Security Vulnerability Engineer (R-00224)
True Zero is seeking a Security Vulnerability Engineer to lead the design, development, and
operation of advanced vulnerability management and threat-detection capabilities across
secure, mission-critical environments. This is a senior technical role for an engineer who pairs
hands-on expertise in security analytics, detection engineering, and predictive risk modeling
with the judgment to guide teams, engage clients, and deliver production-grade, responsibly
governed security solutions.
The ideal candidate brings a track record of directing security and analytics initiatives across
national security and highly regulated environments — combining technical depth in threat
detection and predictive modeling with the strategic acumen to reduce operational risk, minimize
exposure, and enable data-driven decision-making at the command level. This engineer will
configure data pipelines, establish security telemetry ingestion processes, and implement
predictive components that analyze five or more years of historical incident and vulnerability
data to generate time- and location-based risk forecasts that are operationally meaningful to
command staff and field leadership
Job Responsibilities
- Vulnerability Management: Identify, assess, and prioritize vulnerabilities across
enterprise systems; develop and tune detection logic and analytics that meet defined
performance and coverage standards.
- Threat Detection Engineering: Design, develop, and implement detection and
enrichment systems that analyze large volumes of unstructured security telemetry, logs,
and threat-intelligence data.
- Technical Leadership: Lead security engineering projects with a focus on detection,
vulnerability analytics, and emerging defensive technologies.
- Predictive Risk Modeling & Forecasting: Configure data pipelines and telemetry
ingestion processes and implement predictive components that analyze five or more years
of historical incident and vulnerability data to generate time- and location-based risk
forecasts.
- Systems Integration: Integrate detection and vulnerability-management solutions with
existing SIEM, ticketing, and operational systems to ensure seamless data flow and
usability within current workflows; collaborate with cross-functional teams, including work
within the STRIDE platform.
- Validation & Accuracy: Validate data integrity, detection performance, and system
reliability across security tooling; assess detection and forecast accuracy, ensure
alignment between predicted and observed threat patterns, and verify outputs are
operationally meaningful for command staff and field leadership.
- Performance Management: Monitor, evaluate, and continuously improve detection and
vulnerability-analytics performance; identify optimization opportunities and tune for scale,
efficiency, and low false-positive rates in cloud environments.
- Tool Utilization: Leverage common security and analytics tooling (SIEM, vulnerability
scanners, AWS security services, TensorFlow, PyTorch) and custom frameworks for
specialized detection applications.
- Governance & Risk: Assess model and detection risks, biases, and coverage gaps in accordance with responsible-use guidelines and regulatory requirements.
- Detection Operations (DetOps/MLOps): Implement practices to automate deployment,
monitoring, and lifecycle management of detections, analytics, and models.
Job Qualifications
- Experience: Minimum of 5 years in security engineering, vulnerability management, or
detection engineering, spanning design, evaluation, and deployment. - Citizenship: U.S. citizenship required; must be willing to undergo a U.S. Government
background investigation. - Technical Proficiency: Hands-on experience with security analytics and detection
frameworks, scripting/automation (Python), and major cloud platforms; familiarity with
PyTorch, TensorFlow, Keras, Hugging Face, LangChain, and API-driven tooling for
analytics is a strong plus. - Data Management: Experience with large-scale data stores, search/vector databases
(Pinecone, Weaviate, Qdrant, Chroma), and retrieval-based analysis architectures for
security use cases. - Advanced Analytics: Advanced query and detection engineering, model/detection tuning,
and hands-on experience with analytics and automation tooling. - Evaluation: Experience in detection and model evaluation, monitoring, validation,
benchmarking, and deployment
Skills
As published by lever
Resume/CV, Full name, Email, Phone, Current location, Current company, LinkedIn URL, Twitter URL, GitHub URL, Portfolio URL, Other Relevant URL