Vulnerability Engineer at Domino Data Lab | Torre

Vulnerability Engineer

Emma highlights
This highlight was written by Emma’s AI. Ask Emma to edit it.
Full-time

Legal agreement: Employment

Provide your expected compensation while applying
location_on
Remote (for India residents)
Shared by
Emma of Torre.ai
18 days ago

Responsibilities


Who we areAt Domino, we build software that helps the largest, AI-driven organizations build and operate advanced data science and AI solutions at scale. Our platform integrates a streamlined model development environment, MLOps capabilities, and novel features for collaboration, reuse, and reproducibility — all of which make data science teams more productive, reduce time to value, and ensure compliance. Our customers — like Johnson & Johnson, GSK, Bristol Myers, UBS, FINRA and the US Navy — are using our software to solve some of the most important challenges in the world, such as developing new medicines, securing our financial markets, or protecting our country. Backed by Sequoia Capital, Coatue Management, NVIDIA, Snowflake and other leading investors, we have been in business for a decade but are still a small team operating with the spirit of a startup. Especially in the world of AI today, we believe that the future is still being invented — and we want to be the ones building it. For more information, visit www.domino.aiWhat we are buildingDomino's Security team safeguards a platform trusted by some of the most regulated organizations in the world, across financial services, pharma, government, and defense. Vulnerability Management is where that trust gets tested day to day: finding, triaging, and closing out risk across our OS, container, and dependency surface, and giving customers a clear, defensible answer when they ask how exposed they are. This role joins that function as it scales, working closely with our Staff Security Engineer to turn a fast-growing vulnerability workload into faster, more consistent risk assessments.What your impact will beIn your first year, your impact will be:Faster, more consistent Vulnerability Risk Assessments. You'll own first-pass CVSS scoring and exploitability analysis, closing the SLA gap between finding and answerValidated, trustworthy triage. You'll reproduce and confirm customer-reported and pen-test findings before they reach Engineering, so fix priority reflects real exploitability, not just scanner severityReliable scanning pipelines. You'll keep SAST/DAST and vulnerability scanning automations running, troubleshooting failures and tuning configs so the data everyone relies on stays cleanReal partnership with Engineering. You'll build or run PoC exploits on select CVEs, bringing validated risk, not just findings, into prioritization conversationsMore capacity for the function. You'll free up our Staff Security Engineer to focus on program-level improvement instead of carrying all of vulnerability management's day-to-day loadWhat we look for in this roleHands-on experience managing vulnerabilities for a large SaaS product, across OS, container, and dependency exposureA track record triaging and tracking CVEs for a SaaS or containerized product: reading scan reports, prioritizing by severity, and following through to resolutionExperience reproducing and validating reported vulnerabilities, whether from customer disclosures or pen test findings, not just logging themTime spent with vulnerability scanning tools such as Prisma Cloud/Twistlock, JFrog, or Trivy, including reconciling findings across toolsComfort building or maintaining SAST/DAST pipeline automation, and triaging what the scans turn upExperience partnering with Engineering to get fixes prioritized and shipped, not just reportedBackground in a highly regulated environment or modern software company, ideally one that moves at startup or scale-up speedStrong scripting ability, Python preferredWorking knowledge of CVSS v3.1/v4.0 scoring and the judgment to assess risk, not just report itExploit development or PoC skills to validate real-world exploitability of CVEs, using tools like Burp SuiteFamiliarity with OWASP Top 10 and testing methodologyWorking knowledge of containers and Kubernetes, plus core Linux, AWS, and networking fundamentalsBasic understanding of authentication/authorization concepts (tokens, session handling, auth bypass patterns) and API security fundamentalsBasic threat modeling: thinking in attack paths, not just isolated severity scoresClear communication, comfortable navigating risk conversations with Engineering and customers, including drafting risk statements a non-technical audience will actually readComfort operating with ambiguity, since not every finding arrives with a clean severity or fix pathNice to have:OSWA, OSWE, or a similar offensive security certification (e.g. GWAPT, GPEN)Familiarity with Airflow and SnowflakeWhat we valueWe value a growth mindset. High-performing creative individuals who dig into problems and see the opportunities for successWe believe in individuals who seek truth and speak the truth and can be their whole selves at workWe value all of you that believe improving is always possible At Domino Everything is a work in progress – we can do better at everythingWe emphasize an environment of teaching and learning to equip employees with the tools needed to be successful in their function and the companyWe strongly believe in the value of growing a diverse team and encourage people of all backgrounds, genders, ethnicities, abilities, and sexual orientations to apply#LI-Remote