Vulnerability Engineer

๐Ÿข Dominodatalab ยท all 13 jobs
๐Ÿ“ Remote India
๐Ÿ“… Posted Sep 15, 2026 ยท via Greenhouse
Apply on original site โ†—

Who we are

At Domino, we build solutions that help the largest, highly regulated organizations adopt AI to accelerate mission-critical use cases. Our platform integrates a streamlined model and app development environment, advanced model, agent, and app hosting capabilities, and novel governance capabilities providing regulator-ready AI at scale. Our customers โ€” like Johnson & Johnson, GSK, Bristol Myers, UBS, FINRA and the US Navy โ€” are using our software to solve some of the most important challenges in the world, such as developing new medicines, securing our financial markets, or protecting our country. Backed by Sequoia Capital, Coatue Management, NVIDIA, Snowflake and other leading investors, we have been in business for over a decade but are still a small team operating with the spirit of a startup. In the world of AI today, we believe that the future is still being invented โ€” and we want to be the ones building it. For more information, visit www.domino.ai

What we are building

Domino's Security team safeguards a platform trusted by some of the most regulated organizations in the world, across financial services, pharma, government, and defense. Vulnerability Management is where that trust gets tested day to day: finding, triaging, and closing out risk across our OS, container, and dependency surface, and giving customers a clear, defensible answer when they ask how exposed they are. This role joins that function as it scales, working closely with our Staff Security Engineer to turn a fast-growing vulnerability workload into faster, more consistent risk assessments.

What your impact will be

In your first year, your impact will be:

- Faster, more consistent Vulnerability Risk Assessments. You'll own first-pass CVSS scoring and exploitability analysis, closing the SLA gap between finding and answer

- Validated, trustworthy triage. You'll reproduce and confirm customer-reported and pen-test findings before they reach Engineering, so fix priority reflects real exploitability, not just scanner severity

- Reliable scanning pipelines. You'll keep SAST/DAST and vulnerability scanning automations running, troubleshooting failures and tuning configs so the data everyone relies on stays clean

- Real partnership with Engineering. You'll build or run PoC exploits on select CVEs, bringing validated risk, not just findings, into prioritization conversations

- More capacity for the function. You'll free up our Staff Security Engineer to focus on program-level improvement instead of carrying all of vulnerability management's day-to-day load

What we look for in this role

- Hands-on experience managing vulnerabilities for a large SaaS product, across OS, container, and dependency exposure

- A track record triaging and tracking CVEs for a SaaS or containerized product: reading scan reports, prioritizing by severity, and following through to resolution

- Experience reproducing and validating reported vulnerabilities, whether from customer disclosures or pen test findings, not just logging them

- Time spent with vulnerability scanning tools such as Prisma Cloud/Twistlock, JFrog, or Trivy, including reconciling findings across tools

- Comfort building or maintaining SAST/DAST pipeline automation, and triaging what the scans turn up

- Experience partnering with Engineering to get fixes prioritized and shipped, not just reported

- Background in a highly regulated environment or modern software company, ideally one that moves at startup or scale-up speed

- Strong scripting ability, Python preferred

- Working knowledge of CVSS v3.1/v4.0 scoring and the judgment to assess risk, not just report it

- Exploit development or PoC skills to validate real-world exploitability of CVEs, using tools like Burp Suite

- Familiarity with OWASP Top 10 and testing methodology

- Working knowledge of containers and Kubernetes, plus core Linux, AWS, and networking fundamentals

- Basic understanding of authentication/authorization conc

Flights + hotels

This role requires you to be in India. If that means relocating or flying in, it is worth checking fares before you commit to a start date.

Compare flights and hotels โ†’

โ† All remote jobs

Get new remote jobs like this by email
Daily email, only when there's something new. One click to stop.

Get remote jobs like this by email

10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.

Similar for you