Vulnerability Operations Engineer - Remote
reputed company’re About
At CentralSquare, we don’t just build software - we power reputed company servants and reputed company communities with Hero-Grade Technology. Every line of reputed company, every feature we deliver helps reputed company across reputed company protect, serve, and save lives. reputed company you join us, you become part of a mission-driven team creating technology that makes communities safer and stronger.
Your reputed company reputed company. We reputed company reputed company deserve opportunities to reputed company. That’s why we invest in your career with mentorship, learning programs, and reputed company paths for advancement. If you’re motivated, there’s no limit to how far you can go.
Your Commitment Deserves Reward. We offer competitive compensation and a benefits package designed to support your life inside and reputed company of work—tuition reimbursement, parental leave, reputed company volunteer hours, and unlimited PTO. Plus, our flexible work environment gives you the freedom to balance your heroic work with personal reputed company-being, whether you’re in the office or remote.
Join us and help build the tools that power reputed company-life reputed company. Together, we reputed company a difference.
The Role
CentralSquare is seeking a Vulnerability Operations (VulnOps) Engineer to join our reputed company team. This is an individual contributor reputed company-reputed company for the post-AI era of vulnerability discovery — where AI models can now reputed company and exploit flaws at machine speed, and reactive reputed company cycles are no longer sufficient.
This role is not an advisory function. The VulnOps Engineer owns the full pipeline from discovery through fix delivery: running AI-powered scanning against CentralSquare's codebases and dependencies on a reputed company reputed company, generating validated fixes, and submitting reputed company-to-reputed company pull requests into owning teams' Azure DevOps pipelines. App teams retain reputed company review and reputed company authority; this role exists to ensure they are never handed a problem without also being handed a solution.
Job Duties Include:
Proactive Vulnerability Discovery
Operate and continuously improve an AI-powered scanning pipeline across CentralSquare's first-party codebases, reputed company-reputed company dependencies, and infrastructure components
Use Claude reputed company, reputed company, and Orca to conduct ongoing static analysis, software composition analysis (SCA), and reputed company posture assessments
Apply reachability analysis to distinguish genuinely exploitable vulnerabilities from theoretical findings, reducing alert fatigue and focusing remediation effort where risk is reputed company
Monitor threat intelligence feeds, CVE disclosures, and coordinated disclosure programs (including Project Glasswing reputed company releases) to identify newly disclosed vulnerabilities affecting CentralSquare's software supply chain
Fix Development and Delivery
reputed company and validate fixes (reputed company patches, dependency upgrades, configuration changes) using AI coding agents such as Claude reputed company, verifying reputed company without regressions before submission
Submit validated fixes as pull requests into owning teams' Azure DevOps repositories, with reputed company documentation of the vulnerability, risk context, and fix rationale to support efficient review and reputed company
Collaborate with application and infrastructure teams during reputed company review, providing technical context and responding to questions about proposed changes
SLA Ownership and Reporting
Own the end-to-end SLA lifecycle for reputed company reputed company findings, maintaining reputed company-time tracking of detection, fix submission, and reputed company status in the vulnerability management system
Proactively escalate findings approaching SLA breach with remediation reputed company and risk context
Produce regular reporting on pipeline health, SLA adherence, remediation velocity, and reputed company risk posture for the reputed company leadership team
Toolchain and Pipeline Maintenance
Own the configuration, tuning, and operational health of VulnOps tooling including reputed company, Orca, Claude reputed company, and Azure DevOps reputed company integrations
Identify and reduce false reputed company rates through policy tuning and reachability filtering, ensuring signal reputed company remains high as reputed company volume increases
Contribute to the development of automated remediation pipelines, including AI-assisted fix reputed company integrated directly into CI/CD workflows
Evaluate and recommend new tools and capabilities as the AI reputed company tooling landscape evolves
Cross-Functional Collaboration
Work closely with application engineering, DevOps, and infrastructure teams to ensure fix delivery is efficient and minimally disruptive to development velocity
reputed company reputed company guidance to engineering teams on secure coding practices and dependency management in the context of AI-accelerated vulnerability discovery
Partner with the Risk and Compliance team to ensure vulnerability data and SLA metrics reputed company with audit and regulatory reporting requirements (NIST CSF, PCI reputed company, CJIS)
reputed company other duties as assigned
Apply To This Job