SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 191,000 - 293,000 / annual
Tanium is seeking a Senior Security Engineer to join the Customer Transparency team within the R&D Security organization. This team is responsible for making Tanium's security posture transparent and understandable to customers, rather than requiring blind trust.
In this role, you will represent Tanium's R&D Security organization to external stakeholders and take on several key responsibilities:
- Build and maintain security tooling, leveraging AI where appropriate to streamline security processes
- Identify visibility gaps in customers' Tanium deployments and partner with Engineering and Product teams to close them
- Oversee the SBOM and vulnerability management program, providing visibility to internal and external stakeholders
- Collaborate with customers, partners, and Tanium's customer-facing teams to understand actual security needs and build systems to address them
- Serve as a security technical resource for customer-facing teams: answer inbound security inquiries and escalations, maintain a library of reusable answers, and interface directly with customers when needed
- Administer Tanium's bug bounty program: triage inbound reports against SLA, assess exploitability and severity, adjudicate duplicates and out-of-scope submissions, recommend awards, and foster relationships with researchers
- Author and publish Tanium Security Advisories and CVE records, including CWE classification and CVSS scoring
- Coordinate disclosure timing and embargoes across researchers, customers, partners, and external coordinating bodies
Tanium is the Autonomous IT company, driven by AI and real-time endpoint intelligence. The company empowers IT and security teams with a unified platform for endpoint management and security. Tanium has been on the Forbes Cloud 100 list for ten consecutive years.
REQUIREMENTS:
- Bachelor's Degree in Computer Science or other relevant degree, or equivalent experience
- 5+ years industry experience (7+ preferred)
- Experience with product and application security, vulnerability research, or software engineering with substantial security focus
- Experience interacting with customers and external security researchers
- Experience applying AI tooling to security work, with informed perspective on where it helps versus where it creates noise
- Experience building tools or data interfaces used by external stakeholders, including support and customers
- Experience with modern software engineering development and automation tools like git and CI/CD pipelines
- Experience determining the severity and exploitability of vulnerabilities and their business impact
NICE TO HAVE:
- Familiarity with SCA/SBOM tooling and third-party dependency vulnerability management
- Experience with coordinated vulnerability disclosure and mechanics of CVE assignment, CVSS, and CWE; CNA operations experience
- Experience running or substantially supporting a bug bounty program or VDP
- Published vulnerability research, credited CVEs, bug bounty findings, open-source security tooling, or conference talks
- Working knowledge of Tanium's products and services
- Strong understanding of applied cryptography, including encryption, hashing, and secure key management