Vacancy
Senior Vulnerability Management Engineer
Location:
Other, LATAM
Seniority:
Senior
Technologies:
Python, Security

The project is part of a next-generation SaaS technology platform operating in the transportation and supply chain logistics domain. The company behind the platform has decades of industry experience and is recognized as an employer of choice, with a strong culture of innovation and technical excellence.

The platform delivers a suite of data-driven software solutions used daily by millions of customers who rely on accurate, real-time insights to make informed business decisions and improve profitability. At its core, the system supports one of the largest digital marketplaces in its industry, processing hundreds of millions of transactions annually and maintaining a massive database representing hundreds of billions of dollars in global market activity.

The technology stack is built to handle extreme scale, high availability, and data accuracy, enabling customers to operate efficiently in a fast-moving, competitive environment. Engineering teams work on highly distributed systems, advanced data processing pipelines, and analytics-driven services that continuously evolve to meet growing market demands.

You will own vulnerability management end to end, and you will design, build and implement:

  • Design, build, and mature the enterprise Vulnerability Management Program end to end, covering application/code, endpoint, and infrastructure vulnerabilities within DAT's environment.

  • Integrate vulnerability data from multiple existing security and engineering tools into unified, owner assigned workflows

  • Design and implement the integrations between vulnerability sources, ticketing systems, and other internal platforms yourself, and build the automated workflows for ingestion, processing, assignment, tracking, and reporting rather than only recommending them.

  • Build dashboards and reporting that give visibility into outstanding vulnerabilities, ownership, remediation progress, and SLA and policy compliance, broken out by team and by system.

  • Define and enforce remediation SLAs benchmarked to industry standards, tightened where needed to keep DAT's response time ahead of adversaries who are increasingly using AI to find and exploit vulnerabilities faster.

  • Apply an AI first mindset, actively identifying where AI or GenAI can automate or improve vulnerability management workflows rather than defaulting to a manual process.

  • Align the program to NIST CSF (Identify: Risk Assessment, Protect: Platform Security, Detect: Continuous Monitoring) and support evidence needs for DAT’s Security Control Framework and related audits. (e.g., SOC 2, PCI, SOX)

  • Partner with Security, Engineering, and IT stakeholders as a collaborator, making remediation practical and sustainable while balancing secure and fast software development.

  • Bachelor's degree in Computer Science, Information Security, Engineering, or a related field, or equivalent practical experience.

  • 6-8 years of hands-on experience in vulnerability management or security engineering, with a track record designing, building, or significantly scaling a vulnerability management program.

  • Working knowledge of vulnerability management across application/code, endpoint, and infrastructure/cloud security, specifically AWS.

  • Strong engineering background building integrations and automated workflows, with scripting or programming experience, Python preferred.

  • Experience integrating security platforms with ticketing and work management systems.

  • Understanding of vulnerability prioritization, ownership, remediation processes, SLAs, and security metrics.

  • Familiarity with NIST CSF and security controls, and with SOC 2 expectations for vulnerability management.

  • Ability to independently design an end to end technical solution with limited predefined specification.

  • Understanding of AI and GenAI capabilities and practical opportunities to apply them to security automation.

Preferred

  • Experience integrating vulnerability or security programs across organizations involved in M&A activity.

  • Direct experience preparing vulnerability management evidence for a SOC 2 Type 2 audit.

  • GPEN, OSCP, CEH,  or an equivalent technical certification.

Benefits:
  • Paid Vacation
  • Sick Days
  • Floating Holidays
  • Sport/Insurance Compensation
  • English Classes
  • Charity
  • Training Compensation
Apply for this job
Benefits:
  • Paid Vacation
  • Sick Days
  • Floating Holidays
  • Sport/Insurance Compensation
  • English Classes
  • Charity
  • Training Compensation
Similar Vacancies
Looking for More Opportunities?
Explore similar open positions that match your experience.