Security Engineer - Vulnerability Management

Posted 7 Days Ago
Be an Early Applicant
Bengaluru, Bengaluru Urban, Karnataka, IND
In-Office
Senior level
Artificial Intelligence • Cloud • Machine Learning • Security • Software • Cybersecurity • Big Data Analytics
Ship secure software fast with clarity on what matters and AI-powered remediation that scales.
The Role
Advance a proprietary vulnerability database by improving AI pipelines for vulnerability validation, reachability analysis, exploit generation, triage, enrichment, and prioritization. Analyze vulnerabilities, collaborate with zero-day researchers, automate discovery workflows, integrate findings into security pipelines, and author public-facing blogs, advisories, and technical reports. The role requires vulnerability research, production security tooling, AI systems, code analysis, and security communication expertise.
Summary Generated by Built In
Who we are

Our mission is to help developers and AppSec teams spend more time accelerating development and less time dealing with security issues. Watch our 3 min pitch from our Founder & CEO here: https://www.youtube.com/watch?v=B0wmZBcPkFE

Endor Labs has been recognized as a Gartner Cool Vendor, a RSA Innovation Sandbox finalist, and a Black Hat Innovation Spotlight finalist, all in its first year from launch.

The company was founded by Varun Badhwar and Dimitri Stiliadis, who have created multiple category-defining cloud security companies. We have raised $70M in Series A funding and assembled a team of the world’s leading static analysis experts and enterprise software veterans to increase developer productivity and open source software adoption.

What you’ll do
  • The primary focus of this position is to help the team further advance Endor Labs'proprietary vulnerability database — extending and improving our existing AI pipelines,
    e.g., in the areas of automated vulnerability validation, reachability analysis, and exploit generation.
  • Day-to-day work includes monitoring and managing pipelines that triage, enrich, and prioritize vulnerabilities at scale, working with the standards and data sources the
    ecosystem is built on (CVE, CWE, CVSS, EPSS, PURL, NVD, OSV, GHSA, VEX) and continuously improving the accuracy, coverage, and timeliness of our data.
  • You will work hand-in-hand with our world-class 0-day researchers to scale automated vulnerability discovery — turning manual research workflows into repeatable,
    production-grade systems.
  • You will investigate high-impact vulnerabilities and the vulnerability landscape at large, and author external-facing content — blog posts, technical write-ups, and advisories —
    communicating findings clearly to both technical and non-technical audiences.
  • You will collaborate with internal teams to feed findings into detection and analysis pipelines, enrich our vulnerability database, and help improve automated coverage over
    time
What we're looking for 
  • Bachelor's degree in engineering or a related field, with at least 3 years of hands-on professional experience in vulnerability research, vulnerability management, product
    security, or application security
  • Extensive knowledge of software vulnerabilities, triage, and prioritization, including deep familiarity with the associated standards and technologies (CVE, CWE, CVSS, EPSS,
    PURLs, NVD, OSV, VEX, SBOM formats)
  • Hands-on experience building production-grade solutions at enterprise scale — e.g., CI/CD automation, management of SAST/SCA findings, or comparable security tooling
    deployed across large engineering organizations
  • Demonstrated experience shipping AI/agentic systems to production — LLM pipelines, agent frameworks, tool use, prompt and eval design — with a clear track record of
    measuring output quality and a sound sense of where these approaches hold up and where they don't
  • Proficiency in reading and analyzing code across multiple languages (Python, JavaScript/TypeScript, Java, Go), and comfort reasoning about patches, root causes,
    and exploitability
  • Experience producing external security communications: blog posts, advisories, or technical reports intended for a public or customer-facing audience
Nice to have
  • Experience writing proof-of-concept exploits, or with fuzzing, static analysis, or automated vulnerability discovery
  • Contributions to open source vulnerability databases, scanners, or related tooling (OSV, osv-scanner, OpenVEX, etc.)
  • Familiarity with SAST, SCA, and DAST tooling and the realities of triaging their output at scale
  • Understanding of software supply chain security standards and frameworks (SLSA, SSDF, etc.)
  • Prior public research, CVE credits, or published vulnerability findings
  • Security certifications such as OSCP, OSCE, or equivalent
At Endor Labs, we:
  • Strive for excellence in everything we do, prioritizing quality, speed, and impactful outcomes.
  • Engage in first principles thinking to debate ideas, test assumptions, and make decisions.
  • Put data above opinions, seeking truth and clarity in all our endeavors.
  • Embrace a culture of feedback and continuous improvement, assuming good intent in all interactions.
  • Celebrate wins as a team, understanding that our collective success is intertwined with the success of our customers.

Skills Required

  • Bachelor's degree in engineering or a related field
  • At least 3 years of professional experience in vulnerability research, vulnerability management, product security, or application security
  • Extensive knowledge of software vulnerabilities, triage, prioritization, and standards including CVE, CWE, CVSS, EPSS, PURLs, NVD, OSV, VEX, and SBOM formats
  • Experience building production-grade enterprise-scale solutions, such as CI/CD automation, SAST/SCA finding management, or comparable security tooling
  • Experience shipping AI or agentic systems to production, including LLM pipelines, agent frameworks, tool use, prompt design, evaluation design, and output-quality measurement
  • Proficiency reading and analyzing code in Python, JavaScript or TypeScript, Java, and Go
  • Ability to reason about patches, root causes, and exploitability
  • Experience producing public or customer-facing security communications, including blog posts, advisories, or technical reports
  • Experience writing proof-of-concept exploits, fuzzing, static analysis, or automated vulnerability discovery
  • Contributions to open-source vulnerability databases, scanners, or related tooling
  • Familiarity with SAST, SCA, and DAST tooling and large-scale triage
  • Understanding of software supply chain security standards and frameworks such as SLSA and SSDF
  • Prior public research, CVE credits, or published vulnerability findings
  • Security certification such as OSCP, OSCE, or equivalent
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Palo Alto, CA
160 Employees
Year Founded: 2021

What We Do

At Endor Labs, we’re building the modern Application Security platform for the AI-driven era of software development. Our mission is simple but bold: help every organization ship secure software fast with clarity on what matters, and the power to fix it quickly. Today’s AppSec teams are buried in noisy alerts and fragmented tools, while developers race to innovate using open source and AI-generated code. This gap between speed and security puts both innovation and trust at risk. Endor Labs bridges that gap. We unify intelligent code reviews, static analysis, and guided remediation into one connected platform that gives security teams visibility and developers clear, actionable fixes without slowing them down. Our technology deeply analyzes how your software actually works, building a complete graph across first-party, open-source, and AI-generated code. With this context, Endor Labs filters out 92 % of false positives and surfaces the risks that truly matter. Developers can fix vulnerabilities six times faster, automate reviews with AI, and even enable guardrails for AI coding assistants to write secure code by default. We’re trusted by organizations like OpenAI, Snowflake, Peloton, Dropbox, Robinhood, and Rubrik to secure some of the most advanced codebases in the world. Backed by top investors including Lightspeed Venture Partners, DFJ Growth, Coatue, Salesforce Ventures, Dell Technologies Capital, and Citi Ventures, Endor Labs is one of the fastest-growing companies in cybersecurity. But beyond our technology, what truly sets Endor Labs apart is our culture of builders. We’re a team of passionate engineers, researchers, and security experts, over a third with PhDs, united by curiosity, rigor, and the belief that great engineering and great security go hand in hand. We move fast, value craft, and empower each other to innovate boldly while staying grounded in impact.

Why Work With Us

We’re a team of curious builders redefining software security for the AI era. Our culture values ownership, collaboration, and bold thinking where every employee has the freedom to innovate and the support to thrive.

Gallery

Gallery

Similar Jobs

Samsara Logo Samsara

Security Engineer

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
4000 Employees

Tide Logo Tide

Security Engineer

Fintech • Software • Financial Services
In-Office
Bengaluru, Bengaluru Urban, Karnataka, IND
1558 Employees

Guidewire Software Logo Guidewire Software

Security Engineer

Cloud • Information Technology • Insurance • Software • Analytics
In-Office
Bangalore, Bengaluru Urban, Karnataka, IND
3400 Employees

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account