Browse by Job TypeBrowse by SkillsRemote Company List
Sign In
Sign Up
Back to all jobs

Platform Security Vulnerability Management Engineer

Remote, Any, United States, AMER
USD $149,927.34~$179,920
About the Role
Fivetran is building data pipelines to power the modern data stack for thousands of companies. To support building customer trust in our solution, we’re looking for a Platform Security Vulnerability Management Engineer to join Fivetran's Security team. In this role you will work hands on with the team lead to collect, verify, and track platform security vulnerabilities to remediation.
This work is challenging and diverse as Fivetran is a multi-cloud environment operating on AWS, GCP, and Azure. You will be on the team responsible for selecting security tools to detect issues, establishing processes to handle incoming issue reports, run our vendor-supported penetration testing program, design and manage the analysis and triage process, prioritize issues, and create reports, metrics, and dashboards to motivate the engineering organization to address the findings, ultimately raising our security posture while meeting compliance requirements.
This is a full-time position based out of the U.S. and is open to the remote workforce.
Technologies You’ll Use
Bash, Python, JS, BigQuery, Sigma, Looker, Retool, Azure, AWS, GCP, Terraform, Docker, Kubernetes, Github, Buildkite, Sonar, SAST, SCA, DAST, WAF, ASPM, CSPM
What You’ll Do
  • Collaborate with engineering teams during our semi-annual vendor-led pentesting engagement, including verification of results and pursuit of remediation 
  • Assist in the manage both Cloud Infrastructure and Application Security vulnerabilities from a variety of sources: Internal/External Reports, SAST, SCA, Sonar, DAST, Pentesting, Security Scorecard, CSPM, and Incidents
  • Analyze, validate, demonstrate, and adjust severity of vulnerabilities based on actual risk to the organization
  • Document guidance to provide clarity about our vulnerability reporting and remediation processes
  • Refine the secure coding and secure cloud configuration guidance and standards provided to engineers
  • Assisting with evaluation and management of tools for detecting and managing security vulnerabilities
  • Take a “hands-on” approach to build automated integrations with security tools, as well as solutions to inventory, monitor, and report on vulnerability process maturity to leadership and other stakeholders
Skills We’re Looking for
  • Experience with a thriving vulnerability management team and program that includes both Application Security and Cloud Security components
  • Strong analytical skills to determine metrics and reports needed to drive action for both the team and the engineering organization
  • Ability to conduct root cause analysis against vulnerabilities and determine feasible technical solutions
  • Technical background and ability to write scripts and code to integrate tool APIs with internal ticketing, ASPM/VM, and CI/CD pipeline tools
  • Collaborative experience working closely with product teams, SRE/DevOps, and software engineers to drive adoption of security mindset into processes and SDLC habits
Bonus Skills​
  • Strong understanding of cloud infrastructure and container vulnerability scanning techniques in multi-cloud environments as well as IaC, containers, CSPM security tools such as Lacework, Trivy, Prisma, Qualys, StackRox, AquaSec, Twistlock
  • Ability to manage and perform triage/validation of Application Security vulnerabilities, including those found in the OWASP Top 10 and the Application Security Verification Standard (ASVS)
  • Experience with cloud-native container deployment architecture (Kubernetes, Docker, GKE, EKS, AKS) and IaC automation tools (CloudFormation, Terraform, Ansible, Chef, Puppet or Lambda)
  • Experience running third party penetration tests from contracting through remediation of findings


 Apply this job


New Job Alert

Follow us on
Give a ⭐ on