CoreWeave is going through very significant growth as we scale to support our customers, and we need to build the next generation security tools to help us defend against vulnerabilities as they arise. We are seeking an experienced leader to join our team as Senior Manager, Vulnerability Management. This person is responsible for running, evolving, and operating CoreWeave's vulnerability management program and personnel, working with cross-functional teams as well as peer engineering stakeholders to measure, maintain, and improve the security posture of CoreWeave.
In this role, you will:- Create and oversee the execution of vulnerability management policies and procedures (e.g. patching)
- Establish and meet Service Level Objectives for both enterprise security and product impacting vulnerabilities
- Create and ensure adherence to procedures for notifying both the business and clients (where applicable) about risk and impacts from security vulnerabilities
- Communicate and coordinate with other teams to triage and remediate vulnerabilities in first and third-party software and software dependencies
- Act as a liaison between other teams (Hardware, Application Security, Offensive Security) to appropriately assign, follow, and close security tickets
- Experience establishing and maintaining a vulnerability management program at scale
- Ability to drive a team of vulnerability security engineers and analysts to focus on identifying, triaging, and assisting in remediating vulnerabilities
- Ability to risk assess and distinguish what a critical or high impacting vulnerability is within CoreWeave's environment and drive appropriate remediations across multiple engineering and IT teams when necessary
- Knowledge and experience with the identification and remediation of CVEs within a large infrastructure deployment
- Extensive experience with Linux OS environments
- Hands-on experience managing security tool servers in a large environment, including routine Linux and Windows patching and application patching/upgrades
- Experience managing/troubleshooting server, workstation, local EDR, anti-virus software, and log analysis as it relates to security compliance
- Strong technical background and experience with cyber tooling
- Experience operating and maintaining enterprise-level information security tools
- Proven experience in Systems Administration, including server & workstation troubleshooting
- Knowledge and experience with cloud-based infrastructures and network concepts/protocols
- Familiarity with Linux operating systems
- Security+, Network+ certifications
- Experience with container orchestration technologies such as Kubernetes
- Familiarity with sending Requests for Proposals (RFPs) for new cyber tooling
- Experience creating and presenting technical strategies and solution recommendations
- Experience designing, implementing, and integrating new technologies into existing portfolios
- Experience collaborating with cross-functional teams, including engineering
- Any of the following certifications: GREM, GPEN, GCED, CEH, GSEC, OSCP
Wondering if you're a good fit? We believe in investing in our people, and value candidates who can bring their own diversified experiences to our teams – even if you aren't a 100% skill or experience match.
Why CoreWeave?
At CoreWeave, we work hard, have fun, and move fast! We're in an exciting stage of hyper-growth that you will not want to miss out on. We're not afraid of a little chaos, and we're constantly learning. Our team cares deeply about how we build our product and how we work together, which is represented through our core values:
- Be Curious at Your Core
- Act Like an Owner
- Empower Employees
- Deliver Best-in-Class Client Experiences
- Achieve More Together
We support and encourage an entrepreneurial outlook and independent thinking. We foster an environment that encourages collaboration and enables the development of innovative solutions to complex problems. As we get set for takeoff, the organization's growth opportunities are constantly expanding. You will be surrounded by some of the best talent in the industry, who will want to learn from you, too. Come join us!
The base salary range for this role is $188,000 to $275,000. The starting salary will be determined by job-related knowledge, skills, experience, and the market location. We strive for both market alignment and internal equity when determining compensation. In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program (all based on eligibility).
What We Offer
The range we’ve posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and location.
In addition to a competitive salary, we offer a variety of benefits to support your needs. The benefits below reflect our US-based offerings; for roles in other locations, benefits vary and are shared during the hiring process. These include:
- Medical, dental, and vision insurance - 100% paid for by CoreWeave
- Company-paid Life Insurance
- Voluntary supplemental life insurance
- Short and long-term disability insurance
- Flexible Spending Account
- Health Savings Account
- Tuition Reimbursement
- Ability to Participate in Employee Stock Purchase Program (ESPP)
- Mental Wellness Benefits through Spring Health
- Family-Forming support provided by Carrot
- Paid Parental Leave
- Flexible, full-service childcare support with Kinside
- 401(k) with a generous employer match
- Flexible PTO
- Catered lunch each day in our office and data center locations
- A casual work environment
- A work culture focused on innovative disruption
California Applicants
California Consumer Privacy Act
Equal Opportunity & Accommodations
CoreWeave is an equal opportunity employer, committed to fostering an inclusive and supportive workplace. All qualified applicants and candidates will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information.
As part of this commitment and consistent with the Americans with Disabilities Act (ADA), CoreWeave will ensure that qualified applicants and candidates with disabilities are provided reasonable accommodations for the hiring process, unless such accommodation would cause an undue hardship. If reasonable accommodation is needed, please contact: [email protected].
Export Control Compliance
This position requires access to export controlled information. To conform to U.S. Government export regulations applicable to that information, applicant must either be (A) a U.S. person, defined as a (i) U.S. citizen or national, (ii) U.S. lawful permanent resident (green card holder), (iii) refugee under 8 U.S.C. § 1157, or (iv) asylee under 8 U.S.C. § 1158, (B) eligible to access the export controlled information without a required export authorization, or (C) eligible and reasonably likely to obtain the required export authorization from the applicable U.S. government agency. CoreWeave may, for legitimate business reasons, decline to pursue any export licensing process.
Skills Required
- Experience establishing and maintaining a vulnerability management program at scale
- Experience leading a team of vulnerability security engineers and analysts
- Ability to risk assess and prioritize critical/high-impact vulnerabilities and drive remediation across engineering and IT teams
- Knowledge and experience identifying and remediating CVEs in large infrastructure deployments
- Extensive experience with Linux operating systems
- Hands-on experience managing security tool servers, including routine Linux and Windows patching and application upgrades
- Experience managing/troubleshooting servers, workstations, local EDR, anti-virus software, and performing log analysis for security compliance
- Strong technical background and experience with cyber tooling
- Experience operating and maintaining enterprise-level information security tools
- Proven systems administration experience, including server and workstation troubleshooting
- Knowledge of cloud-based infrastructures and network concepts/protocols
- Security+, Network+ or other security certifications
- Experience with container orchestration technologies such as Kubernetes
- Experience issuing RFPs for new cyber tooling and integrating new technologies
- Experience creating and presenting technical strategies and collaborating with cross-functional teams
- Any of the following certifications: GREM, GPEN, GCED, CEH, GSEC, OSCP
CoreWeave Compensation & Benefits Highlights
-
Healthcare Strength — Health coverage is described as comprehensive, including medical, dental, vision, and mental-health resources. Feedback suggests employer-paid employee premiums and inclusive provisions (such as gender-affirming care) make coverage especially attractive.
-
Retirement Support — Retirement support includes a 401(k) with company matching. Feedback suggests this is a dependable component of the package alongside other financial benefits.
-
Flexible Benefits — Flexible PTO and hybrid/remote options are offered. Feedback suggests flexibility is supported by employer-verified language even as on-site hubs remain important.
CoreWeave Insights
What We Do
CoreWeave, the AI Hyperscaler™, delivers a cloud platform of cutting-edge software powering the next wave of AI. The company's technology provides enterprises and leading AI labs with cloud solutions for accelerated computing. Since 2017, CoreWeave has operated a growing footprint of data centers across the US and Europe. CoreWeave was ranked as one of the TIME100 most influential companies and featured on Forbes Cloud 100 ranking in 2024. Learn more at www.coreweave.com.
Why Work With Us
At CoreWeave we work hard, have fun and move fast! Today we are a small, growing team of intelligent, genuine people, that value different perspectives and approaches to solving complex problems. We foster an environment that champions collaboration and prioritizes innovative solutions. Here, you are surrounded by the best.
Gallery
CoreWeave Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.























