Security Engineer – Vulnerability Research
Endor Labs · Bengaluru
Job description
About the role
The primary focus of this position is to help the team further advance Endor Labs' proprietary vulnerability database — extending and improving our existing AI pipelines, e.g., in the areas of automated vulnerability validation, reachability analysis, and exploit generation. Day‑to‑day work includes monitoring and managing pipelines that triage, enrich, and prioritize vulnerabilities at scale, working with the standards and data sources the ecosystem is built on and continuously improving the accuracy, coverage, and timeliness of our data.
Key responsibilities
- Advance and improve Endor Labs' proprietary vulnerability database and AI pipelines, including automated validation, reachability analysis, and exploit generation.
- Monitor and manage pipelines that triage, enrich, and prioritize vulnerabilities at scale, leveraging standards such as CVE, CWE, CVSS, EPSS, PURL, NVD, OSV, GHSA, and VEX.
- Collaborate with world‑class 0‑day researchers to scale automated vulnerability discovery, turning manual workflows into repeatable, production‑grade systems.
- Investigate high‑impact vulnerabilities and the broader vulnerability landscape, authoring blog posts, technical write‑ups, and advisories for both technical and non‑technical audiences.
- Work with internal teams to feed findings into detection and analysis pipelines, enrich the vulnerability database, and improve automated coverage over time.
Required profile
- Bachelor’s degree in engineering or related field with at least 3 years of hands‑on experience in vulnerability research, vulnerability management, product security, or application security.
- Extensive knowledge of software vulnerabilities, triage, and prioritization, with deep familiarity with standards and technologies such as CVE, CWE, CVSS, EPSS, PURLs, NVD, OSV, VEX, and SBOM formats.
- Hands‑on experience building production‑grade solutions at enterprise scale, including CI/CD automation and management of SAST/SCA findings across large engineering organizations.
- Demonstrated experience shipping AI/agentic systems to production, including LLM pipelines, agent frameworks, tool use, prompt and evaluation design, with a track record of measuring output quality.
- Proficiency in reading and analyzing code across multiple languages (Python, JavaScript/TypeScript, Java, Go) and reasoning about patches, root causes, and exploitability.
- Experience producing external security communications such as blog posts, advisories, or technical reports for public or customer‑facing audiences.
Required skills
- Python
- JavaScript/TypeScript
- Java
- Go
- CI/CD automation
- SAST/SCA tooling
- AI/LLM pipeline development
- Prompt and evaluation design
- Vulnerability standards (CVE, CWE, CVSS, EPSS, PURL, NVD, OSV, GHSA, VEX, SBOM)
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in India.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 2 hours ago
Expires 1 month from now
5 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Endor Labs
Bengaluru
Related job offers
-
Senior Product Security Engineer I
DigitalOcean Bengaluru -
Senior Application Security Engineer – Security Platform
DigitalOcean Bengaluru -
Principal Software Engineer – Security (AI/ML)
DigitalOcean Bengaluru -
Security Engineer – Product & AI Security
Dialpad Bengaluru -
Security Operations Centre Specialist II
Deliveroo Hyderabad