Senior Security Engineer
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
Tanium is looking for a Senior Security Engineer to join the Customer Transparency team within the R&D Security organization, which protects the software and cloud services our customers depend on.
Tanium’s customers secure some of the most consequential networks in the world and they extend us a great deal of trust. The Customer Transparency team is responsible for making Tanium’s security posture something our customers can understand and act on, rather than something they have to blindly trust.
As a Senior Security Engineer on the Customer Transparency team, you will represent Tanium’s R&D Security organization to our external stakeholders. You will be responsible for our vulnerability disclosure program, developing a deep understanding of customers’ security needs, and taking action to drive these to resolution.
What you’ll do
- Build and maintain security tooling, leveraging AI where possible to streamline security processes
- Identify what customers can’t see about their own Tanium deployment and partner with Engineering and Product stakeholders to close those gaps
- Oversee the SBOM and vulnerability management program and provide appropriate visibility to internal and external stakeholders
- Collaborate with Customers, Partners, and Tanium’s Customer organization to learn what customers actually need, treat recurring questions as engineering problems, and build the systems that solve them
- Act as a security technical resource for customer-facing teams: answer inbound security inquiries and escalations, maintain a library of reusable answers, interface directly with customers when needed
- Administer Tanium’s bug bounty program: triage inbound reports against SLA, assess the exploitability and severity of reported issues, adjudicate duplicates and out-of-scope submissions, recommend awards, and foster productive relationships with researchers
- Author and publish Tanium Security Advisories and CVE records, including CWE classification and CVSS scoring
- Coordinate disclosure timing and embargoes across researchers, customers, partners, and external coordinating bodies
We’re looking for someone with
Education
- Bachelor’s Degree in Computer Science, or other relevant degree or equivalent experience
Experience
- 5+ years industry experience, 7+ preferred
- Experience with product and application security, vulnerability research, or software engineering with a substantial security focus
- Experience interacting with customers and external security researchers
- Experience applying AI tooling to security work, with an informed view of where it helps and where it manufactures noise
- Experience building tools or data interfaces used by external stakeholders, including support and customers
- Experience with modern software engineering development and automation tools like git and CI/CD pipelines
- Experience determining the severity and exploitability of a vulnerability and their impact to the business
Nice to have:
- Familiarity with SCA/SBOM tooling and third-party dependency vulnerability management
- Experience with coordinated vulnerability disclosure and the mechanics of CVE assignment, CVSS, and CWE; CNA operations experience
- Experience running, or substantially supporting, a bug bounty program or VDP
- Published vulnerability research, credited CVEs, bug bounty findings, open-source security tooling, or conference talks
- Working knowledge of Tanium’s products and services
- Strong understanding of applied cryptography, including encryption, hashing, and secure key management
Core Competencies
- Demonstrates initiative and motivation
- Excellent oral and written communication skills
- Team player
- Person of high ethics and integrity
- Ability to work in a fast-paced, changing environment
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
B2B Product & Implementation Specialist (Sage 100)
Nuvei
United StatesSenior Product Manager
Global Healthcare Exchange
United StatesSenior Engineering Manager and Tech Lead (Marketplace Team)
Propel
New York CityPrincipal Transformation (TX) Consultant
Valiantys
United StatesMore Openings at Tanium
Tanium
View Company ProfileTanium is a leading cybersecurity company that provides endpoint management and security solutions to help organizations manage and secure their complex IT environments. With its cutting-edge technology, Tanium empowers companies to achieve real-time visibility, control, and remediation of endpoints across their entire network. The company's innovative approach to endpoint management has made it a trusted partner for many of the world's largest and most sensitive organizations, including Fortune 100 companies, government agencies, and financial institutions. Tanium's solutions enable organizations to detect and respond to threats in real-time, improve compliance and risk management, and optimize IT operations. The company's team of experienced security professionals and engineers work closely with customers to understand their unique challenges and develop tailored solutions to meet their specific needs. With its strong commitment to innovation, customer satisfaction, and employee success, Tanium has established itself as a leader in the cybersecurity industry.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.
