Senior Technical Security Engineer - Vulnerability Management
Yahoo
Job Overview
Who's the hiring manager?
Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Job Description
Senior Technical Security Engineer - Vulnerability Management at Yahoo
Yahoo serves as a trusted guide for hundreds of millions of people globally, helping them achieve their goals online through our portfolio of iconic products. For advertisers, Yahoo Advertising offers omnichannel solutions and powerful data to engage with our brands and deliver results.
A Little About Us
When you impact millions of people every day, you become a large target for adversaries of all types within all layers of the stack. Our job is to keep our users safe and make Yahoo one of the safest places on the Internet. We are the information security team at Yahoo; known as "The Paranoids".
About Our Team
Our job is to keep our users safe and make Yahoo one of the safest places on the Internet. The Vulnerability & Controls Operations team finds, triages, and tracks security weaknesses across infrastructure and cloud environments. We identify high-risk issues like zero-day vulnerabilities and cloud exposures.
A Lot About You
We are looking for a Senior Technical Security Engineer - Vulnerability Management to serve as the Program Lead for Vulnerability Management. This is a hybrid role that requires strong engineering skills and operational leadership. You will be the engine behind the scenes. You will identify and drive mitigation of vulnerabilities, manage requirements for automation, oversee vendor relationships, and utilize large datasets to identify risks.
You will also stand on the front lines. You must have critical vulnerability handling experience. When a major threat emerges you will help lead the coordination and response. You will work alongside analysts, engineers, and senior leadership to manage these remediation efforts.
Key Responsibilities
- Direct the coordination and remediation of high-severity security vulnerabilities.
- Manage the process from detection, assessment, communication, remediation coordination of security vulnerabilities.
- Use Databricks to parse and analyze massive datasets in order to address vulnerabilities across the company.
- Identify vulnerability trends across the company and create reports for senior leadership.
- Oversee the technical requirements for vulnerability scanning vendors. Configure scanners to match our changing environment and manage the vendor relationship to attain the features required.
- Perform vulnerability scan, analysis, validation and remediation activities.
- Validate vulnerabilities discovered through scans and code analysis. Prioritize risks based on the specific context of the Yahoo environment, distinct mitigating factors, and assessment of the impacts of internal and external threat factors.
- Own, maintain, and create the operational process documentation and vulnerability handling runbooks regarding program execution.
- Work with product teams, developers, and system administrators to explain security risks, and provide remediation guidance for vulnerabilities.
- Provide security subject matter expertise to Yahoo product teams including developers and system administrators.
- Watch public and proprietary sources for vulnerability information. Assess the impact of zero-day threats and recommend immediate action.
- Research and assess new threats, vulnerability security trends and security alerts, recommend remedial action.
- Develop metrics and dashboards for vulnerability management functions.
- Perform technical and non-technical compliance activities, as needed.
- Participate in an on-call rotation and provide after-hours support to drive the resolution of critical vulnerability handling.
Minimum Qualifications
- Bachelor’s degree in a technical discipline (i.e., Computer Science, Engineering, Information Security) or equivalent practical experience.
- 7+ years of experience in information security, specifically within vulnerability management or security engineering.
- Strong understanding of common application, network, and OS vulnerabilities (Linux, Windows and OSX), patching, and attack patterns.
- Proven experience driving critical vulnerability remediation activities. Ability to lead coordination with stakeholders during high-pressure vulnerability remediation efforts.
- Extensive experience with core vulnerability management scanners (i.e., Tenable, Nexpose, Qualys, AWS Inspector, GCP SCC, Github Advanced Security).
- Experience with various vulnerability assessment solutions, vulnerability management, patch management, software development life cycle (SDLC), host based security systems, networking, systems administration, application development, cloud computing and information security best practices.
- Strong understanding of AI and AI prompting. You must be proficient in using AI tools to assist with coding, automation, and complex problem-solving.
- Proficiency with data analysis platforms. You should have experience using Databricks or similar tools to query and visualize large datasets to prioritize impactful vulnerabilities and reduce noise.
- Proficiency in Python or Go. You are comfortable building automation, working with APIs, writing clean and testable code.
- Deep understanding of supply chain risks (such as NPM), dependency confusion attacks, and detection and handling of malicious package attacks.
- Stays up to date with current vulnerabilities and vulnerability related news in various industries.
- Strong understanding of common cloud platforms, such as AWS, GCP, and container technologies, (Kubernetes, AWS EKS, Docker).
- Familiarity with a variety of web application protocols, operating systems and networking technologies.
- Ability to work independently with limited data and operate with a high sense of urgency to shift priorities quickly in a fast-paced environment.
Preferred Qualifications
- Certified Information Systems Security Professional (CISSP).
- Experience independently leading projects to completion.
- Intermediate to advanced capabilities with Databricks for log analysis and dashboard creation.
- Background in software development life cycle (SDLC) and patch management.
- Experience collaborating with cross-functional teams, engineers, and leadership.
Key skills/competency
- Vulnerability Management
- Security Engineering
- Critical Vulnerability Remediation
- Databricks
- Cloud Security
- Python/Go
- Zero-day Threats
- Risk Prioritization
- Security Automation
- Compliance
How to Get Hired at Yahoo
- Research Yahoo's culture: Study their mission, values, recent news, and employee testimonials on LinkedIn and Glassdoor.
- Tailor your resume: Highlight extensive experience in vulnerability management, cloud security, and programming skills in Python or Go.
- Showcase critical thinking: Prepare to discuss complex security incidents and your leadership in remediation efforts during interviews.
- Demonstrate data analysis: Emphasize your proficiency with Databricks or similar tools for querying and visualizing large security datasets.
- Network effectively: Connect with Yahoo security professionals on LinkedIn to gain insights and express interest in the team.
Frequently Asked Questions
Find answers to common questions about this job opportunity
Explore similar opportunities that match your background