Senior Security Engineer – Vulnerability Management
Job Fit Check
Base Career helps you apply smarter for this job.
Key skills for this role
Role Overview
Lead Vulnerability Management as an automation-first, intelligence-driven security function.
Own vulnerability risk reduction across cloud, infrastructure, endpoints, and internal environments.
The role combines hands-on system building, technical authority, mentoring, and strategic influence.
Key Skills for This Role
Full Job Posting
Role Overview
Lead Vulnerability Management as an automation-first, intelligence-driven security function.
Own vulnerability risk reduction across cloud, infrastructure, endpoints, and internal environments.
The role combines hands-on system building, technical authority, mentoring, and strategic influence.
What You’ll Do
- Own discovery, enrichment, prioritization, remediation, validation, and executive reporting across the vulnerability lifecycle.
- Operate and optimize Qualys VMDR across AWS, GCP, Azure, Kubernetes, containers, endpoints, and network infrastructure.
- Prioritize risk using CVSS, EPSS, CISA KEV, exploit intelligence, and asset criticality.
- Define remediation SLAs, exception management, and risk-acceptance governance.
- Correlate findings with CSPM, IAM exposure, threat intelligence, SIEM, and EDR data.
- Design automated workflows for intake, ticket creation, assignment, tracking, and remediation validation.
- Use AI to enrich vulnerability context and implement secure automated patching when risk-appropriate.
- Serve as technical authority, mentor analysts, and represent the function in audits and architecture reviews.
Who You Are
- 8–12 or more years of cybersecurity experience with deep specialization in vulnerability management.
- Expert-level Qualys VMDR experience or equivalent Tenable or Rapid7 experience.
- Strong knowledge of exploit intelligence, risk scoring, and vulnerability lifecycle governance.
- Hands-on cloud security, CSPM, endpoint patching, configuration management, and SIEM or EDR correlation experience.
- Strong Python, Bash, API integration, and workflow automation capabilities.
- Experience implementing AI-assisted prioritization or remediation workflows.
- Experience building executive dashboards and KPIs.
- Experience in regulated environments involving ISO 27001, GDPR, PCI-DSS, or DORA.
- Strong communication skills for translating technical exposure into business risk.
Business Context
Deriv protects global traders across distributed platforms and cloud environments.
Vulnerability Management supports a continuously operating fintech platform and enterprise risk reduction.
Employment
The job information identifies this as a full-time position.
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at Deriv.com
Compliance Technology Specialist
, UAE
Deriv is seeking a Compliance Technology Specialist to build and extend production systems for regulatory monitoring, AML and fraud workflows, RegTech integration, data governance, and risk modeling. The role requires ha
Senior Security Operations Engineer (Security Operations & AI-Driven Defense)
, UAE
Deriv is seeking a Senior Security Operations Engineer to build proactive, automated detection and response capabilities across cloud, identity, endpoint, network, and application environments. The role requires 8+ years
Senior Compliance Analyst
, UAE
The employer is seeking a Senior Compliance Analyst to investigate accounts and transactions, perform customer due diligence, conduct sanctions and adverse-media screening, and support regulatory reporting. The role requ