you be selected for hire. As part of the process, a comprehensive background check will be conducted, and please note that U.S. citizenship or permanent residency is generally required to obtain CJIS clearance.

Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Vulnerability Operations Engineer @CentralSquare Technologies
All Others
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted YDay
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 140,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 140,000+ Remote Jobs
Γ—

Apply to the best remote jobs
before everyone else

Access 140,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews
Unlock All Jobs Now

Maybe later