SlipstreamJobsFresh Startup & VC-Backed Jobs

Security Engineer - Vulnerability Management

Endor Labs - Bengaluru, India - In-office - posted 2026-08-31

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Endor Labs is seeking a Security Engineer to advance its proprietary vulnerability database and AI-driven vulnerability management platform. The role focuses on extending and improving AI pipelines for automated vulnerability validation, reachability analysis, and exploit generation. Day-to-day responsibilities include monitoring and managing vulnerability triage, enrichment, and prioritization pipelines at scale. You'll work with industry standards and data sources (CVE, CWE, CVSS, EPSS, PURL, NVD, OSV, GHSA, VEX) to continuously improve data accuracy, coverage, and timeliness. Collaboration with world-class 0-day researchers is central to scaling automated vulnerability discovery—transforming manual research workflows into production-grade systems. You will investigate high-impact vulnerabilities and the broader vulnerability landscape, authoring external-facing content including blog posts, technical write-ups, and security advisories for both technical and non-technical audiences. Internal collaboration feeds findings into detection and analysis pipelines, enriching the vulnerability database and improving automated coverage over time. Required qualifications include a bachelor's degree in engineering or related field with at least 3 years of hands-on experience in vulnerability research, vulnerability management, product security, or application security. You must have extensive knowledge of software vulnerabilities, triage, and prioritization standards (CVE, CWE, CVSS, EPSS, PURLs, NVD, OSV, VEX, SBOM formats). Hands-on experience building production-grade solutions at enterprise scale is essential—CI/CD automation, SAST/SCA findings management, or comparable security tooling deployed across large organizations. Demonstrated experience shipping AI/agentic systems to production is required, including LLM pipelines, agent frameworks, tool use, and prompt/eval design with clear quality measurement and judgment about where these approaches succeed. Proficiency in reading and analyzing code across multiple languages (Python, JavaScript/TypeScript, Java, Go) is necessary, along with comfort reasoning about patches, root causes, and exploitability. Experience producing external security communications (blog posts, advisories, technical reports) is required. Nice-to-have skills include proof-of-concept exploit writing, fuzzing, static analysis, automated vulnerability discovery, contributions to open source vulnerability databases, familiarity with SAST/SCA/DAST tooling, understanding of software supply chain security standards (SLSA, SSDF), prior public research or CVE credits, and security certifications (OSCP, OSCE).

Similar roles