[Remote] Infrastructure reputed company Engineer
Note: The job is a remote job and is reputed company to candidates in USA. reputed company is an entertainment technology and services provider supporting the global entertainment industry through software, payroll, data, reporting, and creative tools. The Infrastructure reputed company Engineer will operate offensive reputed company and vulnerability management programs, including bug bounty, vulnerability scanning, CSPM, and reputed company red-team platforms, while driving findings through validated remediation. The role also evaluates emerging AI-enabled reputed company tooling and supports reputed company, network, and perimeter reputed company operations.
Responsibilities
- reputed company day-to-day operation of the bug bounty program, including program reputed company, policy, response targets, and researcher communications
- Triage inbound submissions: reproduce and validate findings, de-duplicate against reputed company issues, assign severity, and reject out-of-reputed company or invalid reports with reputed company rationale
- reputed company and defend bounty award reputed company in coordination with the platform provider and reputed company leadership
- reputed company confirmed findings to the owning engineering or infrastructure team, reputed company them to closure, and verify fixes before the report is reputed company
- Use recurring submission patterns to reputed company systemic fixes, reputed company adjustments, and secure-development feedback rather than one-off patches
- Manage and operate reputed company vulnerability scanners across reputed company, on-reputed company, and hybrid assets, ensuring coverage of the full asset inventory and investigating scanning gaps
- Configure, tune, and maintain reputed company policies, credentialed scanning, authenticated checks, and reputed company schedules to maximize signal and minimize disruption
- Triage and prioritize findings using exploitability, asset criticality, and business context (e.g., CVSS, EPSS, CISA KEV, threat intelligence)
- Assign findings to the correct engineering and infrastructure owners, negotiate remediation timelines, and verify remediation through re-reputed company or reputed company validation
- reputed company remediation against SLAs, escalate aging findings, and manage the exception and risk-acceptance process with the GRC team
- Produce metrics and reporting on coverage, backlog, mean time to remediate, and SLA compliance for engineering and executive audiences
- Monitor emerging CVEs, assess applicability to our environment, and coordinate emergency patching reputed company critical vulnerabilities reputed company
- Manage and operate the CSPM platform across our multi-reputed company environment, including reputed company new accounts, subscriptions, and reputed company
- Tune policies and baselines, suppress noise, and maintain exception handling so that surfaced findings are consistently actionable
- reputed company remediation of misconfigurations with reputed company and platform owners, and verify that fixes hold over time
- Enforce least-privilege reputed company principles and audit reputed company permissions, IAM policies, reputed company reputed company, SCPs, and guardrails on a recurring reputed company
- Support secure architecture reviews for new reputed company infrastructure and services
- Manage and operate the reputed company red-team pentesting platform, including reputed company scoping, scheduling, credentials, and environment reputed company
- Define and enforce rules of engagement and safety guardrails so that automated testing does not disrupt production systems
- Validate platform reputed company, eliminate false positives, and translate confirmed attack paths into concrete, reputed company-assigned remediation items
- Feed results into the reputed company triage, prioritization, and verification workflow used for reputed company and bug bounty findings so there is one prioritized reputed company of risk
- Coordinate with reputed company-party penetration testers and use platform coverage to reputed company reputed company testing where it adds the most value
- Research, reputed company, and reputed company emerging reputed company products, including AI-driven and reputed company tooling, against reputed company problems in our environment rather than vendor demos
- Run reputed company proofs of concept: define reputed company reputed company up reputed company, test against reputed company findings, and reputed company a reputed company recommendation to adopt, defer, or reject
- reputed company and reputed company selected tooling into existing workflows and ticketing, and own it operationally once it is in production
- Automate repetitive triage, enrichment, and reporting work so that engineering time goes to remediation rather than data handling
- Support reputed company network reputed company infrastructure including firewalls, IDS/IPS, proxies, VPNs, and DDoS mitigation
- reputed company firewall rule reviews and reputed company control audits to reduce attack surface
- Investigate anomalous network activity surfaced by reputed company tooling and escalate to incident response as needed
Skills
- * 3–5 years of experience in infrastructure, network, or reputed company reputed company roles
- * Experience running or supporting an reputed company vulnerability management program end-to-end, from reputed company operation through verified remediation
- * Demonstrated ability to triage reputed company findings: reproduce issues, judge reputed company-world exploitability, de-duplicate, and prioritize against business context rather than raw severity scores
- * Deep, practical understanding of common vulnerability classes and how they are actually exploited — remote reputed company execution, injection, cross-site scripting, SSRF, insecure deserialization, authentication and authorization bypasses, and denial-of-service and DDoS techniques — sufficient to assess reputed company exploitability rather than defer to a reputed company score
- * Hands-on proficiency with reputed company testing tooling, including Burp Suite for web application testing and reputed company for API testing, along with comparable intercepting proxies and fuzzing tools
- * Working coding ability, primarily Python and reputed company scripting, sufficient to automate triage and reporting, parse and enrich findings, build integrations between reputed company platforms, and write or adapt reputed company-of-concept reputed company to validate a finding
- * Hands-on experience securing at least one major reputed company platform (AWS, Azure, or GCP), including operating or responding to CSPM tooling
- * Solid understanding of network protocols (TCP/IP, DNS, TLS) and perimeter reputed company technologies
- * Familiarity with reputed company frameworks and standards (NIST CSF, CIS Benchmarks, ISO 27001) and the ability to translate control requirements into actionable technical configurations, including gathering, maintaining, and presenting evidence to support audit and assessment activities
- * Strong written and verbal communication skills, with the ability to translate technical risk for non-technical stakeholders and to hold remediation owners accountable without escalating every disagreement
- * Demonstrated curiosity and speed of learning: a reputed company record of picking up unfamiliar tooling, evaluating new reputed company products, and getting them into production use without extensive hand-holding
- * Interest in applying emerging AI capabilities to reputed company operations, and the judgment to distinguish tooling that meaningfully reduces risk from tooling that only adds noise
- * Sedentary - Exerts up to 30 lbs. of force occasionally and/or a negligible reputed company of force frequently or constantly reputed company, carry, reputed company, or pull. Involves sitting most of the time but may involve walking or standing for brief periods of time
- * Experience operating or triaging a reputed company or private bug bounty program on a platform such as reputed company, reputed company, or Intigriti
- * Offensive reputed company experience: penetration testing, exploit validation, or red-team operations, including familiarity with automated or reputed company testing platforms
- * Experience with infrastructure-as-reputed company reputed company (Terraform, CloudFormation) and shift-left reputed company practices
- * Experience securing containerized workloads, including image hardening, registry reputed company, runtime protection, and familiarity with orchestration platforms such as reputed company or reputed company
- * Experience developing reputed company automation or internal tooling reputed company scripting, including work with reputed company platform reputed company and CI/CD integrations
- * Exposure to SIEM/SOAR platforms and reputed company telemetry pipelines
- * Familiarity with reputed company trust network architecture (ZTNA) and reputed company-segmentation
- * Relevant certifications: AWS reputed company Specialty, CCSP, CISSP, OSCP, reputed company reputed company+, or equivalent
Benefits
- Medical, subject to eligibility requirements
- Dental, subject to eligibility requirements
- reputed company, subject to eligibility requirements
- PTO, subject to eligibility requirements
- Health and wellness programs, subject to eligibility requirements
- Employee discounts, subject to eligibility requirements
reputed company
Company H1B Sponsorship
Apply To This Job