Domino Data Lab

Vulnerability Engineer

Domino Data Lab

Itanagar, Arunachal Pradesh, India · Full Time

Be the first to apply

Experience
Any
Salary
Openings
1
Posted
1 week ago
Work mode
In office
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About Domino Data Lab

Domino Data Lab develops software that empowers large AI-driven organizations to create and deploy sophisticated data science and AI applications at scale. The platform offers a unified environment for model development, MLOps functions, and innovative tools for collaboration, reuse, and reproducibility—enhancing productivity, accelerating value, and ensuring compliance. Clients including Johnson & Johnson, GSK, Bristol Myers, UBS, FINRA, and the US Navy utilize Domino's solutions to address critical challenges such as drug development, financial market security, and national defense. Supported by prominent investors like Sequoia Capital, Coatue Management, NVIDIA, and Snowflake, Domino operates with a startup mentality despite a decade in business.

Role Overview

The Security team at Domino safeguards a platform relied upon by highly regulated sectors like finance, pharmaceuticals, government, and defense. Within this team, Vulnerability Management plays a key role, focusing on identifying, prioritizing, and mitigating risks across operating systems, containers, and software dependencies. This position supports the growth of the vulnerability management function by collaborating closely with the Staff Security Engineer to improve the speed and consistency of risk assessments.

Key Responsibilities

  • Conduct initial CVSS scoring and evaluate exploitability to accelerate and standardize vulnerability risk assessments, minimizing response time from detection to resolution.
  • Validate and verify vulnerabilities reported by customers or penetration tests before escalating to engineering, ensuring prioritization aligns with actual exploit risks rather than scanner-reported severity levels.
  • Maintain and troubleshoot automated scanning pipelines (including SAST and DAST tools), ensuring consistent and accurate vulnerability data is available to all stakeholders.
  • Work collaboratively with engineering teams, developing or executing proof-of-concept exploits for selected CVEs to provide validated risk insights during prioritization discussions.
  • Increase the operational capacity of the vulnerability management function, enabling leadership to focus on strategic improvements instead of daily workload.

Qualifications and Skills

  • Proven experience managing vulnerabilities in a large SaaS environment, with expertise covering operating systems, containerized applications, and software dependencies.
  • Demonstrated ability to triage and track CVEs for SaaS or containerized products, interpreting scan outputs, prioritizing by severity, and seeing issues through to resolution.
  • Experience reproducing and confirming reported vulnerabilities from both customer disclosures and penetration testing.
  • Proficiency with vulnerability scanning tools such as Prisma Cloud (Twistlock), JFrog, or Trivy, including reconciling findings across multiple scanners.
  • Background in developing or sustaining SAST/DAST automation pipelines and effectively triaging scan results.
  • Excellent collaboration skills working with engineering teams to ensure timely prioritization and deployment of fixes.
  • Experience operating in highly regulated environments or fast-paced software companies resembling startup or scale-up dynamics.
  • Strong scripting skills, favoring Python, to automate and support vulnerability management processes.
  • Solid understanding of CVSS versions 3.1 and 4.0, with sound judgment to accurately assess risk beyond numeric scores.
  • Capability in exploit development or crafting proof-of-concept exploits with tools like Burp Suite to validate real-world exploitability.
  • Familiarity with OWASP Top 10 vulnerabilities and testing methodologies.
  • Knowledge of containers, Kubernetes, Linux fundamentals, AWS services, and networking basics.
  • Basic grasp of authentication and authorization principles, including tokens, session management, and common bypass patterns, along with API security fundamentals.
  • Understanding of threat modeling concepts focusing on attack vectors and paths rather than isolated severity metrics.
  • Strong communication skills comfortable engaging with both technical teams and non-technical customers by articulating risk clearly.
  • Ability to work effectively amid uncertainty, accommodating findings that may lack clear severity or straightforward remediation plans.

Preferred Qualifications

  • Possession of offensive security certifications such as OSWA, OSWE, GWAPT, or GPEN is advantageous.
  • Familiarity with Airflow and Snowflake data platforms adds value.

Our Values

  • A culture that encourages continuous learning, adaptability, and problem-solving creativity.
  • An emphasis on honesty, authenticity, and inclusivity where individuals can fully express themselves.
  • Commitment to continual improvement and openness to feedback as core aspects of our work environment.
  • Strong support for diversity in all forms, welcoming applicants from all genders, ethnicities, abilities, and orientations.
  • A nurturing learning environment empowering employees with necessary tools and knowledge to succeed.

How they work

Communication Teamwork & Collaboration Adaptability
🤖
Online · instant AI help
Broxer