Build and continuously improve an internal security tooling platform that consolidates vulnerability data, scan results, asset context, and remediation workflows into a single source of truth.
Develop and maintain the Vulnerability Management (VM) application — including ingestion pipelines, normalization, deduplication, risk scoring (CVSS/EPSS/contextual), SLA tracking, and reporting dashboards over very large finding datasets.
Engineer the Web Application Security (WAS) tooling — orchestration of DAST scans, authenticated scan profiles, scan scheduling, finding triage workflows, and developer ticketing integrations (Jira, Azure DevOps, GitHub Issues).
Integrate SAST, SCA, secrets-scanning, IaC scanning, and container-image scanning tools into CI/CD pipelines, and surface results through the security platform.
Model assets, identities, and relationships as a graph to power blast-radius and attack-path analysis used by remediation workflows.
Reduce manual effort for the security team by automating recurring workflows (ticket creation, exception management, evidence collection, compliance evidence) using durable workflow orchestration.
Partner with the AppSec and Cloud Security teams to operationalize Secure SDLC controls (threat modeling intake, security requirements, gating policies, paved-road templates).
Deliver a high-quality developer and analyst experience: fast, intuitive UIs handling high-cardinality data; reliable APIs; well-documented integrations; observable, resilient services.
Champion engineering best practices — code quality, automated testing, performance, accessibility, and security-by-design in everything we build.
Design, develop, test, deploy, and maintain end-to-end features across frontend, backend, and data layers for the security tooling platform.
Build responsive, accessible web UIs using React with TypeScript, virtualized data grids, charting libraries, and real-time updates (WebSockets / Server-Sent Events) for scan progress and live findings.
Develop scalable backend services and REST APIs (OpenAPI-first) using Python (FastAPI/Django) or Node.js — including authentication, authorization (RBAC/ABAC), and audit logging.
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
Design relational, document, search, and analytical data models — PostgreSQL for operational data, OpenSearch/Elasticsearch for finding search, and a columnar store (ClickHouse, Snowflake, BigQuery, or Iceberg/Parquet) for analytics over billions of findings.
Build event-driven and batch data pipelines for ingesting scanner output, asset inventory, ticketing data, and threat intelligence feeds.
Implement durable workflow orchestration for scan lifecycle, ticket lifecycle, SLA timers, and evidence collection.
Qualifications
Bachelor's or Master's degree in Computer Science, Software Engineering, Cybersecurity, or a related discipline — or equivalent professional experience.
7+ years of professional software engineering experience building production web applications end-to-end.
Strong proficiency in React (preferred) with TypeScript, modern CSS, and component libraries; experience with virtualized data grids (TanStack Table, AG-Grid) and a charting library (Recharts, D3, ECharts) for high-density security dashboards.
Strong proficiency in Python (FastAPI/Django/Flask) — preferred for this role given the security tooling ecosystem — and/or Node.js (Express/Nest). Java (Spring Boot) or Go experience is a plus.
Solid REST API design (OpenAPI-first), authentication and identity standards (OAuth 2.0, OIDC, JWT), and authorization patterns (RBAC/ABAC).
Proficiency with PostgreSQL (or MySQL) and at least one of OpenSearch/Elasticsearch, MongoDB, or Redis.
Experience with event-driven systems and message brokers (Kafka, SQS, RabbitMQ, Pub/Sub).
Strong fundamentals in data structures, algorithms, system design, and software engineering best practices (SOLID, clean architecture, testing pyramid).
Hands-on experience with Git, modern CI/CD, containerization (Docker), and at least one cloud platform (AWS, Azure, or GCP).
Hands-on experience with GitHub Actions for CI/CD pipeline development and Argo CD for GitOps-based continuous delivery to Kubernetes.
Real-time UX patterns — WebSockets or Server-Sent Events for live scan status and findings updates.
Working knowledge of OWASP Top 10 / OWASP ASVS and how to prevent common web vulnerabilities in code.
Understanding of the Vulnerability Management lifecycle — discovery, triage, prioritization (CVSS, EPSS, business context), remediation, and reporting.
Familiarity with common security testing tools — SAST, DAST, SCA, secrets scanning, container scanning, IaC scanning — and experience integrating at least one into a CI/CD pipeline.
Hands-on experience with durable workflow— critical for scan, ticket, and SLA lifecycle management.
Experience designing for large-scale finding/telemetry data
Understanding of Secure SDLC principles — security requirements, threat modeling, secure coding standards, security gates, and DevSecOps automation.
Hands-on experience implementing or consuming cloud security controls — IAM least privilege, KMS/Secrets Manager, VPC design, security groups, logging (CloudTrail / Defender / Cloud Audit Logs).
Familiarity with policy-as-code authorization engines (OPA/Rego, Cedar) for both product policy and platform RBAC.