Senior Security Engineer II, Vulnerability Management
$165k - $242kCoreWeave
Senior Security Engineer II, Vulnerability Management
Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence. Trusted by leading AI labs, startups, and global enterprises, CoreWeave combines superior infrastructure performance with deep technical expertise to accelerate breakthroughs and turn compute into capability. Founded in 2017, CoreWeave became a publicly traded company (Nasdaq: CRWV) in March 2025. Learn more at
What You'll Do:
We are seeking a Senior Security Engineer to build the Vulnerability Management program protecting CoreWeave's AI infrastructure. You will architect intelligent automation systems that defend the GPU clusters powering breakthrough AI research and enterprise AI applications. You'll solve security problems at the intersection of cloud-scale infrastructure and specialized hardware—from GPU firmware vulnerabilities to AI-powered threat detection. This role combines technical depth, strategic thinking, and the autonomy to design workflows that will protect infrastructure driving the future of AI.
About the Role:
- Build and scale AI-powered triage workflows: evaluate tools (LLM integration, TINES orchestration), architect solutions, and deploy to production
- Drive intelligent, risk-based vulnerability prioritization while simultaneously training AI models—your assessments become the foundation for automation
- Influence automation priorities: recommend which areas of the vulnerability pipeline would most benefit from automation to improve team efficiency
- Design and implement automated detection-to-ticket pipelines: build workflows that generate vulnerability detections, test them, scale across the environment, and auto-create Jira tickets
- Execute remediation campaigns: build automated workflows for EOL product removal, vulnerable software upgrades, and OS migrations at scale
- Manage embargoed vendor disclosures from hardware partners, including embargo verification and zero-day response coordination
- Lead security incident investigations related to high-profile vulnerabilities, coordinating cross-functional response and impact assessment
- Participate in on-call rotation for rapid-response vulnerability analysis during active zero-day events or critical security incidents
- Partner with IT, Infrastructure, and Engineering teams to drive remediation efforts, enforce SLAs, and escalate blockers strategically
- Write daily operations reports documenting vulnerability trends, remediation velocity, and emerging threats for security leadership
- Drive process improvements and workflow automation to improve operational efficiency and reduce manual toil
Who You Are:
- 7+ years of relevant experience with demonstrated impact in vulnerability management, application security, platform security, or cloud security engineering
- Bachelor's or Master's degree in Computer Science, Computer Engineering, Electrical Engineering, or equivalent practical experience.
- Proven hands-on experience building security automation (SOAR workflows, detection pipelines, or vulnerability prioritization frameworks)
- Deep subject matter expertise with vulnerability management best practices: CVSS, EPSS, CISA KEV, exploit intelligence, and compensating controls
- Strong development background with proficiency in Python, Go, or similar languages for building production-grade security tools
- Experience with modern vulnerability management tooling such as Wiz, Semgrep, Rapid7, or similar platforms
- Demonstrated ability to partner with cross-functional teams (IT, SRE, Engineering) to drive remediation without formal authority
- Strong familiarity with common security vulnerabilities and the ability to judge their severity and business impact
Preferred:
- Practical experience building AI/ML-powered security workflows (LLM integration, automated triage, human-in-the-loop validation)
- Experience managing hardware security vulnerabilities (GPU/DPU firmware, BMC/IPMI, specialized compute environments)
- Production experience with security automation platforms such as TINES, Splunk SOAR, or serverless frameworks (AWS Lambda)
- Strong DevOps, DevSecOps, or SRE background with experience in AWS/GCP/Azure cloud services and Infrastructure as Code (Terraform, CloudFormation)
- Deep understanding of container security and Kubernetes (image scanning, admission control, runtime protection, supply chain security)
- Experience supporting customer audits (SOC 2, ISO 27001, FedRAMP) with vulnerability evidence and control validation
- Experience integrating vulnerability management into modern CI/CD pipelines with a "shift-left" mentality
Wondering if you're a good fit? We believe in investing in our people and value candidates who can bring their diverse experiences to our teams – even if you aren't a 100% skill or experience match. Here are a few qualities we've found compatible with our team. If some of this describes you, we'd love to talk.
You love to:
- Architect and build security systems with full ownership, not just maintain existing tools
- Drive cross-functional initiatives and influence without formal authority
- Mentor engineers and see your automation multiply team impact
You're curious about:
- How to apply AI/ML to vulnerability management at cloud scale
- The intersection of hardware security and cloud infrastructure
- What makes security automation that engineering teams actually adopt
You're an expert in:
- Risk-based vulnerability prioritization and threat modeling
- Building production-grade security automation (SOAR, detection pipelines)
- Balancing security rigor with business velocity
Why CoreWeave?
At CoreWeave, we work hard, have fun, and move fast! We're in an exciting stage of hyper-growth that you will not want to miss out on. We're not afraid of a little chaos, and we're constantly learning. Our team cares deeply about how we build our product and how we work together, which is represented through our core values:
- Be Curious at Your Core
- Act Like an Owner
- Empower Employees
- Deliver Best-in-Class Client Experiences
- Achieve More Together
We support and encourage an entrepreneurial outlook and independent thinking. We foster an environment that encourages collaboration and enables the development of innovative solutions to complex problems. As we get set for takeoff, the organization's growth opportunities are constantly expanding. You will be surrounded by some of the best talent in the industry, who will want to learn from you, too. Come join us!
The base salary range for this role is $165,000 to $242,000. The starting salary will be determined based on job-related knowledge, skills, experience, and market location. We strive for both market alignment and internal equity when determining compensation. In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program (all based on eligibility).
What We Offer
The range we've posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and location.
In addition to a competitive salary, we offer a variety of benefits to support your needs, including:
- Medical, dental, and vision insurance - 100% paid for by CoreWeave
- Company-paid Life Insurance
- Voluntary supplemental life insurance
- Short and long-term disability insurance
- Flexible Spending Account
- Health Savings Account
- Tuition Reimbursement
- Ability to Participate in Employee Stock Purchase Program (ESPP)
- Mental Wellness Benefits through Spring Health
- Family-Forming support provided by Carrot
- Paid Parental Leave
- Flexible, full-service childcare support with Kinside
- 401(k) with
$153k - $214k
...Overview We are excited to welcome a Senior Engineer to join our Vulnerability Management team at 1Password. Vulnerability Management enables us to build and deliver secure products with confidence, owning the end-to-end vulnerability lifecycle from identification to remediation...SeniorShift work- ...Overview As a Senior Security Engineer II for Identity and Access Management (IAM) at Aledade, you will play a central role in enhancing the security posture of our enterprise, cloud-native environments, and applications. We are seeking a dedicated professional with in...SeniorTemporary workRemote workFlexible hours
$225k - $300k
...CLEAR is building THE secure identity company of the future. Our mission is to make experiences safer and easier... ...the magic of frictionless experiences. As a Senior Product Security Engineer, Vulnerability Management on our Product Security team you'll help run and evolve...SeniorCasual workWork at officeFlexible hours$115.5k - $165k
...efficient, resilient, and secure. Our cloud native Zero... ...of cybersecurity. Our Engineering team built the world’s... ..., Tenable.sc / Nessus Manager or similar) Building... ...) 5+ years in Vulnerability Management or Security... ...DoD 8570/8140 IAT Level II certification (e.g., Security+...SuggestedWork at officeLocal areaWorldwide$188k - $275k
...Staff Security Engineer, Vulnerability Management Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA CoreWeave... ..., and BMC surfaces) Act as senior technical responder for embargoed... ...as a (i) U.S. citizen or national, (ii) U.S. lawful permanent resident (green...SuggestedPermanent employmentTemporary workCasual workWork at officeRemote workFlexible hours$153k - $214k
...cybersecurity firm in the United States is seeking a Senior Engineer for its Vulnerability Management team. This role focuses on maturing the vulnerability... ...over 5 years of experience in IT or Engineering with a security focus, including strong skills in bug bounty programs...Senior- ...Overstory is looking for a talented Senior Security Engineer to enhance the company's security and compliance posture. The ideal candidate will lead security initiatives across vulnerability management, compliance, and security operations while collaborating with various...SeniorRemote workFlexible hours
- ...growing technology company in the United States is seeking a Senior Security Engineer to enhance the security of their SaaS platform and... ...frameworks like SOC 2. You will be responsible for conducting vulnerability assessments, securing cloud deployments, and leading...SeniorRemote work
- ...Senior Security Engineer II – Threat Detection & Response Client is seeking a Senior Security Engineer- Detection & Response (Threat-Informed... ...in our defense-in-depth strategy. Advanced Incident Management: Lead the full lifecycle of high-severity security incidents...SeniorImmediate start
- ...updates as new positions become available. Senior Security Engineer - Remote, India - 8AM - 5PM EST At... ...to streamline IT Support and provide managed solutions with a strategic consulting... .... Data Loss Prevention Solutions. Vulnerability Scanners. Responding to and managing...SeniorLocal areaRemote work
- ...Title : Senior Security Engineer Location : Hybrid- New York, NY or Tempe, AZ About Us... ..., empowering more than 1,000 wealth management firms to modernize how they talk about... ...annual SOC 2 audit. Improve our vulnerability and patch management: Create secure...SeniorTemporary workRemote workFlexible hours
$150k - $180k
...CommandLink is seeking a senior security engineer to enhance their product security. You will take ownership of vulnerability management, secrets hygiene, and threat modeling while partnering with engineering teams. Key requirements include at least 8 years of experience...SeniorRemote work- ...Job Description: A Vulnerability Analyst II with a data focus is responsible... ...of vulnerability management data across multiple sources... ...collaborates closely with engineering, application, cloud, and governance... ...management tools, security concepts, and risk-based methodologies...
$138k - $200k
Google is seeking a Technical Vulnerability Management Analyst for its Public Sector team in New York City. This role involves assessing cybersecurity threats, managing vulnerability programs for municipalities, and presenting findings to stakeholders. Candidates should...Senior- DelDOT seeks a Health/Human Service Case Manager II to work in the Division of Social Services’ Change Report Center in Delaware. The successful... ..., and report writing. This position promises to contribute positively to Delaware's vulnerable populations. #J-18808-Ljbffr DelDOTSenior
- ...fintech company in the United Kingdom seeks a security operations expert to enhance incident response and vulnerability management. The role involves responding to security... ...processes, and collaborating with engineering teams to foster a security-first culture. The...Senior
$175k - $200k
...long-term preventive care and condition management. Our model delivers 24/7... ...What you'll do As our first Product Security Engineer , you will sit at the intersection of... ...a system that eliminates a class of vulnerability than manually triage individual alerts...SeniorWork at officeLocal areaRemote work$150k - $175k
...investment bank. Our team of senior professionals delivers... ...investment managers, including private equity... ...improving a robust and secure technology foundation... ...and drive the firm's vulnerability management and patching... ...coordinate fixes directly with engineering and infrastructure...Shift work$209.66k - $220.7k
...Join MoonPay's Product Security Squad MoonPay is a unified payments... ...modelling. We actively manage our Bug Bounty program, ensuring... ...of security services to our Engineering teams including cloud... ...in security automation and vulnerability management, integrating tooling...SeniorRemote workWorldwideHome office$102.6k - $179.25k
...The Cloud Security Engineer - FAB supports the security, resilience, and compliance of FAB (Foundation and Beyond) , Wolters Kluwer... ...secure cloud configuration, identity and access management, vulnerability management, and security monitoring , working closely with...SeniorWork at office- ...everything in between, the security team at TRM is integral... ...aspect of our business. As a Senior Cloud Security Engineer, you will contribute to... ..., configuration management, and environment design Leverage... ...communicate cloud platform vulnerabilities and mitigation options to...SeniorSummer work
- A premier health institution in New York is looking for a Sr. II Security Analyst specializing in vulnerabilities. This role involves conducting security assessments, analyzing security data, and coordinating remediation efforts. Candidates should have a Bachelor's degree...Senior
- ...healthcare technology firm is seeking a Senior Information Security Engineer to protect its cloud-based... ...customer data. You will design and manage security solutions that meet regulatory... ...in cloud security, DevSecOps, and vulnerability management. With responsibilities spanning...SeniorRemote work
- ...Shield AI is seeking a Senior Cyber Engineer, focusing on endpoint security management in a remote capacity. Key responsibilities include deploying security tooling, enforcing configurations, and collaborating with IT teams for integration. The ideal candidate will possess...SeniorRemote work
$180k - $190k
...Senior Security Engineer (DevSecOps) Remote in US (workingండ్ EST hours)รุ่งนี้ Base Pay Range: $180,000.00/yr - $190,000.00/yr No visa sponsorship... ...teams and own critical systems like SIEM and identity management. Requirements 5+ years of experience in security, IT,...SeniorFull timeRemote workVisa sponsorship$180k - $258k
...done by armies of humans who track and manage complex rules and processes specific... ...The Role We're looking for a Senior Security Engineer who is ready to elevate the safety and... ...we remain compliant and informed. Vulnerability Management: Regularly audit our platforms...SeniorFlexible hours- ...including but not limited to Nexus Series (5k/7k/9k), Cisco ACI platform, Catalyst Switches, ISR Routers, Cisco SDWAN and network management tools. Expert understanding of IP multicast routing. Experience working with large trading floor technologies, managing,...SeniorRemote work
- ...PAM administration (EPV, PSM, PVWA, CPM, CCP) Privileged Access Management concepts (vaulting, JIT access, session management, secrets)... ...enterprise applications Enforce privileged access policies and security standards Support audits, access reviews, and risk assessments...SeniorH1bRemote work
- ...Data Streaming Platform. We are looking for an experienced security engineer to join our infrastructure security engineering team with a... ...directly with engineering teams. Contribute to strategy, risk management and prioritization for all efforts around detection and response...Senior
$170k - $300k
...Senior Security Engineer (Remote – US) Compensation: $170K–$300K base + equity... ...identity Conduct threat modeling, vulnerability assessments, and... ...Own and evolve SOC 2 Type II compliance Establish a secure... ...incident response and postmortems Manage identity/access systems (...SeniorFull timeRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Security Engineer II, Vulnerability Management. Be the first to apply!
- staff security engineer New York, NY
- senior application security engineer New York, NY
- sr information security engineer New York, NY
- security engineering manager New York, NY
- security operations engineer New York, NY
- cloud security engineer New York, NY
- azure security engineer New York, NY
- endpoint security engineer New York, NY
- physical security engineer New York, NY
- systems security engineer New York, NY

