Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Security Engineer, Vulnerability Management

$188k - $275k

CoreWeave

CoreWeave is The Essential Cloud for AI. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence. Trusted by leading AI labs, startups, and global enterprises, CoreWeave combines superior infrastructure performance with deep technical expertise to accelerate breakthroughs and turn compute into capability. Founded in 2017, CoreWeave became a publicly traded company (Nasdaq: CRWV) in March 2025. Learn more at .What You’ll Do:We are seeking a Staff Security Engineer to lead the most complex technical work in CoreWeave’s Vulnerability Management program. You will design and implement scalable triage, prioritization, and remediation-tracking systems across application, infrastructure, and hardware domains. You will set technical standards, drive high-impact initiatives, and mentor engineers through technical leadership, while partnering with leadership on priorities and execution risks.About the role:Lead high-complexity VM technical initiatives and deliver architecture decisions for assigned program areasDesign and build scalable triage automation, including integrations, decision logic, and production hardeningImplement end-to-end workflow components from assessment and detection to ticket routing and remediation trackingProvide deep technical leadership on hardware-adjacent vulnerabilities (GPU firmware, DPU firmware/BlueField, and BMC surfaces)Act as senior technical responder for embargoed disclosures and zero-day events, coordinating with owner teams that deploy fixesImprove prioritization logic, severity models, and exception workflows through code, design reviews, and technical proposalsProduce actionable technical metrics and risk insights for leadership consumptionLead root-cause analysis for high-impact vulnerability incidents and implement durable technical improvementsMentor IC3/IC4/IC5 engineers through design guidance, code review, and incident coachingPartner with security, engineering, and operational stakeholders to improve workflow reliability and accelerate remediation outcomesWho You Are: 9+ years of relevant experience with demonstrated strategic impact in vulnerability management, application security, platform security, or cloud security engineeringProven track record building and scaling security automation (SOAR workflows, AI/ML systems, detection pipelines) in production environmentsDeep subject matter expertise with vulnerability management best practices: CVSS, EPSS, CISA KEV, threat intelligence integration, and risk-based prioritization frameworksExcellent development background with strong coding skills in Python, Go, or similar languages for building scalable, production-grade security systemsSignificant experience with modern vulnerability management tooling (for example Wiz, Semgrep, Rapid7, Tenable, or equivalent)Experience with specialized infrastructure: GPU/DPU environments, firmware security, hardware vulnerabilities, or high-performance computingDemonstrated track record mentoring engineers across levels and driving cross-functional technical initiatives at organizational scaleStrong business acumen and understanding of how security decisions impact engineering velocity, customer trust, and business outcomesPreferred:Practical experience building AI/ML-powered security systems (LLM integration, automated decision-making, human-in-the-loop validation) in productionExperience managing hardware vendor security partnerships (embargoed disclosures and pre-release collaboration)Production experience with security automation platforms such as TINES and serverless frameworks (AWS Lambda, GCP Cloud Functions)Strong DevOps, DevSecOps, or SRE background with deep experience in AWS/GCP/Azure cloud services and Infrastructure as Code (Terraform, CloudFormation)Deep understanding of Kubernetes security (container scanning, admission controllers, supply chain security, runtime protection)Experience leading security programs through rapid hypergrowth (10x+ infrastructure scaling) in startup or cloud-native environmentsPractical experience managing vulnerabilities within a FedRAMP-certified environment or similar regulatory frameworksWhy CoreWeave?At CoreWeave, we work hard, have fun, and move fast! We’re in an exciting stage of hyper-growth that you will not want to miss out on. We’re not afraid of a little chaos, and we’re constantly learning. Our team cares deeply about how we build our product and how we work together, which is represented through our core values: Be Curious at Your CoreAct Like an OwnerEmpower EmployeesDeliver Best-in-Class Client ExperiencesAchieve More TogetherWe support and encourage an entrepreneurial outlook and independent thinking. We foster an environment that encourages collaboration and enables the development of innovative solutions to complex problems. As we get set for takeoff, the organization's growth opportunities are constantly expanding. You will be surrounded by some of the best talent in the industry, who will want to learn from you, too. Come join us! The base salary range for this role is $188,000 to $275,000. The starting salary will be determined based on job-related knowledge, skills, experience, and market location. We strive for both market alignment and internal equity when determining compensation. In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program (all based on eligibility). What We OfferThe range we’ve posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and location.In addition to a competitive salary, we offer a variety of benefits to support your needs. The benefits below reflect our US-based offerings for full-time employees; for roles in other locations, benefits vary and are shared during the hiring process. These include:Medical, dental, and vision insurance - 100% paid for by CoreWeaveCompany-paid Life Insurance Voluntary supplemental life insurance Short and long-term disability insurance Flexible Spending AccountHealth Savings AccountTuition Reimbursement Ability to Participate in Employee Stock Purchase Program (ESPP)Mental Wellness Benefits through Spring Health Family-Forming support provided by CarrotPaid Parental Leave Flexible, full-service childcare support with Kinside401(k) with a generous employer matchFlexible PTOCatered lunch each day in our office and data center locationsA casual work environmentA work culture focused on innovative disruptionCalifornia ApplicantsCalifornia Consumer Privacy Act Equal Opportunity & AccommodationsCoreWeave is an equal opportunity employer, committed to fostering an inclusive and supportive workplace. All qualified applicants and candidates will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information.As part of this commitment and consistent with the Americans with Disabilities Act (ADA), CoreWeave will ensure that qualified applicants and candidates with disabilities are provided reasonable accommodations for the hiring process, unless such accommodation would cause an undue hardship. If reasonable accommodation is needed, please contact: View email address on click.appcast.io Control ComplianceThis position requires access to export controlled information. To conform to U.S. Government export regulations applicable to that information, applicant must either be (A) a U.S. person, defined as a (i) U.S. citizen or national, (ii) U.S. lawful permanent resident (green card holder), (iii) refugee under 8 U.S.C. § 1157, or (iv) asylee under 8 U.S.C. § 1158, (B) eligible to access the export controlled information without a required export authorization, or (C) eligible and reasonably likely to obtain the required export authorization from the applicable U.S. government agency. CoreWeave may, for legitimate business reasons, decline to pursue any export licensing process.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Staff Security Engineer, Vulnerability Management in New York, NY vacancy
  • We’re seeking a team member for the role of SVP, Vulnerability Management & Cloud Security Posture Platform Engineering to join our Cybersecurity Engineering Tools & Platforms team. This role is located in New York, NY; Pittsburgh, PA; or Washington, DC.This is a high-... 
    Suggested
    Work experience placement
    Worldwide
    Flexible hours

    The Bank of New York Mellon

    New York, NY
    3 days ago
  • $174k - $252k

    Identify security issues and implement and design security controls...  ...including Privilege Access Management (PAM), Model Oversight,...  ...of experience with security engineering, computer and network...  ...and fix security flaws and vulnerabilities.PRISM is the central engineering... 
    Suggested

    Google

    New York, NY
    3 days ago
  • $147k - $210k

     ...Model (LLM) tooling to scale advanced vulnerability research, defensive engineering, and mitigation strategies across...  ...teams for vulnerability management and tool building, while proactively...  ...improve efficiency.Conduct deep-dive security research into Android vulnerabilities... 
    Suggested

    Google

    New York, NY
    1 hour ago
  •  ...We are seeking an experienced Mobile Security Vulnerability Management Engineer to lead Proof of Technology (PoT) evaluations, implement enterprise mobile vulnerability management solutions, and manage security compliance across iOS, iPadOS, and Android devices. The ideal... 
    Suggested
    Temporary work

    Techvilla Solutions

    New York, NY
    18 days ago
  • $82.6k - $162.8k

     ...Continuous Threat Exposure Management (CTEM) team. In this role, you...  ..., and remediating security exposures across complex technology...  ...stakeholders to strengthen vulnerability management and patching processes...  ...you'll do As a Security Engineer II on the Cyber Defense & Resilience... 
    Suggested
    Local area

    Deloitte

    New York, NY
    4 days ago
  • $180k - $247k

    Secure Every Identity, from AI to HumanIdentity is the key to unlocking the potential...  ...where Identity belongs to you.The Staff Product Security Engineer OpportunityThe Security team's...  ...on leveraging AI to uncover vulnerabilities, automate root cause analysis, automate... 
    Local area
    Worldwide
    Flexible hours

    Okta

    New York, NY
    1 day ago
  •  ...computers. For the first time ever, you can manage and automate every part of the...  ...The RoleWe're looking for a hands-on staff security engineer to play a key role in building Rippling...  ...about an innovative way to reduce vulnerabilities in your organization What You'll DoBuild... 
    Work at office
    Relocation
    3 days per week
    1 day per week

    Rippling

    New York, NY
    3 days ago
  • $224k - $300k

     ...world value. THE WORK: As a Senior Staff Security Engineer focused on AI Security, you will be...  ...poisoning, excessive agency, and MCP server vulnerabilities. Experience securing agentic AI...  ...to our culture, and we give managers and teams the flexibility to decide... 
    Full time
    Work at office
    Local area

    P2P

    New York, NY
    4 days ago
  •  ...Job Description Job Description Senior Cybersecurity Engineer – Vulnerability Management & Incident Response Position Overview Our client...  ...incident response operations. This role is ideal for a security professional who enjoys balancing strategic program ownership... 
    Weekend work

    RennerBrown Staffing

    New York, NY
    8 days ago
  •  ...Responsibilities Drive Ripple’s AI Security technical strategy and...  ...~10+ years of Security Engineering experience with depth in at...  ..., excessive agency, and MCP vulnerabilities. ~ Experience securing agentic...  ...-office collaboration with managers and teams deciding which 10+... 
    Full time
    Work at office

    Ripple

    New York, NY
    8 days ago
  • $150k - $250k

     ...HRT) is seeking a curious, innovative Security Engineer to join our Enterprise Security team...  ..., ownership of a comprehensive vulnerability management program, securing SaaS deployments,...  ...valued. HRT is proud of our diverse staff; we have offices all over the globe... 
    Work at office
    Local area
    Immediate start

    Hudson River Trading

    New York, NY
    3 days ago
  • cFocus Software Incorporated seeks a Vulnerability Management Analyst to support the United States DFC program. The role is remote and requires an Active Public Trust clearance. You will coordinate authenticated vulnerability scans, analyze outputs from enterprise platforms... 
    Remote job

    cFocus Software Incorporated

    New York, NY
    4 days ago
  • Capgemini seeks an experienced Vulnerability Management SME / Product Analyst to translate security requirements into platform capabilities, workflows, prioritization models, reporting, and remediation processes for vulnerability management modernization initiatives. The... 

    Capgemini

    New York, NY
    1 day ago
  •  ...Description We are seeking an experienced Vulnerability Management SME / Product Analyst to serve as the...  ...controls. Facilitate workshops with security teams, application owners,...  ...strengths from strategy and design to engineering, all fueled by its market leading capabilities... 
    Full time
    Local area

    Capgemini

    New York, NY
    1 day ago
  • $244k - $305k

    As a Staff Application Security Engineer at Datadog, you'll set technical direction for how we approach...  ...documentationSolid grounding in OWASP Top 10, web vulnerabilities (XSS, injection, access control,...  ...core platforms alongside product managers and engineering teamsAble to... 

    Datadog

    New York, NY
    3 days ago
  • $150k - $250k

     ...ARELed by the Chief Information Security Officer (CISO), Technology...  ...for risk, partnering with engineers to architect and design secure...  ...in helping counterparts manage riskRESPONSIBILITIES AND QUALIFICATIONSJob...  ...Engineer, Architect, Vulnerability Manager).Design or... 

    Goldman Sachs

    New York, NY
    3 days ago
  • $132k - $184.4k

    Job Duties: Associate, Security Engineering with Goldman Sachs & Co. LLC in New York, New York....  ...assessments across the SDLC, including vulnerability assessments and penetration testing...  ...applications in coordination with vulnerability management teams. Perform secure code reviews... 
    Work experience placement
    Shift work

    Goldman Sachs

    New York, NY
    3 days ago
  • $169k - $199k

     ...standards, clear accountability, and a strong focus on security and ethics in everything we build!The Red Team’s mission...  ...simulating adversary behavior and testing defenses. As a Staff Offensive Security Engineer, you will plan and execute security assessments across applications... 
    Work at office
    Shift work
    3 days per week

    Robinhood Financial

    New York, NY
    1 day ago
  • $245.92k - $286.9k

    Hi, we're Oscar. We're hiring a Staff Security Engineer, GRC to join our Information Security Team.Oscar is the first health insurance company...  ...compliance-as-code patterns, evidence workflows, and risk management practices for AWS-hosted and Azure-hosted systems. You... 
    Full time
    Work experience placement
    Work at office
    Flexible hours

    Oscar Health Insurance

    New York, NY
    3 days ago
  • $160k - $190k

     ...Mission or Department OverviewThe newsroom security engineer within Cybersecurity is a hands-on...  ...the Cybersecurity department, you will manage complex projects end-to-end. You will also...  ...strengthen protections for newsroom staff while supporting efficient journalistic... 
    Work at office
    Local area
    Flexible hours

    The New York Times

    New York, NY
    1 day ago
  •  ...safety, operations, and quality management. Our technology gives...  .... The Role As our first security hire, you’ll build our security...  ...blocker—earning trust across engineering and product by being a...  ...Lead threat modeling and vulnerability management—working with engineering... 

    intenseye

    New York, NY
    8 days ago
  •  ...Senior Vice President, Security Engineering About the Company Leading financial services organization seeking to strengthen enterprise...  ...tasked with advancing the firm's threat intelligence, vulnerability management, and cybersecurity engineering capabilities, with a... 

    Confidential

    New York, NY
    5 days ago
  • $120k - $145k

     ...NBCUniversal is seeking a Staff Cyber Systems Engineer to build and scale modern application security capabilities across the enterprise...  ...chain workflows. Improve vulnerability prioritization, triage,...  ...application security, vulnerability management, and software supply chain... 
    Full time
    Local area
    Remote work

    NBCUniversal

    New York, NY
    17 days ago
  • $106k - $209k

     ...Want to secure the future of data management and AI/ML? At MongoDB we are transforming industries and empowering...  ...You Are With a strong security engineering background, you’re looking for a...  ...security researchers to identify vulnerabilities that eventually are published CVEs... 
    Work at office
    Local area
    Remote work
    Worldwide
    Flexible hours

    MongoDB

    New York, NY
    5 days ago
  • 1440 Foods is seeking an IT/OT Security Engineer & Incident Response Lead to join our manufacturing security team in New York. You...  ...own security engineering, drive incident coordination, manage EDR and vulnerability programs, and work with our SOC to ensure timely... 

    1440 Foods

    New York, NY
    1 day ago
  • $142.5k - $260k

     ...financial industry. As a Senior Lead Security Engineer at JPMorganChase within Cybersecurity...  ...changes during periods of vulnerability, incident response, remediation, or emerging...  ...technologies, secure design patterns, and risk management practices Required qualifications,... 
    Full time
    For contractors

    JPMorgan Chase & Co.

    New York, NY
    3 days ago
  • $192.6k - $260.5k

    Amazon's Specialized Businesses Security team is seeking a Security Engineer Manager to lead our Specialized Detections team. This is a forward-driving leadership...  ...no other team at Amazon covers; the first targets vulnerability classes outside the reach of standard Builder... 
    Remote work
    Flexible hours

    Amazon

    New York, NY
    3 days ago
  •  ...Security Operations EngineerArch is a Series B financial technology...  ...company that automates the management of private investments,...  ...Role:As a Security Operations Engineer, you'll join our small, growing...  ...focused role supporting our vulnerability management and detection... 
    Full time
    Work at office
    Relocation

    ARCH COMPANY

    New York, NY
    2 days ago
  • $220k - $235k

     ...About Savvy Wealth: Wealth management is a $545 billion industry that still runs on...  ...We are seeking a Senior Application Security Engineer to join Savvy Wealth at our NYC headquarters...  ...-to-day work centered on identifying vulnerabilities, remediating them, and closing the... 
    Full time
    Work at office

    Savvy Wealth

    New York, NY
    2 days ago
  • $100k - $228k

     ...small, highly motivated, and focused on engineering excellence. This organization is for...  ...Compliance (GRC) Engineer to own and scale our security and AI governance compliance posture as...  ...the company's governance and AI management system posture. Identify, assess,... 
    Permanent employment
    Full time
    Temporary work

    SpaceXAI

    New York, NY
    9 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Security Engineer, Vulnerability Management. Be the first to apply!