Vulnerability Operations Engineer - Remote
CentralSquare Technologies
What We're About At CentralSquare , we don't just build software - we power public servants and uplift communities with Hero-Grade Technology. Every line of code, every feature we deliver helps heroes across North America protect, serve, and save lives. When you join us, you become part of a mission-driven team creating technology that makes communities safer and stronger. Your Growth Matters. We believe heroes deserve opportunities to rise. That's why we invest in your career with mentorship, learning programs, and clear paths for advancement. If you're motivated, there's no limit to how far you can go. Your Commitment Deserves Reward. We offer competitive compensation and a benefits package designed to support your life inside and outside of work-tuition reimbursement, parental leave, paid volunteer hours, and unlimited PTO. Plus, our flexible work environment gives you the freedom to balance your heroic work with personal well-being, whether you're in the office or remote. Join us and help build the tools that power real-life heroes. Together, we make a difference. The Role CentralSquare is seeking a Vulnerability Operations (VulnOps) Engineer to join our Security team. This is an individual contributor role purpose-built for the post-AI era of vulnerability discovery - where AI models can now find and exploit flaws at machine speed, and reactive patch cycles are no longer sufficient. This role is not an advisory function. The VulnOps Engineer owns the full pipeline from discovery through fix delivery: running AI-powered scanning against CentralSquare's codebases and dependencies on a continuous basis, generating validated fixes, and submitting ready-to-merge pull requests into owning teams' Azure DevOps pipelines. App teams retain code review and merge authority; this role exists to ensure they are never handed a problem without also being handed a solution. Job Duties Include: Proactive Vulnerability Discovery
Qualifications Education and Experience
Qualifications
- Operate and continuously improve an AI-powered scanning pipeline across CentralSquare's first-party codebases, open-source dependencies, and infrastructure components
- Use Claude Code, Veracode, and Orca to conduct ongoing static analysis, software composition analysis (SCA), and cloud posture assessments
- Apply reachability analysis to distinguish genuinely exploitable vulnerabilities from theoretical findings, reducing alert fatigue and focusing remediation effort where risk is real
- Monitor threat intelligence feeds, CVE disclosures, and coordinated disclosure programs (including Project Glasswing patch releases) to identify newly disclosed vulnerabilities affecting CentralSquare's software supply chain
- Develop and validate fixes (code patches, dependency upgrades, configuration changes) using AI coding agents such as Claude Code, verifying resolution without regressions before submission
- Submit validated fixes as pull requests into owning teams' Azure DevOps repositories, with clear documentation of the vulnerability, risk context, and fix rationale to support efficient review and merge
- Collaborate with application and infrastructure teams during code review, providing technical context and responding to questions about proposed changes
- Own the end-to-end SLA lifecycle for all open findings, maintaining real-time tracking of detection, fix submission, and merge status in the vulnerability management system
- Proactively escalate findings approaching SLA breach with remediation options and risk context
- Produce regular reporting on pipeline health, SLA adherence, remediation velocity, and open risk posture for the security leadership team
- Own the configuration, tuning, and operational health of VulnOps tooling including Veracode, Orca, Claude Code, and Azure DevOps security integrations
- Identify and reduce false positive rates through policy tuning and reachability filtering, ensuring signal quality remains high as scan volume increases
- Contribute to the development of automated remediation pipelines, including AI-assisted fix generation integrated directly into CI/CD workflows
- Evaluate and recommend new tools and capabilities as the AI security tooling landscape evolves
- Work closely with application engineering, DevOps, and infrastructure teams to ensure fix delivery is efficient and minimally disruptive to development velocity
- Provide security guidance to engineering teams on secure coding practices and dependency management in the context of AI-accelerated vulnerability discovery
- Partner with the Risk and Compliance team to ensure vulnerability data and SLA metrics align with audit and regulatory reporting requirements (NIST CSF, PCI DSS, CJIS)
- Perform other duties as assigned
Qualifications Education and Experience
- Bachelor's degree in Cybersecurity, Computer Science, or Information Technology, or equivalent professional experience
- 5-7 years of professional experience in application security, vulnerability management, or a combined security engineering role
- Demonstrated hands-on experience using AI coding agents (Claude Code or equivalent) to find, evaluate, and generate fixes for software vulnerabilities
- Proficiency with SAST and SCA tooling; direct experience with Veracode strongly preferred
- Experience with cloud security posture management; direct experience with Orca preferred
- Working experience with Azure DevOps for CI/CD pipeline integration and pull request workflows
- Ability to read, understand, and write code across at least two languages commonly used in enterprise SaaS environments (e.g., Java, C#, Python, JavaScript/TypeScript, Terraform)
- Strong understanding of reachability analysis and the ability to apply it to distinguish exploitable findings from theoretical risk
- Familiarity with dependency and supply chain security concepts, including SBOM generation and management
- Working knowledge of common vulnerability classes (injection, memory corruption, authentication flaws, insecure deserialization, etc.) and their remediation patterns
- Understanding of security frameworks including NIST CSF and CIS Controls
- Highly systematic and process-driven - capable of managing a high volume of concurrent findings without losing precision or letting items fall through the cracks
- Self-directed and accountable: this role is measured by fix delivery and SLA outcomes, not activity metrics
- Strong written communication skills - fix submissions must include documentation that gives owning teams sufficient context for confident, efficient code review
- Comfortable working across organizational boundaries, earning credibility with engineering teams through technical quality rather than authority
- Able to prioritize effectively under pressure, with clear judgment about when to escalate versus resolve independently
Qualifications
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Vulnerability Operations Engineer - Remote in United States vacancy
$165k - $242k
...Do We are seeking a Senior Security Engineer to build the Vulnerability Management program protecting CoreWeave... ...blockers strategically Write daily operations reports documenting vulnerability... ...prioritize a hybrid work environment, remote work may be considered for...Remote workPermanent employmentTemporary workCasual workWork at officeFlexible hoursShift work- ...A leading cybersecurity company is seeking a Senior Vulnerability Engineer to enhance vulnerability management capabilities. This fully remote position involves designing systems for vulnerability detection and automating workflows while collaborating with various teams...Remote work
- ...Vulnerability Operations Engineer Cloud Engineering/DevOps Vulnerability Operations Engineer | Location: Hybrid (3x on-site) in New York, NY or Charlotte, NC | Contract This Vulnerability Operations Engineer contract role will operationalize vulnerability management...SuggestedContract work
- ...pivotal role in transforming raw tool output into actionable insights. This position focuses on enhancing the vulnerability management operations through engineering, automation, and AI-driven solutions, reducing operational risks and delivering productivity gains across...SuggestedWork experience placementImmediate start
- ...Job Title: Senior Dev Operations Engineer - SRE (CR260) Location: Remote Duration: Long Term MUST HAVES Experience setting up alerts / alarms... ...skills. • Security assessments and addressing vulnerabilities. • Design and deploy AWS solutions using AWS...Remote work
- ...Carriers choose us to scale and operate at unprecedented speed,... ...us. Bestow offers flexible remote/hybrid work, meaningful benefits... ...As our Security Operations Engineer II, you will play an important... .... Support the execution of vulnerability and patch management programs...Remote workWork experience placementWork at officeWork from homeFlexible hours
- ...Monitoring and enhancing security operations, the full-time Security Operations Engineer II will support vulnerability management, incident response, and IAM practices while working remotely. Key responsibilities Monitor, investigate, and respond to security events,...Remote workFull time
- ...We are seeking a Cybersecurity Operations Engineer to run security operations across a holding... ...security strategy, CIS hardening, CASB/DLP, vulnerability management, and continuous pentesting.... ...or training. For roles eligible for remote work, the base salary is tailored to...Remote workFull timeTemporary workLive outWork at officeLocal area
- ...seeking a skilled professional to join their Security Operations team. In this role, you will manage vulnerabilities, conduct security assessments, and build security... ...and non-technical teams. This position offers remote work flexibility along with opportunities for in-office...Remote workWork at office
$91k - $120k
...Cyber Operations Engineer III Through our dedicated associates, Conduent delivers mission-critical... ...that streamline incident response, vulnerability management, and security monitoring.... ...In this role, you can expect: ~ Remote Work: Enjoy the flexibility of working...Remote workWork from homeFlexible hours$40 per hour
...BenefitsThis is a full-time or part-time REMOTE positionYou'll be able to choose which... ...content, including threat analysis, vulnerability assessments, and offensive security techniquesDesign... ...teaming, incident response, detection engineering, DFIR, malware analysis, threat...Remote workHourly payFull timePart time$83.43k - $222.48k
## Senior Adversary Operations EngineerApplyremote type: Remote/Hybridlocations: Work At Home-New Yorktime type... ...*The Senior Adversary Operations Engineer plays a critical role in... ...activities that uncover high‐risk vulnerabilities across enterprise, cloud, identity...Remote workHourly payFull timeTemporary workLocal areaWork from home- ...learning and building new solutions. Remote Flexibility: Enjoy the freedom and flexibility... ...We are seeking a skilled Security Operations Engineer to enhance our security monitoring and... ...are properly patched Implement a vulnerability & patch management process Ensure all...Remote workHome officeShift work
- ...Security Operations Engineer The Security Operations Engineer (SecOps Engineer) supports day-to-day security operations for our managed... ...approach to risk—by supporting threat detection, response, vulnerability management, and security engineering efforts. Role & Responsibilities...Remote workContract workWork at office
$110k - $140k
...is responsible for executing hands-on security operations to protect the organization's cloud... ...response actions to contain threats and remediate vulnerabilities. This individual works closely with detection engineering, cloud, and platform teams to maintain the reliability...Remote workFull timeLocal area- ...Job Description Title: Junior Operations Technology System Engineer Location: Bridgeport, West Virginia... ...support experience. • Strong in remote support and troubleshooting •... ...infrastructure support (HP Simplivity) • Vulnerability Management (IP360, Nessus, Nexpose)...Remote workWork at office
- ...Senior SOC Engineer CloudBees provides the leading software delivery platform for enterprises... ...threat detection and intelligence, vulnerability assessment and working on various other... ...is necessary as well as being able to operate SIEM, EDR, and other security tools....Remote workCasual workWorldwideWeekend work
- ...currently looking for a Senior Security Operations Engineer in the United States. This is a unique... ...within a highly collaborative remote‑first environment. You’ll have the opportunity... ...management, endpoint protection, vulnerability management, and overall cloud security...Remote work
- ...Junior Security Operations Engineer Dublin, Ireland; Amsterdam, Netherlands Telnyx is an... ...alongside our GRC lead to improve our vulnerability intake, threat response, darkweb posture... ...Logistics Full-time contract. Remote-first and async-friendly. We have hubs...Remote workFull timeContract workWork at officeImmediate start
- ...Red Canyon Technologies is seeking an Operations and Security Engineer to support mainframe and legacy system modernization engagements under... ...implementation activities including access control configuration, vulnerability assessment, and compliance documentation. ~...Remote workFull timeContract workFor contractorsFor subcontractor
- ...Location: Remote (US-based) Why This Role Exists: Dispel is pursuing... ...while simultaneously operating a commercial security program... ...Google SecOps RBAC Detection Engineering Build and deploy production... ...for tracking and escalation Vulnerability Management Operationalize monthly...Remote workPermanent employmentFlexible hours
- ...delivers robust security and operational efficiency without... ...product leadership, outstanding engineers, and strategic investment from... ...diverse systems. This is a remote role that is based in the United... ...detection and response, vulnerability management, threat intelligence...Remote workWork experience placementH1bLocal area
$82.5k - $110k
...Systems Operations Engineer With limited guidance from leadership, the System Operations Engineer utilizes knowledge and experience to help with vulnerability management, endpoint & device management, software distribution, Systems administration and Active Directory...Remote workTemporary workWork experience placementWork at officeLocal area$50 - $80 per hour
...job summary: The ideal Security Operations (SecOps) Engineer for this one-year consulting contract should possess specialized expertise in... ...Strong understanding of Microsoft 365 threat protection, vulnerability management, and endpoint detection and response (EDR)...Remote workHourly payContract workTemporary workWork experience placementWork at officeLocal area- ...Security Operations Engineer - Miami/Hybrid About the Role Boats Group is looking for... ...applications and APIs. Research vulnerabilities, document remediation/mitigating... ...: Embrace a balanced work model with remote work on Mondays and Fridays and in-office...Remote workWork at officeMonday to Friday
- BAVA (Baseline App Vulnerability Assessment) Operations & Support Engineer Contract One of our clients in Bay Area, it’s a long term contract opportunity. The candidate needs to be strong only with CheckMarx. Please let me know your interest and availability. One of our...Long term contractContract work
- ...Network Operations Engineer (L3) Job Summary The Network Operations Engineer is responsible... ...Assist in security audits compliance and vulnerability remediation. Ensure compliance with... ...development opportunities in a dynamic, remote work environment. Competitive compensation...Remote workShift work
- ...Join the team as an SD-WAN Engineer, a role that offers a unique... ...maintaining the overall technical and operational quality and resolutions of... ...firmware, patches, vulnerabilities, and documentation. Serve as... ...system. Assisted in coordinating remote field engineer dispatches...Remote workPermanent employmentShift workNight shiftRotating shift
- ...Title: Product Security Operations Engineer Location: Remote in Bay area Duration: 2+ Months About the Role As the Member of... ...Go) to automate the tracking of library versions and vulnerability status. Familiarity with supply chain security standards...Remote work
- Senior Security Operations Engineer (Viator) AWS GCP Security Operations Incident Response SIEM... ...security monitoring solutions. Expertise in vulnerability assessments, threat hunting, and... ...equity. Flexible work arrangements with a remote-first approach. Donation matching for...Remote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vulnerability Operations Engineer - Remote. Be the first to apply!
Related searches
- operations engineer United States
- production planning engineer United States
- cloud operations engineer United States
- security operations engineer United States
- production operations engineer United States
- data operations engineer United States
- operations process engineer United States
- network operations center engineer United States
- development operations engineer United States
- security operations center engineer United States

