Senior Security Engineer – Vulnerability Management
Job Fit Check
Base Career helps you apply smarter for this job.
Key skills for this role
Role Overview
This is a hands-on leadership role building an automation-first, intelligence-driven vulnerability management function.
The role covers cloud, infrastructure, endpoints, internal environments, and regulated fintech operations.
The position is accountable for reducing exploitable exposure and shortening remediation windows.
Key Skills for This Role
Full Job Posting
Role Overview
This is a hands-on leadership role building an automation-first, intelligence-driven vulnerability management function.
The role covers cloud, infrastructure, endpoints, internal environments, and regulated fintech operations.
The position is accountable for reducing exploitable exposure and shortening remediation windows.
What You Will Do
- Own discovery, enrichment, prioritization, remediation, validation, and executive reporting across the vulnerability lifecycle.
- Operate and optimize Qualys VMDR across AWS, GCP, Azure, Kubernetes, containers, endpoints, and office or network infrastructure.
- Apply CVSS, EPSS, CISA KEV, exploit intelligence, and asset criticality to risk prioritization.
- Define remediation SLAs and govern exceptions and risk acceptance.
- Correlate vulnerability findings with CSPM, IAM exposure, threat intelligence, SIEM, EDR, and cloud-native controls.
- Design automated workflows for intake, ticketing, assignment, tracking, and remediation validation.
- Use AI to enrich vulnerability context and support secure automated patching where appropriate.
- Bridge Global Security Operations with IT and Engineering and mentor analysts in risk-based triage and exploit analysis.
Who You Are
- You have 8-12 or more years of cybersecurity experience with deep vulnerability management specialization.
- You have expert-level experience with Qualys VMDR or an equivalent platform such as Tenable or Rapid7.
- You understand exploit intelligence, risk scoring, and vulnerability lifecycle governance.
- You have hands-on cloud security, CSPM, endpoint patching, configuration management, and SIEM or EDR correlation experience.
- You can automate with Python, Bash, APIs, and workflow tools.
- You have implemented AI-assisted prioritization or remediation workflows.
- You can build dashboards and KPIs that influence executive decisions.
- You have operated in regulated environments involving ISO 27001, GDPR, PCI-DSS, or DORA.
- You can translate technical exposure into business risk.
Operating Context
- The role includes technical authority for Vulnerability Management in Cyberjaya and collaboration with global security, IT, and engineering teams.
Company Context
Deriv operates distributed trading platforms and cloud environments serving millions of global traders.
Vulnerability Management is positioned as a core defensive layer within the security organization.
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at Deriv
Compliance Technology Specialist
Dubai, UAE
Deriv is seeking a Compliance Technology Specialist to build and extend production systems for regulatory monitoring, AML, fraud detection, and RegTech integration. The role requires hands-on experience with microservice
Senior Compliance Analyst
Dubai, UAE
Deriv is seeking a Senior Compliance Analyst to investigate accounts and transactions, conduct due diligence, perform sanctions and adverse media screening, and support regulatory reporting. The role requires a relevant
Compliance Technology Specialist
Dubai, UAE
Compliance Technology Specialist
Dubai, UAE
Senior Compliance Analyst
Dubai, UAE
Senior In-Legal Counsel
London, GBR
Senior SOC Analyst
, UAE
Internal IT Auditor (Regulated Fintech)
Dubai, UAE
Senior Offensive Security Engineer
Dubai, UAE
Communications Lead, Growth
Dubai, UAE