About this role
Our client is seeking a skilled Security Engineer specializing in Detection & Response Operations to lead the operational aspects of their Vulnerability Detection & Response (VDR) program. This role will focus on ensuring that vulnerabilities are evaluated, remediated, and verified within strict SLA timeframes, particularly for critical exploitable findings.
Key Responsibilities:
- Develop and maintain a comprehensive runbook library for vulnerability response, including triage, evaluation, and standard remediation workflows.
- Design and implement an on-call and escalation model, incorporating alerting rules tied to urgency thresholds.
- Operate the response process during the parallel-run and cutover period, ensuring real findings are effectively managed through all stages.
- Build and manage the remediation verification process to confirm fixes in the deployed environment.
- Define SLA telemetry and drift alerting, creating dashboards and alerts for monitoring compliance with timeframes.
- Coordinate remediation efforts with engineering teams, providing guidance and clear acceptance criteria for fixes.
- Conduct tabletop exercises for emergency-patch scenarios and refine runbooks based on lessons learned.
- Train internal security and platform teams on runbooks and produce high-quality documentation for operational handoff.
Required Skills:
- 5+ years in security operations, vulnerability management, or detection & response roles.
- Hands-on experience with patching campaigns, container image updates, and dependency upgrades.
- Proven ability to write operational runbooks and incident response procedures that are executable by others.
- Familiarity with exploit intelligence and its impact on urgency.
- Experience with alerting and on-call tools like PagerDuty and SLA-driven workflows.
- Proficient in cloud and container environments, particularly EKS/ECS + ECR + CI.
Preferred Skills:
- Experience in a regulated environment such as FedRAMP, where remediation timelines are compliance obligations.
- Knowledge of DefectDojo or similar systems for response workflows.
- Background in incident response, especially for emergency-patch scenarios.
- Experience conducting tabletop exercises and operational readiness reviews.
What we offer:
Our client provides a dynamic work environment, opportunities for professional growth, and a chance to make a significant impact in the field of security operations.
This role is managed by VettedBench on behalf of our client. Your application is reviewed directly by our talent team.