Domino Data Lab logo
Domino Data LabΒ·

Vulnerability Engineer - Domino Data Lab

Domino Data Lab builds solutions that help highly regulated organizations adopt AI, providing a platform for streamlined model development, hosting, and governance. Our customers include Johnson & Johnson, GSK, UBS, and the US Navy. We are a remote-first company, backed by leading investors, operating with a startup spirit.

Domino's Security team safeguards a platform trusted by some of the most regulated organizations globally. This role joins our Vulnerability Management function, which is critical for finding, triaging, and closing out risk across our OS, container, and dependency surface. You will work closely with our Staff Security Engineer to scale our vulnerability workload into faster, more consistent risk assessments.

What Your Impact Will Be

In your first year, your impact will include:

  • Faster, more consistent Vulnerability Risk Assessments: Own first-pass CVSS scoring and exploitability analysis, closing the SLA gap between finding and answer.
  • Validated, trustworthy triage: Reproduce and confirm customer-reported and pen-test findings before they reach Engineering, ensuring fix priority reflects real exploitability, not just scanner severity.
  • Reliable scanning pipelines: Keep SAST/DAST and vulnerability scanning automations running, troubleshooting failures and tuning configurations to maintain clean data.
  • Real partnership with Engineering: Build or run Proof-of-Concept (PoC) exploits on select CVEs, bringing validated risk, not just findings, into prioritization conversations.
  • Increased function capacity: Free up our Staff Security Engineer to focus on program-level improvement by taking on day-to-day vulnerability management load.

What We Look For In This Role

  • Hands-on experience managing vulnerabilities for a large SaaS product, across OS, container, and dependency exposure.
  • A track record triaging and tracking CVEs for a SaaS or containerized product: reading scan reports, prioritizing by severity, and following through to resolution.
  • Experience reproducing and validating reported vulnerabilities, whether from customer disclosures or pen test findings, not just logging them.
  • Time spent with vulnerability scanning tools such as Prisma Cloud/Twistlock, JFrog, or Trivy, including reconciling findings across tools.
  • Comfort building or maintaining SAST/DAST pipeline automation, and triaging what the scans turn up.
  • Experience partnering with Engineering to get fixes prioritized and shipped, not just reported.
  • Background in a highly regulated environment or modern software company, ideally one that moves at startup or scale-up speed.
  • Strong scripting ability, Python preferred.
  • Working knowledge of CVSS v3.1/v4.0 scoring and the judgment to assess risk, not just report it.
  • Exploit development or PoC skills to validate real-world exploitability of CVEs, using tools like Burp Suite.
  • Familiarity with OWASP Top 10 and testing methodology.
  • Working knowledge of containers and Kubernetes, plus core Linux, AWS, and networking fundamentals.
  • Basic understanding of authentication/authorization concepts (tokens, session handling, auth bypass patterns) and API security fundamentals.
  • Basic threat modeling: thinking in attack paths, not just isolated severity scores.
  • Clear communication, comfortable navigating risk conversations with Engineering and customers, including drafting risk statements a non-technical audience will actually read.
  • Comfort operating with ambiguity, since not every finding arrives with a clean severity or fix path.

Nice to have:

  • OSWA, OSWE, or a similar offensive security certification (e.g., GWAPT, GPEN).
  • Familiarity with Airflow and Snowflake.

What We Value

  • Growth Mindset: High-performing creative individuals who dig into problems and see opportunities for success.
  • Truth-Seeking: Individuals who seek truth and speak the truth, and can be their whole selves at work.
  • Continuous Improvement: Belief that improving is always possible; everything is a work in progress.
  • Teaching and Learning: An environment of teaching and learning to equip employees with tools for success.
  • Diversity: Strong belief in the value of growing a diverse team; people of all backgrounds, genders, ethnicities, abilities, and sexual orientations are encouraged to apply.

Timezone overlap

UTC+8–+12

Open to

APAC

Sign in to track applications and earn points.

More roles at Domino Data Lab

Similar remote roles