Sr Technical Security Engineer - Vulnerability Management
Listed on 2026-02-16
-
IT/Tech
Cybersecurity -
Engineering
Cybersecurity
Overview
Yahoo serves as a trusted guide for hundreds of millions of people globally, helping them achieve their goals online through our portfolio of iconic products. For advertisers, Yahoo Advertising offers omnichannel solutions and powerful data to engage with our brands and deliver results.
A Little About UsIt takes powerful technology to connect our brands and partners with an audience of hundreds of millions of people. Whether you're looking to write mobile app code, engineer the servers behind our massive ad tech stacks, or develop algorithms to help us process trillions of data points a day, what you do here will have a huge impact on our business—and the world.
AboutOur Team
When you impact millions of people every day, you become a large target for adversaries of all types within all layers of the stack. Our job is to keep our users safe and make Yahoo one of the safest places on the Internet. The Vulnerability & Controls Operations team finds, triages, and tracks security weaknesses across infrastructure and cloud environments. We identify high-risk issues like zero-day vulnerabilities and cloud exposures.
ALot About You
We are looking for a Senior Security Engineer to serve as the Program Lead for Vulnerability Management. This is a hybrid role that requires strong engineering skills and operational leadership. You will be the engine behind the scenes. You will identify and drive mitigation of vulnerabilities, manage requirements for automation, oversee vendor relationships, and utilize large datasets to identify risks.
You will also stand on the front lines. You must have critical vulnerability handling experience. When a major threat emerges you will help lead the coordination and response. You will work alongside analysts, engineers, and senior leadership to manage these remediation efforts.
Key Responsibilities- Direct the coordination and remediation of high-severity security vulnerabilities.
- Manage the process from detection, assessment, communication, remediation coordination of security vulnerabilities.
- Use Databricks to parse and analyze massive datasets in order to address vulnerabilities across the company.
- Identify vulnerability trends across the company and create reports for senior leadership.
- Oversee the technical requirements for vulnerability scanning vendors.
- Configure scanners to match our changing environment and manage the vendor relationship to attain the features required.
- Perform vulnerability scan, analysis, validation and remediation activities.
- Validate vulnerabilities discovered through scans and code analysis.
- Prioritize risks based on the specific context of the Yahoo environment, distinct mitigating factors, and assessment of the impacts of internal and external threat factors.
- Own, maintain, and create the operational process documentation and vulnerability handling runbooks regarding program execution.
- Work with product teams, developers, and system administrators to explain security risks, and provide remediation guidance for vulnerabilities.
- Provide security subject matter expertise to Yahoo product teams including developers and system administrators.
- Watch public and proprietary sources for vulnerability information.
- Assess the impact of zero-day threats and recommend immediate action.
- Research and assess new threats, vulnerability security trends and security alerts, recommend remedial action.
- Develop metrics and dashboards for vulnerability management functions.
- Perform technical and non-technical compliance activities, as needed.
- Participate in an on-call rotation and provide after-hours support to drive the resolution of critical vulnerability handling.
- Bachelor's degree in a technical discipline (i.e., Computer Science, Engineering, Information Security) or equivalent practical experience.
- 7+ years of experience in information security, specifically within vulnerability management or security engineering.
- Strong understanding of common application, network, and OS vulnerabilities (Linux, Windows and OSX), patching, and attack patterns.
- Proven experience driving critical vulnerability remediation activities.
- Ability to lead coordination with stakeholders during high-pressure vulnerability remediation efforts.
- Extensive experience with core vulnerability management scanners (i.e., Tenable, Nexpose, Qualys, AWS Inspector, GCP SCC, Github Advanced Security).
- Experience with various vulnerability assessment solutions, vulnerability management, patch management, software development life cycle (SDLC), host based security systems, networking, systems administration, application development, cloud computing and information security best practices.
- Strong understanding of AI and AI prompting. You must be proficient in using AI tools to assist with coding, automation, and complex problem-solving.
- Proficiency with data analysis platforms. You should have experience using Databricks or similar tools to query and visualize large datasets to prioritize impactful…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).