Senior Security Engineer, Customer Transparency

Posted 22hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior Security Engineer improving customer transparency for Tanium’s AI-powered endpoint management and security platform. Managing vulnerability disclosure, SBOM visibility, bug bounty operations, and security advisories.

Responsibilities:

  • Build and maintain security tooling, leveraging AI where possible to streamline security processes
  • Identify what customers cannot see about their Tanium deployment and partner with Engineering and Product stakeholders to close those gaps
  • Oversee the SBOM and vulnerability management program and provide visibility to internal and external stakeholders
  • Collaborate with customers, partners, and Tanium’s Customer organization to identify customer needs and build systems that solve recurring problems
  • Act as a security technical resource for customer-facing teams by answering security inquiries and escalations, maintaining reusable answers, and interfacing directly with customers when needed
  • Administer Tanium’s bug bounty program, including triaging reports, assessing exploitability and severity, adjudicating duplicates and out-of-scope submissions, recommending awards, and fostering researcher relationships
  • Author and publish Tanium Security Advisories and CVE records, including CWE classification and CVSS scoring
  • Coordinate disclosure timing and embargoes across researchers, customers, partners, and external coordinating bodies

Requirements:

  • Bachelor's Degree in Computer Science, or other relevant degree or equivalent experience
  • 5+ years industry experience (7+ preferred)
  • Experience with product and application security, vulnerability research, or software engineering with a substantial security focus
  • Experience interacting with customers and external security researchers
  • Experience applying AI tooling to security work
  • Experience building tools or data interfaces used by external stakeholders, including support and customers
  • Experience with modern software engineering development and automation tools such as git and CI/CD pipelines
  • Experience determining vulnerability severity and exploitability and their business impact
  • Familiarity with SCA/SBOM tooling and third-party dependency vulnerability management (nice to have)
  • Experience with coordinated vulnerability disclosure, CVE assignment, CVSS, CWE, and CNA operations (nice to have)
  • Experience running or substantially supporting a bug bounty program or VDP (nice to have)
  • Published vulnerability research, credited CVEs, bug bounty findings, open-source security tooling, or conference talks (nice to have)
  • Working knowledge of Tanium products and services (nice to have)
  • Strong understanding of applied cryptography, including encryption, hashing, and secure key management (nice to have)
  • Excellent oral and written communication skills
  • Ability to work in a fast-paced, changing environment

Benefits:

  • Equity awards
  • Medical, dental and vision plan
  • Family planning benefits
  • Health savings account
  • Flexible spending account
  • Transportation savings account
  • 401(k) retirement savings plan with company match
  • Life, accident and disability coverage
  • Business travel accident insurance
  • Employee assistance programs
  • Disability insurance
  • Other well-being benefits
  • 5 days of volunteer time off (VTO)