Senior DevSecOps Engineer II, Vulnerability Management (Remote)

Job Description

Who We Are

Having surpassed $200M ARR and continuing to grow rapidly, AuditBoard is the leading audit, risk, ESG, and InfoSec platform on the market. Nearly 50% of the Fortune 500, including 7 of the Fortune 10, leverage our award-winning technology to move their businesses forward with greater clarity and agility. And our customers love us: AuditBoard is top-rated on G2.com and Gartner Peer Insights.


At AuditBoard we inspire each other to innovate and are proud of what we are producing. We spend each day thinking of new ways to help our customers and contribute to the greater good of our company and our surrounding communities. We are all about assisting each other and breaking through barriers to create the most loved audit, risk, ESG, and InfoSec platform by our customers. This is how we have become one of the 500 fastest-growing tech companies in North America for the fifth year in a row as ranked by Deloitte!

AuditBoard is looking for a passionate and experienced Senior Security Engineer II, Vulnerability Management who​ ​will​ be responsible for vulnerability assessments, triage, management, reporting and associated engineering required to protect and maintain the overall security of the enterprise. The vulnerability management engineer will develop and maintain internal security team assessment tooling and capabilities 

This role will also play an instrumental role in the design and enhancement of cloud and container security baselines, configure cloud security assessment tool(s), analyze results, identify meaningful threats, and recommend remediation actions.

We’re based in Los Angeles, growing rapidly and looking for bright, motivated people to join us! Learn more at auditboard.com.

Responsibilities: 

  • Develop, integrate and maintain internal security team systems and CIDC pipelines, including those used to detect and manage security vulnerabilities. 

  • Creating thorough reports and documentation of all vulnerabilities and configuration findings; presenting findings to team leadership on a routine basis. 

  • Assist with remediation of discovered security vulnerabilities on cloud platforms such as AWS, Azure, and containerized applications built on Kubernetes. 

  • Participate in cross-team efforts to design, develop, deploy, and maintain cloud and containerized infrastructure to enable high performance SaaS applications globally in the cloud.

  • Drive enhancements to standard baselines for cloud and container security in line with security frameworks and benchmarks

  • Promptly respond to security threats and incidents, acting individually and as part of a team to resolve issues as necessary.

  • Assist with other Security Compliance activities as required

Requirements

  • 3 - 5 years working experience within Information Security related fields

  • BS or MS in computer science or related field

  • Experience with scripting languages such as Python, Bash, PowerShell, and infrastructure automation languages such as HCL (Terraform). 

  • Knowledge of operating systems including Linux/Unix and Windows, as well as containerization/virtualization technologies including docker and kubernetes. 

  • Technical understanding and competence with Public Cloud platforms especially AWS and Azure.

  • Experience with building and securing CICD pipelines and incorporating supply chain security best practices. 

  • Experience with security assessment tools (SCA, SAST, DAST, CSPM) such as Qualys, SonarCloud, Prisma or similar is a plus. 

  • Excellent organization, time management, and attention to detail 

  • Must be action-oriented and have a proactive approach to solving issues

Perks*

  • Launch a career at one of the fastest-growing SaaS companies in North America!

  • Live your best life (LYBL)! $200/mo for anything that enhances your life

  • Remote and hybrid work options, plus lunch in the Cerritos office

  • Comprehensive employee health coverage (all locations)

  • 401K with match (US) or pension with match (UK)

  • Competitive compensation & bonus program

  • Flexible Vacation (US exempt & CA) or 25 days (UK)

  • Time off for your birthday & volunteering

  • Employee resource groups

  • Opportunities for team and company-wide get-togethers!

*perks may vary based on eligibility

Please note that background checks are required. Qualified Applicants with arrest or conviction records will be considered for Employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. This role may have access to highly sensitive data, including: employee data, customer data, company financials, and proprietary product information.

 

#LI-Remote