Sr Staff PSIRT Engineer
Listed on 2026-08-05
-
IT/Tech
Cybersecurity -
Engineering
Cybersecurity
Sr Staff PSIRT Engineer
This position requires a technical professional for the investigation of reported security vulnerabilities. The role involves conducting impact analysis, severity scoring, and root cause analysis. The ideal candidate will partner with engineering teams to develop remediations and contribute to the continuous improvement of vulnerability response workflows.
Key Responsibilities
- Conduct technical investigations of reported security vulnerabilities, including reproduction, impact analysis, and severity scoring (CVSS).
- Drive root cause analysis for reported vulnerabilities and partner with product engineering teams to develop and validate remediations.
- Collaborate with product, engineering, legal, privacy, and threat intelligence teams on vulnerability response strategies.
- Engage with customers and security researchers to discuss vulnerability details, mitigation steps, and disclosure timelines.
- Maintain familiarity with industry vulnerability handling standards and organizations such as CNA, NIST, and FIRST.
- Contribute to the continuous improvement of PSIRT workflows, automation, and tooling.
- Perform hotseat duties.
- Draft and publish security advisories.
Required Qualifications
Education:
A BS or MS Degree in Computer Science, Engineering, or Cybersecurity is required.
Experience:
4+ years of experience in product security, application security, or vulnerability research is necessary.
Technical
Skills:
Expertise in Product Security, Application Security, Pen Testing, Vulnerability Triaging, and Vulnerability Assessment is required. Proficiency in reverse engineering, debugging, and secure software development practices is also necessary.
Preferred Qualifications
- Automation and scripting experience (e.g., Python, Go, Bash, or Power Shell).
- Familiarity with CVSS, CVE, and public vulnerability databases.
- Ability to assess the exploitability of complex vulnerabilities.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).