Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Security Engineer, Vulnerability Management

$188k - $275k

CoreWeave

CoreWeave is The Essential Cloud for AI. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence. Trusted by leading AI labs, startups, and global enterprises, CoreWeave combines superior infrastructure performance with deep technical expertise to accelerate breakthroughs and turn compute into capability. Founded in 2017, CoreWeave became a publicly traded company (Nasdaq: CRWV) in March 2025. Learn more at .What You’ll Do:We are seeking a Staff Security Engineer to lead the most complex technical work in CoreWeave’s Vulnerability Management program. You will design and implement scalable triage, prioritization, and remediation-tracking systems across application, infrastructure, and hardware domains. You will set technical standards, drive high-impact initiatives, and mentor engineers through technical leadership, while partnering with leadership on priorities and execution risks.About the role:Lead high-complexity VM technical initiatives and deliver architecture decisions for assigned program areasDesign and build scalable triage automation, including integrations, decision logic, and production hardeningImplement end-to-end workflow components from assessment and detection to ticket routing and remediation trackingProvide deep technical leadership on hardware-adjacent vulnerabilities (GPU firmware, DPU firmware/BlueField, and BMC surfaces)Act as senior technical responder for embargoed disclosures and zero-day events, coordinating with owner teams that deploy fixesImprove prioritization logic, severity models, and exception workflows through code, design reviews, and technical proposalsProduce actionable technical metrics and risk insights for leadership consumptionLead root-cause analysis for high-impact vulnerability incidents and implement durable technical improvementsMentor IC3/IC4/IC5 engineers through design guidance, code review, and incident coachingPartner with security, engineering, and operational stakeholders to improve workflow reliability and accelerate remediation outcomesWho You Are: 9+ years of relevant experience with demonstrated strategic impact in vulnerability management, application security, platform security, or cloud security engineeringProven track record building and scaling security automation (SOAR workflows, AI/ML systems, detection pipelines) in production environmentsDeep subject matter expertise with vulnerability management best practices: CVSS, EPSS, CISA KEV, threat intelligence integration, and risk-based prioritization frameworksExcellent development background with strong coding skills in Python, Go, or similar languages for building scalable, production-grade security systemsSignificant experience with modern vulnerability management tooling (for example Wiz, Semgrep, Rapid7, Tenable, or equivalent)Experience with specialized infrastructure: GPU/DPU environments, firmware security, hardware vulnerabilities, or high-performance computingDemonstrated track record mentoring engineers across levels and driving cross-functional technical initiatives at organizational scaleStrong business acumen and understanding of how security decisions impact engineering velocity, customer trust, and business outcomesPreferred:Practical experience building AI/ML-powered security systems (LLM integration, automated decision-making, human-in-the-loop validation) in productionExperience managing hardware vendor security partnerships (embargoed disclosures and pre-release collaboration)Production experience with security automation platforms such as TINES and serverless frameworks (AWS Lambda, GCP Cloud Functions)Strong DevOps, DevSecOps, or SRE background with deep experience in AWS/GCP/Azure cloud services and Infrastructure as Code (Terraform, CloudFormation)Deep understanding of Kubernetes security (container scanning, admission controllers, supply chain security, runtime protection)Experience leading security programs through rapid hypergrowth (10x+ infrastructure scaling) in startup or cloud-native environmentsPractical experience managing vulnerabilities within a FedRAMP-certified environment or similar regulatory frameworksWhy CoreWeave?At CoreWeave, we work hard, have fun, and move fast! We’re in an exciting stage of hyper-growth that you will not want to miss out on. We’re not afraid of a little chaos, and we’re constantly learning. Our team cares deeply about how we build our product and how we work together, which is represented through our core values: Be Curious at Your CoreAct Like an OwnerEmpower EmployeesDeliver Best-in-Class Client ExperiencesAchieve More TogetherWe support and encourage an entrepreneurial outlook and independent thinking. We foster an environment that encourages collaboration and enables the development of innovative solutions to complex problems. As we get set for takeoff, the organization's growth opportunities are constantly expanding. You will be surrounded by some of the best talent in the industry, who will want to learn from you, too. Come join us! The base salary range for this role is $188,000 to $275,000. The starting salary will be determined based on job-related knowledge, skills, experience, and market location. We strive for both market alignment and internal equity when determining compensation. In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program (all based on eligibility). What We OfferThe range we’ve posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and location.In addition to a competitive salary, we offer a variety of benefits to support your needs. The benefits below reflect our US-based offerings for full-time employees; for roles in other locations, benefits vary and are shared during the hiring process. These include:Medical, dental, and vision insurance - 100% paid for by CoreWeaveCompany-paid Life Insurance Voluntary supplemental life insurance Short and long-term disability insurance Flexible Spending AccountHealth Savings AccountTuition Reimbursement Ability to Participate in Employee Stock Purchase Program (ESPP)Mental Wellness Benefits through Spring Health Family-Forming support provided by CarrotPaid Parental Leave Flexible, full-service childcare support with Kinside401(k) with a generous employer matchFlexible PTOCatered lunch each day in our office and data center locationsA casual work environmentA work culture focused on innovative disruptionCalifornia ApplicantsCalifornia Consumer Privacy Act Equal Opportunity & AccommodationsCoreWeave is an equal opportunity employer, committed to fostering an inclusive and supportive workplace. All qualified applicants and candidates will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information.As part of this commitment and consistent with the Americans with Disabilities Act (ADA), CoreWeave will ensure that qualified applicants and candidates with disabilities are provided reasonable accommodations for the hiring process, unless such accommodation would cause an undue hardship. If reasonable accommodation is needed, please contact: View email address on click.appcast.io Control ComplianceThis position requires access to export controlled information. To conform to U.S. Government export regulations applicable to that information, applicant must either be (A) a U.S. person, defined as a (i) U.S. citizen or national, (ii) U.S. lawful permanent resident (green card holder), (iii) refugee under 8 U.S.C. § 1157, or (iv) asylee under 8 U.S.C. § 1158, (B) eligible to access the export controlled information without a required export authorization, or (C) eligible and reasonably likely to obtain the required export authorization from the applicable U.S. government agency. CoreWeave may, for legitimate business reasons, decline to pursue any export licensing process.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Staff Security Engineer, Vulnerability Management in New York, NY vacancy
  • $199k - $249k

     ...More than 1,400 firms in nearly 60 countries use Addepar to manage and advise on nearly $9 trillion in assets. Its open...  ...Singapore and São Paulo. The RoleWe are seeking a well rounded Staff Security Engineer to join our growing Information Security & Risk team. In this... 
    Suggested
    H1b
    Remote work
    Worldwide
    Visa sponsorship
    Work visa

    Addepar

    New York, NY
    12 hours ago
  • We’re seeking a team member for the role of SVP, Vulnerability Management & Cloud Security Posture Platform Engineering to join our Cybersecurity Engineering Tools & Platforms team. This role is located in New York, NY; Pittsburgh, PA; or Washington, DC.This is a high-... 
    Suggested
    Work experience placement
    Worldwide
    Flexible hours

    The Bank of New York Mellon

    New York, NY
    4 days ago
  • $82.6k - $162.8k

     ...Continuous Threat Exposure Management (CTEM) team. In this role, you...  ..., and remediating security exposures across complex technology...  ...stakeholders to strengthen vulnerability management and patching processes...  ...you'll do As a Security Engineer II on the Cyber Defense & Resilience... 
    Suggested
    Local area

    Deloitte

    New York, NY
    12 hours ago
  •  ...computers. For the first time ever, you can manage and automate every part of the...  ...The RoleWe're looking for a hands-on staff security engineer to play a key role in building Rippling...  ...about an innovative way to reduce vulnerabilities in your organization What You'll DoBuild... 
    Suggested
    Work at office
    Relocation
    3 days per week
    1 day per week

    Rippling

    New York, NY
    4 days ago
  • $180k - $247k

    Secure Every Identity, from AI to HumanIdentity is the key to unlocking the potential...  ...where Identity belongs to you.The Staff Product Security Engineer OpportunityThe Security team's...  ...on leveraging AI to uncover vulnerabilities, automate root cause analysis, automate... 
    Suggested
    Local area
    Worldwide
    Flexible hours

    Okta

    New York, NY
    2 days ago
  • $244k - $305k

    As a Staff Application Security Engineer at Datadog, you'll set technical direction for how we approach...  ...documentationSolid grounding in OWASP Top 10, web vulnerabilities (XSS, injection, access control,...  ...core platforms alongside product managers and engineering teamsAble to... 

    Datadog

    New York, NY
    4 days ago
  • $114.39k - $240.35k

     ...certified and licensed security support to ensure...  ...Information Systems Security Engineer/Analyst provides...  ...planning, risk management, certification and authorization...  ...security risks, vulnerabilities, and threats, and...  ...part time or on-call staff, compensation is proportionately... 
    Full time
    Contract work
    Part time
    Local area
    Remote work

    Noblis

    Atlantic City, NJ
    4 days ago
  • $150k - $250k

     ...HRT) is seeking a curious, innovative Security Engineer to join our Enterprise Security team...  ..., ownership of a comprehensive vulnerability management program, securing SaaS deployments,...  ...valued. HRT is proud of our diverse staff; we have offices all over the globe... 
    Work at office
    Local area
    Immediate start

    Hudson River Trading

    New York, NY
    4 days ago
  • $153.4k - $207.5k

     ...flexibly harness compute, storage, security, and other services from...  ...(IoT), identity and access management, mobile devices,...  ...for an Application Security Engineer to help validate that our services...  ...Knowledge of system security vulnerabilities and remediation techniques,... 
    Internship
    Flexible hours

    Amazon

    New York, NY
    4 days ago
  • $169k - $199k

     ...standards, clear accountability, and a strong focus on security and ethics in everything we build!The Red Team’s mission...  ...simulating adversary behavior and testing defenses. As a Staff Offensive Security Engineer, you will plan and execute security assessments across applications... 
    Work at office
    Shift work
    3 days per week

    Robinhood Financial

    New York, NY
    2 days ago
  • $160k - $190k

     ...Mission or Department OverviewThe newsroom security engineer within Cybersecurity is a hands-on...  ...the Cybersecurity department, you will manage complex projects end-to-end. You will also...  ...strengthen protections for newsroom staff while supporting efficient journalistic... 
    Work at office
    Local area
    Flexible hours

    The New York Times

    New York, NY
    2 days ago
  • $150k - $250k

     ...ARELed by the Chief Information Security Officer (CISO), Technology...  ...for risk, partnering with engineers to architect and design secure...  ...in helping counterparts manage riskRESPONSIBILITIES AND QUALIFICATIONSJob...  ...Engineer, Architect, Vulnerability Manager).Design or... 

    Goldman Sachs

    New York, NY
    4 days ago
  •  ...world’s leading vendor of Cyber Security, facing the most...  ...Description The Sales Engineer will report to the Sales Engineering...  ...business problems. Plan, manage and execute prospect POVs (Proof...  ..., XDR, SIEM/SOC workflows, vulnerability management). ~ Experience... 

    Check Point Software Technologies

    New York, NY
    5 days ago
  • $192.6k - $260.5k

    Amazon's Specialized Businesses Security team is seeking a Security Engineer Manager to lead our Specialized Detections team. This is a forward-driving leadership...  ...no other team at Amazon covers; the first targets vulnerability classes outside the reach of standard Builder... 
    Remote work
    Flexible hours

    Amazon

    New York, NY
    4 days ago
  • DESCRIPTION:Duties: Provide security solutions across a number of...  ...Engage and collaborate with engineers across the business to understand...  ..., Terragrunt, or Helm; managing secrets, keys, and certificates...  ..., or harness; leading vulnerability management programs, implementing... 
    Full time

    JP Morgan Chase

    New York, NY
    3 days ago
  •  ...Job Description Job Description Senior Cybersecurity Engineer – Vulnerability Management & Incident Response Position Overview Our client...  ...incident response operations. This role is ideal for a security professional who enjoys balancing strategic program ownership... 
    Weekend work

    RennerBrown Staffing

    New York, NY
    9 days ago
  • $175k - $250k

     ...the world’s largest alternative asset manager. Blackstone seeks to deliver...  ...edge. Your Team and Role: Blackstone's Security Engineering (SecEng) team is responsible for securing...  ...secure code reviews, penetration testing, vulnerability management, software supply chain... 
    Full time
    Local area

    Blackstone Group

    New York, NY
    1 day ago
  •  ...New York, Washington D.C., London and Amsterdam. Security Engineering is the engineering function inside the Plaid security org that...  ...security-related infrastructure: secure data storage, key management systems, internal identity platform, internal... 
    Full time
    Work experience placement
    Local area

    Plaid

    New York, NY
    15 hours ago
  • $180k - $247.5k

    Secure Every Identity, from AI to HumanIdentity is the key to unlocking the potential of AI. Okta secures AI by building the...  ...'re all in on this mission. If you are too, let's talk.The Staff AI Security Engineer OpportunityIdentity is the key to unlocking the potential of... 
    Local area
    Worldwide
    Flexible hours

    Okta

    New York, NY
    1 day ago
  • $200k - $225k

     ...our team as we help shape a brighter way forward. The Senior Security Engineer, AI Enablement is Security's embedded, full-time...  ...frameworks, such as SPIFFE/SPIRE, or modern non-human identity management. Certifications such as CISSP, OSCP, or GIAC credentials focused... 
    Full time
    Local area
    Immediate start
    Remote work

    Jones Lang LaSalle

    New York, NY
    2 days ago
  • $105.1k - $164.13k

     ...network architecture, design, and security — individuals who are ready...  ...up from traditional network engineering roles to take ownership of...  ...with System Engineers, Program Managers, and cybersecurity...  ...status. For part time or on-call staff, compensation is proportionately... 
    Permanent employment
    Full time
    Contract work
    Part time
    Local area
    Remote work

    Noblis

    Atlantic City, NJ
    3 days ago
  • $152k - $258k

     ...small, highly motivated, and focused on engineering excellence. This organization is for...  ...Compliance (GRC) Engineer to own and scale our security and AI governance compliance posture as...  ...the company's governance and AI management system posture.Identify, assess, and prioritize... 
    Permanent employment
    Temporary work

    X

    New York, NY
    12 hours ago
  • $200k - $225k

    Blackstone is the world’s largest alternative asset manager. Blackstone seeks to deliver compelling returns for institutional and...  ...its competitive edge.Your Team and Role:Blackstone’s Security Engineering (SecEng) Team is responsible for enabling secure software delivery... 
    Full time
    Local area

    Blackstone Group

    New York, NY
    4 days ago
  • $163.94k - $215.18k

    Hi, we're Oscar. We're hiring a Senior Identity and Access Manager to join our Security Team.Oscar is the first health insurance company built...  ...doctor in the family.As an Identity and Access Management Engineer, you will build Oscar's identity and access management disciplines... 
    Full time
    Work at office
    Flexible hours

    Oscar Health Insurance

    New York, NY
    12 hours ago
  •  ...A premier health institution in New York is looking for a Sr. II Security Analyst specializing in vulnerabilities. This role involves conducting security assessments, analyzing security data, and coordinating remediation efforts. Candidates should have a Bachelor's degree... 

    NYU Langone

    New York, NY
    4 days ago
  • $102.6k - $179.25k

    The Cloud Security Engineer - FAB supports the security, resilience, and compliance of FAB (Foundation and Beyond), Wolters Kluwer...  ...emphasizes secure cloud configuration, identity and access management, vulnerability management, and security monitoring, working closely... 
    Full time
    Work at office

    Wolters Kluwer

    New York, NY
    1 day ago
  • $115k - $135k

    ## Lead Security EngineerApplyremote type: Hybridlocations: Atlanta...  ...relationship, and practice management solutions that advisors use...  ...You'll Do:**The Lead Security Engineer is responsible for ensuring...  ...scheduled and on demand vulnerability assessments and develop mitigation... 
    Flexible hours

    AssetMark

    New York, NY
    15 hours ago
  • $83k - $209k

    Senior Cloud Security EngineerAt BNY, our culture allows us to run...  ...President, Cloud Security Engineer to join our Cloud Security team...  ...leadership, posture management, and close partnership with...  ...Kubernetes security, API security, vulnerability management, and cloud-native... 
    Temporary work
    Worldwide
    Flexible hours

    The Bank of New York Mellon

    New York, NY
    1 day ago
  • $83k - $209k

    Cloud Security Engineer At BNY, our culture allows us to run our company better and enables...  ...operational maturity of Cloud Security Posture Management (CSPM) capabilities to identify...  ...security, API security, or vulnerability management is a plus.Strong problem-solving... 
    Temporary work
    Worldwide
    Flexible hours

    The Bank of New York Mellon

    New York, NY
    1 day ago
  • $226k - $339.7k

     ...President to lead our global Cyber Exposure Management / Cyber Engineering & Architecture organization within a...  ...capabilities, shape long-term security architecture strategy, and lead...  ...exposure management capabilities including vulnerability management and attack surface... 
    Full time
    Work at office

    Wolters Kluwer

    New York, NY
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Security Engineer, Vulnerability Management. Be the first to apply!