We're looking for a Cybersecurity Engineer to help us mature our vulnerability management program. You'll join our Cybersecurity team, a skilled group of programmers and security experts dedicated to keeping the firm safe.
Vulnerability management is the focus of this role, but it doesn't tell the whole story—we want a well-rounded engineer whose knowledge spans the different facets of cybersecurity, because that broader perspective is what lets you reason well about real risk and where to spend effort.
Vulnerability management is a well-established part of how we keep the firm safe, and as we grow, we're continuing to invest in it, with a particular focus on automation and on scaling the program to keep pace with an expanding environment.
This is a hands-on, build-heavy role. We want someone with a strong technical foundation who isn't afraid to build something themselves, who has good judgment about what actually matters, and who can explain the "why" behind a risk and its mitigation. Manual triage doesn't scale at our size, so you'll lean on automation, including AI tooling paired with good judgment, knowing where it helps and when we need a human in the loop.
Your work will also include:
- Supporting and improving the vulnerability management lifecycle end to end, from discovery and validation through triage, assignment, remediation tracking, and verification
- Reviewing new findings from automated scanning tools, threat intel, and security advisories, then prioritizing based on real exploitability and exposure rather than severity score alone, so we act on what genuinely matters
- Validating and deduplicating findings across sources, confirming whether an affected product or component is actually present, and routing work to the team that owns the fix
- Measuring scanning coverage and data quality and knowing what isn't being scanned, where scans are stale, and where authentication is failing, rather than assuming coverage is complete
- Driving automation across vulnerability management tooling and processes
- Broadening scanning coverage across asset classes, including evaluating and migrating scanning platforms as needed
- Bringing software inventory and SBOM data into the picture so we can answer where a vulnerable component is used across our software, not just what's running on a given host
- Building dashboards and metrics that measure coverage, SLAs, and progress
- You automate rather than do things by hand, keep your code and configs in version control by default, work comfortably under code review, and care about leaving things maintainable
- You’re comfortable working with data, querying and shaping it, and building and debugging the data pipelines and integrations that stitch messy, inconsistent inputs into something dependable
- You have hands-on vulnerability management experience in a substantial environment, including experience with an automated scanning platform such as Rapid7, Tenable, or Qualys, and an understanding of how scanning, asset inventory, and remediation tracking fit together
- You’re a measured responder who reasons about trade-offs and context, understands threat modeling, and knows not every finding deserves the same urgency
- You follow cybersecurity developments and can tell the difference between an interesting hack and what matters day-to-day
- You understand and practice good personal cybersecurity hygiene, and can talk to others about it
- You’re a clear communicator across audiences, who writes things down so others can follow
- You have a positive and collaborative attitude; You understand that a key component of cybersecurity is bringing others along with you on the journey
If you're a recruiting agency and want to partner with us, please reach out to [email protected]
Skills Required
- Hands-on vulnerability management experience in a substantial environment
- Experience with automated scanning platforms such as Rapid7, Tenable, or Qualys
- Experience driving automation across vulnerability management tooling and processes
- Familiarity with software inventory and SBOM usage for vulnerability analysis
- Comfort working with data: querying, shaping, and building/debugging data pipelines and integrations
- Keep code and configs in version control and work comfortably under code review
- Ability to validate and deduplicate findings, confirm presence of affected components, and route fixes
- Ability to prioritize based on exploitability and exposure rather than severity score alone
- Clear written and verbal communication across technical and non-technical audiences
- Positive, collaborative attitude and ability to bring others along on security initiatives
- Follows cybersecurity developments and practices good personal cybersecurity hygiene
Jane Street Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Jane Street and has not been reviewed or approved by Jane Street.
-
Career-Linked Recognition & Rewards — Pay is considered exceptionally strong across roles, with substantial bonuses in strong years and firm-wide performance sharing. Collaboration is expected and rewarded, reinforcing a team-oriented payout model.
-
Healthcare Strength — Benefits include zero-premium medical, dental, and vision coverage in the U.S., plus access to on-site or concierge primary care, physical therapy, and mental health services. This breadth and convenience signal a robust healthcare offering.
-
Parental & Family Support — Paid parental leave is described as generous, with equipped nursing rooms and backup childcare cited. Family-oriented supports like fertility coverage and elder‑care backup further enhance the package.
Jane Street Insights
What We Do
Jane Street works differently. As a liquidity provider and market maker, we trade on more than 200 trading venues across 45 countries and help form the backbone of global markets. Our approach is rooted in technology and rigorous quantitative analysis, but our success is driven by our people. Our bright, beautiful offices in the heart of New York, London, Hong Kong, and Amsterdam are open and buzzing with conversation. We come from many backgrounds and encourage travel between offices to share perspectives. Some of our best ideas come from bumping into a visiting colleague at the office coffee bar. Markets move fast. Staying competitive as we’ve grown has required constant invention—of new trading strategies, technology, and processes. We’ve found this is easier when you hire humble, kind people. They tend to help each other, and prioritize teamwork over titles. We invest heavily in teaching and training. There’s a library and a classroom in every office, because deepening your understanding of something is considered real work. Guest lectures, classes, and conferences round out the intellectual exchanges that happen every day. People grow into long careers at Jane Street because there are always new and interesting problems to solve, systems to build, and theories to test. More than twenty years after our founding, it still feels like we’re just getting started.







