Senior Vulnerability and Risk Engineer

| Remote
Sorry, this job was removed at 3:09 a.m. (PST) on Thursday, February 4, 2021
Find out who's hiring remotely in San Francisco.
See all Remote Cybersecurity + IT jobs in San Francisco
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

We’re Cruise, the self-driving ride-hailing service.

We are building the world’s most advanced self-driving vehicles to safely connect people to the places, things, and experiences they care about. We believe self-driving vehicles  will help save lives, reshape cities, give back time in transit, and restore freedom of movement for many.

At Cruise, our engineers have opportunities to grow and develop while learning from leaders at the cutting-edge of their fields. With a culture of internal mobility, there's opportunity to thrive in a variety of disciplines. This is a place for dreamers and doers to succeed.

If you are looking to solve one of today’s most complex engineering challenges, see the results of your work in hundreds of self-driving cars, and make a positive impact in the world starting in our cities, join us.

We are looking for someone who understands how vulnerabilities translate to significant incidents in both traditional and cloud based environments.  As a technical expert, you will translate requirements into scalable processes and technologies, formulate and prioritize risks, collaborate with asset owners to prioritize vulnerability remediation, and create measures and processes that ensure our efficient resolution of risks.

As the Staff Vulnerability & Risk Management Engineer you will report to the Director of Security Assurance and Trust. Given the nature of the role, you will be a point of contact for a wide range of teams and folks at all levels of the organization. We are ok with fully remote candidates. 

What you'll be doing:

  • Creation and review of requirements for vulnerability management systems
    inclusive of their upstream and downstream dependencies
  • Detection, assessment, and ranking of vulnerabilities to ensure protection of our
    most valuable resources from their most serious vulnerability exploits
  • Work with TPM, IT, and asset owners to achieve timely remediation actions
  • Aid in the measurement and continuous improvement of the aforementioned
  • Foster and maintain a fiduciary obligation with your stakeholders: be a credible,
    reliable, and trustworthy partner and subject matter expert

What you must have:

  • 5 years or more of related experience that demonstrates:
    • Strong familiarity with commodity vulnerabilities via Nessus, Qualys, Prisma, Redlock, Twistlock, and like systems
    • Fluency in all industry standard vulnerability types OWASP, CSA, and like
    • Familiarity with vetting and disposition of non-commodity vulnerabilities via application security or red team findings; the ability to validate potential vulnerabilities or design remeditations to vulnerabilities with non-obvious mitigations
    • Fluency in scripting with Python, shell, or like languages
    • 3 or more years leading departmental initiatives / work that changes how your team, department, or cybersecurity program does work
    • Fluency with agile or like structured planning framework; you must be comfortable and competent moving from high-level asks to UML like design while maintaining alignment and cohesion within the team
    • Experience with cloud and container based deployments, using AWS/GCP, Kubernetes, Docker etc.
    • Understanding of Linux, Mac, and Windows security controls.
  • Experience communicating at all levels of the organization; meeting Cruiser’s at their level of expertise and the ability to bring others along will be critical to your success in this role  

Bonus points!

  • hackerone reputation score, Blackhat / Defcon presenter, or like bonafides
  • One or more of the following certifications: OSCP, OSCE, GVEA, GCIH, GCED, or like
  • Experience with security orchestration, automation, and deployment tools, and using Terraform
Read Full Job Description
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

Technology we use

  • Engineering
  • People Operations
    • JavaLanguages
    • MatlabLanguages
    • PythonLanguages
    • SqlLanguages
    • C Languages
    • Google HangoutsCollaboration
    • SlackCollaboration
    • ZoomCollaboration

Location

Our sleek, modern offices in San Francisco's SoMa neighborhood include catered meals, an on-site gym and stunning city views from our roof decks.

What are Cruise Perks + Benefits

Cruise Benefits Overview

A job at Cruise is meaningful. Your work on all-electric, self-driving vehicles will save lives, help the planet, and make cities better. It’s something to be proud of. It’s career-defining work. When you’re building something that’s never been done before, it’s important to feel safe — safe to experiment, safe to fail, safe to share, and safe to express yourself. At Cruise, we’re committed to the safety, inclusivity, and professional development of our employees from the recruiting process through retirement — and every professional milestone along the way. In addition to professional development perks, Cruise offers a range of robust medical, family and wellness benefits that ensure you and your family feel supported, safe, and healthy—whether working onsite or working from home.

Culture
Volunteer in local community
Partners with nonprofits
OKR operational model
Team based strategic planning
Open office floor plan
Flexible work schedule
Remote work program
Diversity
Dedicated diversity and inclusion staff
Mandated unconscious bias training
Diversity employee resource groups
Cruise Community Groups include: AAPI, Chai-paani, Cruisers of the African Diaspora, Empowering Women of Cruise, Families at Cruise, Latinx, LGBTQruise, Middle Easterners @ Cruise, and Veterans.
Health Insurance + Wellness
Flexible Spending Account (FSA)
Disability insurance
Dental insurance
Vision insurance
Health insurance
Life insurance
Wellness programs
Mental health benefits
Financial & Retirement
401(K)
401(K) matching
Company equity
We’ve developed a unique Recurring Liquidity Opportunity that gives Cruisers the potential upside of a private company and the liquidity of a public company.
Performance bonus
Child Care & Parental Leave
Generous parental leave
Family medical leave
Company sponsored family events
Vacation + Time Off
Unlimited vacation policy
Generous PTO
Paid holidays
Paid sick days
Office Perks
Commuter benefits
Company-sponsored outings
Free daily meals
Free snacks and drinks
Company-sponsored happy hours
Recreational clubs
Home-office stipend for remote employees
Onsite gym
Professional Development
Job training & conferences
Lunch and learns
Promote from within
Mentorship program
Continuing education stipend
Online course subscriptions available

More Jobs at Cruise

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about CruiseFind similar jobs like this