Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Vulnerability Operations Engineer - Remote

CENTRAL SQUARE INC

Vulnerability Operations Engineer

At CentralSquare, we don't just build software - we power public servants and uplift communities with Hero-Grade Technology. Every line of code, every feature we deliver helps heroes across North America protect, serve, and save lives. When you join us, you become part of a mission-driven team creating technology that makes communities safer and stronger.

Your Growth Matters. We believe heroes deserve opportunities to rise. That's why we invest in your career with mentorship, learning programs, and clear paths for advancement. If you're motivated, there's no limit to how far you can go.

Your Commitment Deserves Reward. We offer competitive compensation and a benefits package designed to support your life inside and outside of work—tuition reimbursement, parental leave, paid volunteer hours, and unlimited PTO. Plus, our flexible work environment gives you the freedom to balance your heroic work with personal well-being, whether you're in the office or remote.

Join us and help build the tools that power real-life heroes. Together, we make a difference.

The Role

CentralSquare is seeking a Vulnerability Operations (VulnOps) Engineer to join our Security team. This is an individual contributor role purpose-built for the post-AI era of vulnerability discovery — where AI models can now find and exploit flaws at machine speed, and reactive patch cycles are no longer sufficient.

This role is not an advisory function. The VulnOps Engineer owns the full pipeline from discovery through fix delivery: running AI-powered scanning against CentralSquare's codebases and dependencies on a continuous basis, generating validated fixes, and submitting ready-to-merge pull requests into owning teams' Azure DevOps pipelines. App teams retain code review and merge authority; this role exists to ensure they are never handed a problem without also being handed a solution.

Job Duties Include:
  • Proactive Vulnerability Discovery
  • Operate and continuously improve an AI-powered scanning pipeline across CentralSquare's first-party codebases, open-source dependencies, and infrastructure components
  • Use Claude Code, Veracode, and Orca to conduct ongoing static analysis, software composition analysis (SCA), and cloud posture assessments
  • Apply reachability analysis to distinguish genuinely exploitable vulnerabilities from theoretical findings, reducing alert fatigue and focusing remediation effort where risk is real
  • Monitor threat intelligence feeds, CVE disclosures, and coordinated disclosure programs (including Project Glasswing patch releases) to identify newly disclosed vulnerabilities affecting CentralSquare's software supply chain
  • Fix Development and Delivery
  • Develop and validate fixes (code patches, dependency upgrades, configuration changes) using AI coding agents such as Claude Code, verifying resolution without regressions before submission
  • Submit validated fixes as pull requests into owning teams' Azure DevOps repositories, with clear documentation of the vulnerability, risk context, and fix rationale to support efficient review and merge
  • Collaborate with application and infrastructure teams during code review, providing technical context and responding to questions about proposed changes
  • SLA Ownership and Reporting
  • Own the end-to-end SLA lifecycle for all open findings, maintaining real-time tracking of detection, fix submission, and merge status in the vulnerability management system
  • Proactively escalate findings approaching SLA breach with remediation options and risk context
  • Produce regular reporting on pipeline health, SLA adherence, remediation velocity, and open risk posture for the security leadership team
  • Toolchain and Pipeline Maintenance
  • Own the configuration, tuning, and operational health of VulnOps tooling including Veracode, Orca, Claude Code, and Azure DevOps security integrations
  • Identify and reduce false positive rates through policy tuning and reachability filtering, ensuring signal quality remains high as scan volume increases
  • Contribute to the development of automated remediation pipelines, including AI-assisted fix generation integrated directly into CI/CD workflows
  • Evaluate and recommend new tools and capabilities as the AI security tooling landscape evolves
  • Cross-Functional Collaboration
  • Work closely with application engineering, DevOps, and infrastructure teams to ensure fix delivery is efficient and minimally disruptive to development velocity
  • Provide security guidance to engineering teams on secure coding practices and dependency management in the context of AI-accelerated vulnerability discovery
  • Partner with the Risk and Compliance team to ensure vulnerability data and SLA metrics align with audit and regulatory reporting requirements (NIST CSF, PCI DSS, CJIS)
  • Perform other duties as assigned
Qualifications

Education and Experience

  • Bachelor's degree in Cybersecurity, Computer Science, or Information Technology, or equivalent professional experience
  • 5–7 years of professional experience in application security, vulnerability management, or a combined security engineering role
  • Demonstrated hands-on experience using AI coding agents (Claude Code or equivalent) to find, evaluate, and generate fixes for software vulnerabilities

Technical Skills

  • Proficiency with SAST and SCA tooling; direct experience with Veracode strongly preferred
  • Experience with cloud security posture management; direct experience with Orca preferred
  • Working experience with Azure DevOps for CI/CD pipeline integration and pull request workflows
  • Ability to read, understand, and write code across at least two languages commonly used in enterprise SaaS environments (e.g., Java, C#, Python, JavaScript/TypeScript, Terraform)
  • Strong understanding of reachability analysis and the ability to apply it to distinguish exploitable findings from theoretical risk
  • Familiarity with dependency and supply chain security concepts, including SBOM generation and management
  • Working knowledge of common vulnerability classes (injection, memory corruption, authentication flaws, insecure deserialization, etc.) and their remediation patterns
  • Understanding of security frameworks including NIST CSF and CIS Controls

Soft Skills and Work Style

  • Highly systematic and process-driven — capable of managing a high volume of concurrent findings without losing precision or letting items fall through the cracks
  • Self-directed and accountable: this role is measured by fix delivery and SLA outcomes, not activity metrics
  • Strong written communication skills — fix submissions must include documentation that gives owning teams sufficient context for confident, efficient code review
  • Comfortable working across organizational boundaries, earning credibility with engineering teams through technical quality rather than authority
  • Able to prioritize effectively under pressure, with clear judgment about when to escalate versus resolve independently
CJIS Clearance

A required part of the onboarding process for this role involves obtaining CJIS (Criminal Justice Information Services) clearance—a critical credential for safeguarding public safety data. At CentralSquare, we'll stand with you every step of the way to secure this clearance should you be selected for hire. As part of the process, a comprehensive background check will be conducted, and please note that U.S. citizenship or permanent residency is generally required to obtain CJIS clearance.

CentralSquare Technologies is proud to be an Equal Opportunity Employer. We are committed to fostering a workplace that is inclusive, respectful, and free from discrimination—where all individuals are valued, supported, and provided equal opportunity to succeed.

We place a strong emphasis on supporting military veterans and their spouses and recognize the leadership, discipline, resilience, and mission-oriented mindset they bring to the workforce. The skills developed through military service—such as accountability, teamwork, adaptability, and the ability to perform under pressure—are highly valued at CentralSquare and directly contribute to our success.

In addition to our commitment to veterans, CentralSquare Technologies welcomes and encourages applicants from all backgrounds. We are committed to equal employment opportunity for all qualified individuals, regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, age, marital status, disability, veteran status, or any other characteristic protected by applicable federal, state, or local law.

Our employees reflect a wide range of experiences, perspectives, and identities, and this diversity strengthens our ability to innovate and serve the public sector, whether through our public safety or public administration businesses. Through our technology, we support public servants and the communities they serve, and we believe our workforce should reflect those communities as well.

If you are seeking an opportunity to contribute to meaningful work that impacts communities nationwide—whether continuing a legacy of service or beginning a new chapter—CentralSquare Technologies invites you to apply.

Your next mission

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Vulnerability Operations Engineer - Remote in United States vacancy
  •  ...personal well-being, whether you're in the office or remote. Join us and help build the tools that power real-life...  .... The Role CentralSquare is seeking a Vulnerability Operations (VulnOps) Engineer to join our Security team. This is an individual contributor... 
    Remote work
    Permanent employment
    Work experience placement
    Work at office
    Flexible hours

    CentralSquare Technologies

    United States
    1 day ago
  •  ...security challenges, reduce risk, and improve operational resilience amid fast-evolving threats....  ...span cyber threat intelligence, vulnerability intelligence, geopolitical risk, physical...  .... As a Junior Vulnerability Automation Engineer, you will play a pivotal role in... 
    Remote work
    Local area
    Shift work

    Flashpoint.io, Inc

    United States
    11 hours ago
  •  ...Vulnerability Operations Engineer Cloud Engineering/DevOps This Vulnerability Operations Engineer contract role will operationalize vulnerability management across infrastructure, applications, and cloud environments in a large-scale enterprise setting. You'll own scanning... 
    Suggested
    Contract work

    Delphi-US, LLC - Peacemakers in the Talent War

    New York, NY
    11 hours ago
  •  ...We are seeking a Cybersecurity Operations Engineer to run security operations across a holding...  ...security strategy, CIS hardening, CASB/DLP, vulnerability management, and continuous pentesting....  ...or training. For roles eligible for remote work, the base salary is tailored to... 
    Remote work
    Full time
    Temporary work
    Live out
    Work at office
    Local area

    Momentum

    Dallas, TX
    4 days ago
  •  ...Senior Cybersecurity Operations Engineer - AI The Senior Cybersecurity Operations Engineer -...  ...Requirements: Normal office environment. (Remote or Hybrid), 3 to 4 days per month are...  ...to: Networking, LDAP Directories, Vulnerability/Patch Management, Change Management,... 
    Remote work
    Work at office
    Afternoon shift

    Bread Financial Holdings

    Columbus, OH
    4 days ago
  • $91k - $120k

     ...Cyber Operations Engineer III Through our dedicated associates, Conduent delivers mission-critical...  ...that streamline incident response, vulnerability management, and security monitoring....  ...In this role, you can expect: ~ Remote Work: Enjoy the flexibility of working... 
    Remote work
    Work from home
    Flexible hours

    Conduent

    United States
    1 day ago
  • $110k - $140k

     ...executing hands-on security operations to protect the organization’s...  ...contain threats and remediate vulnerabilities. This individual works closely with detection engineering, cloud, and platform teams to...  ...communication skills. #LI-AS1 #LI-Remote Note: This job description... 
    Remote work
    Full time
    Local area

    SitusAMC

    United States
    3 days ago
  • $153k - $187k

     ...Through solutions like bug bounty, vulnerability disclosure, agentic...  ...We Default to Disclosure by operating with transparency and integrity...  ...re-architecting the revenue engine, leading the build of an AI-native...  ...this philosophy, this is a remote role targeted for candidates... 
    Remote work
    Apprenticeship
    Local area
    Flexible hours
    Shift work

    HackerOne

    San Francisco, CA
    3 days ago
  •  ...Position Summary: The Security Operations Engineer is a pivotal role within the cybersecurity...  ...potential security risks and vulnerabilities. Assist with implementation of risk...  ...in office in Wyoming, MI with 1 day remote What you'll bring to the table:... 
    Remote work
    Work at office
    Monday to Friday
    Night shift

    Gordon Food Service

    Wyoming, MI
    11 hours ago
  •  ...Junior Security Operations Engineer Dublin, Ireland; Amsterdam, Netherlands Telnyx is an...  ...alongside our GRC lead to improve our vulnerability intake, threat response, darkweb posture...  ...Logistics Full-time contract. Remote-first and async-friendly. We have hubs... 
    Remote work
    Full time
    Contract work
    Work at office
    Immediate start

    Telnyx

    United States
    11 hours ago
  •  ...Senior SOC Engineer CloudBees provides the leading software delivery platform for enterprises...  ...threat detection and intelligence, vulnerability assessment and working on various other...  ...is necessary as well as being able to operate SIEM, EDR, and other security tools.... 
    Remote work
    Casual work
    Worldwide
    Weekend work

    CloudBees

    United States
    11 hours ago
  •  ...Red Canyon Technologies is seeking an Operations and Security Engineer to support mainframe and legacy system modernization engagements under...  ...implementation activities including access control configuration, vulnerability assessment, and compliance documentation. ~... 
    Remote work
    Full time
    Contract work
    For contractors
    For subcontractor

    Diné Development

    United States
    3 days ago
  •  ...Security Operations Engineer - Miami/Hybrid About the Role Boats Group is looking for...  ...applications and APIs. Research vulnerabilities, document remediation/mitigating...  ...: Embrace a balanced work model with remote work on Mondays and Fridays and in-office... 
    Remote work
    Work at office
    Monday to Friday

    Boats Group

    Miami, FL
    11 hours ago
  •  ...is seeking a hands-on Senior Security Operations Engineer to help secure and scale our platform....  ...impactful work. Our flexible and fully remote work setup allows you to balance your...  ...endpoint/EDR posture. # Coordinate vulnerability management end-to-end: scanning, prioritization... 
    Remote work
    Flexible hours
    Shift work

    Total Administrative Svc

    United States
    1 day ago
  •  ...delivers robust security and operational efficiency without...  ...product leadership, outstanding engineers, and strategic investment from...  ...through production. This is a remote role that is based in the...  ...network detection and response, vulnerability management, threat... 
    Remote work
    Work experience placement
    H1b
    Local area

    Delinea

    United States
    11 hours ago
  •  ...Linux and AWS Technical Operations Engineer – Work From Home This is a 100% remote Linux and AWS Technical Operations Engineer opportunity. Candidates located...  ...platforms. ~ Investigate abuse and security vulnerabilities while creating and documenting policies related... 
    Remote work
    Local area
    Work from home

    NextStep

    United States
    1 day ago
  •  ...currently looking for a Senior Security Operations Engineer in the United States. This is a...  ...practices within a highly collaborative remote‑first environment. You’ll have the opportunity...  ...management, endpoint protection, vulnerability management, and overall cloud security... 
    Remote work

    Jobgether

    New York, NY
    11 hours ago
  • Location: Remote (US-based) Why This Role Exists: Dispel is pursuing...  ...while simultaneously operating a commercial security program...  ...Google SecOps RBAC Detection Engineering Build and deploy production...  ...tracking and escalation Vulnerability Management Operationalize monthly... 
    Remote work
    Permanent employment
    Flexible hours

    Dispel

    New York, NY
    1 day ago
  • $126k - $189k

     ...months) Development, Security, and Operations "DevSecOps" Engineer to support and scale the organization...  ...our U.S. office locations and some remote locations. Job Description:...  ...reviews with emphasis on security vulnerabilities, error handling, resilience, and maintainability... 
    Remote work
    Full time
    Temporary work
    Work at office
    Flexible hours

    Fenwick & West

    Mountain View, CA
    11 hours ago
  •  ...its affiliates. DMBA began operations in 1970 and is now in its 56...  ...Information Security Operations Engineer to join the Information...  ...to detect misconfigurations, vulnerabilities, or weaknesses requiring mitigation...  ...program Work in a hybrid remote work and office work... 
    Remote work
    Work at office

    Deseret Mutual Benefit Administrators

    Salt Lake City, UT
    4 days ago
  •  ...Senior Cloud Operations Engineer for Stellus Rx We're opening eyes, hearts and minds to the impact that a pharmacy team can have in...  ...for policy violations, security drift, and OWASP-related vulnerabilities — rather than relying on point-in-time manual audits. Oversee... 
    Remote work

    Stellus Rx

    United States
    11 hours ago
  • $130k - $150k

     ...Job Description Job Description Mission Operations Engineer - Ground Systems Location: Eastern NM Employment Type: Full Time, Exempt...  ...stratospheric platforms for communications, imaging, and remote sensing. These high-altitude lighter-than-air systems... 
    Remote work
    Full time
    Local area

    LHH US

    Moriarty, NM
    6 days ago
  • $92k - $195k

     ...seeking an experienced Cyber Operations Capabilities Developer to...  ...technical position suited for engineers with deep hands-on experience...  ...analysis Contribute to vulnerability research and exploit development...  ...and cross compiling a full Remote Access Tool (RAT)... 
    Remote work

    Vantor

    Anne Arundel County, MD
    11 hours ago
  • $165k - $175k

     ...Senior Security Operations Center (SOC) Cloud Engineer The IT Security Team is looking for a seasoned professional...  ...workloads. This role can be remote anywhere in the country. The...  ...on new and evolving threats and vulnerabilities targeting cloud platforms and recommend... 
    Remote work
    Work experience placement
    Night shift

    Bayview Asset Management

    United States
    11 hours ago
  •  ...As a Senior Azure Cloud Operations Engineer, you will be responsible for architecting, implementing...  ..., network security groups (NSG), and vulnerability management. • Proactively identify...  .... • Experience working in remote-first teams. Infrastructure as Code... 
    Remote work
    Flexible hours

    Texas State Library and Archives Commision

    United States
    2 days ago
  •  ...Description Job Description Salary: Members of Scientific Operations (SciOps) are responsible for providing the on-site technical (...  ...experiments at the bench, scientists on the ECL leverage the remote, automated execution of all standard biology and chemistry experiments... 
    Remote work
    Night shift

    Emerald Cloud Lab

    Austin, TX
    9 days ago
  • $150k - $250k

    The Opportunity Do you have a Space Systems Engineering background? Are you looking for an opportunity...  ...and fielding the next generation of remote sensing satellite and ground systems. As a Transition to Operations Engineer on our team, you will work with SFA... 
    Remote work
    For contractors
    Work at office
    Work from home
    Relocation package
    Flexible hours

    Space Force Analytics LLC

    Aurora, CO
    5 hours ago
  • $25 - $33 per hour

     ...support, and maintenance. We are seeking two Trimark Operations Center (TOC) Engineers to provide end-to-end customer service in a highly...  ...support CAISO direct telemetry requirements, CAISO SQMD, remote data acquisition, etc. Responds to end-user phone, email... 
    Remote work
    Hourly pay
    Work at office

    Trimark Associates

    Norfolk, VA
    14 days ago
  •  ...functionally with Information Security Operations and Infrastructure/DevOps...  ...cloud security alerts and vulnerabilities; implement timely...  ...configurations for Kubernetes Engine environments, including:...  ...members. Flexible Work ~ Remote from the start, we believe in... 
    Remote work
    Flexible hours

    HealthX Ventures

    United States
    1 day ago
  • $137.7k - $152k

    Position Overview This Senior Cloud Operations Engineer role is central to scaling and maintaining...  ...checks, perform compliance scans, and vulnerability testing directly into the deployment...  ...on Mondays, Tuesdays, and Thursdays. Remote on Wednesdays and Fridays (unless you... 
    Remote work
    Work at office
    3 days per week

    REsurety, Inc.

    Boston, MA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Vulnerability Operations Engineer - Remote. Be the first to apply!