Senior DevSecOps Engineer II (Vuln Mgmt and Internal Security Tools)

Job Description

Who We Are

Having surpassed $150M ARR and continuing to grow rapidly, AuditBoard is the leading audit, risk, and compliance platform on the market. More than 40% of the Fortune 500, including 6 of the Fortune 10, leverage our award-winning technology to move their businesses forward with greater clarity and agility. And our customers love us: AuditBoard is top-rated on and Gartner Peer Insights.

At AuditBoard we inspire each other to innovate and are proud of what we are producing. We spend each day thinking of new ways to help our customers and contribute to the greater good of our company and our surrounding communities. We are all about assisting each other and breaking through barriers to create the most loved audit, risk, and compliance platform by our customers. This is how we have become one of the 500 fastest-growing tech companies in North America for the fourth year in a row as ranked by Deloitte! 

Why This Role is Exciting

AuditBoard is looking for a passionate and experienced Senior Security Engineer (Vulnerability Management) who​ ​will​ be responsible for vulnerability assessments, triage, management, reporting, and associated engineering required to protect and maintain the enterprise's overall security. The vulnerability management engineer will develop and maintain internal security team assessment tooling and capabilities 

This role will also play an instrumental role in the design and enhancement of cloud and container security baselines, configuring cloud security assessment tool(s), analyzing results, identifying meaningful threats, and recommending remediation actions.

Key Responsibilities: 

  • Promptly responding to security threats and incidents, acting individually and as part of a team to resolve issues.
  • Participate in cross-team efforts to design, develop, deploy, and maintain cloud and containerized infrastructure to enable high-performance SaaS applications globally in the cloud.
  • Drive enhancements to standard baselines for cloud and container security in line with security frameworks and benchmarks
  • Assist with remediation of discovered security vulnerabilities on cloud platforms such as AWS, Azure, and containerized applications built on Kubernetes. 
  • Creating thorough reports and documentation of all vulnerabilities and configuration findings; presenting findings to team and leadership on a routine basis
  • Assist with other Security Compliance activities as required

Attributes for a Successful Candidate

  • 3 - 5 years working experience within Information Security related fields
  • BS or MS in computer science or related field
  • Experience with scripting languages such as Python, Bash, PowerShell, node.js, and infrastructure automation languages such as HCL (Terraform). 
  • Knowledge of operating systems including Linux/Unix and Windows and containerization/virtualization technologies including docker and Kubernetes. 
  • Technical understanding and competence with Public Cloud platforms especially AWS and Azure
  • Experience with building and securing CICD pipelines and incorporating supply chain security best practices. 
  • Experience with security assessment tools (SCA, SAST, DAST, CSPM) such as Qualys, SonarCloud, Prisma, or similar is a plus. 
  • Excellent organization, time management, and attention to detail 
  • Must be action-oriented and have a proactive approach to solving issues
  • Ability to work within an on-call shift rotation
  • Launch a career at one of the fastest-growing SaaS companies in North America!
  • Live your best life (LYBL)! $200/mo for anything that enhances your life
  • Remote and hybrid work options, plus lunch in the office
  • Comprehensive employee health coverage (all locations)
  • 401K with match (US) or pension with match (UK)
  • Competitive compensation & bonus program
  • Flexible Vacation (US exempt & CA) or 25 days (UK)
  • Time off for your birthday & volunteering
  • Unlimited access to LinkedIn Learning
  • Employee resource groups
  • Stock options
  • Opportunities for team and company-wide get togethers!


*perks may vary based on eligibility