
Staff Security Engineer, Vulnerability Management
Job description
About the role
CoreWeave is seeking a technical expert to lead vulnerability management initiatives across our high-performance AI infrastructure. You will design and implement strategies to identify, assess, and remediate security risks within our large-scale GPU compute environments. This position requires a deep understanding of cloud-native security principles and the ability to operate at scale. The successful candidate will act as a subject matter expert, driving security improvements across the entire infrastructure stack. You will be responsible for ensuring that vulnerability management practices are robust, efficient, and aligned with the needs of AI workloads. This role demands a proactive approach to identifying and mitigating risks before they can be exploited. You will play a critical role in protecting the integrity and availability of our compute platforms.
Key facts
What you'll do
- Architect and evolve comprehensive vulnerability management programs tailored to cloud-native and GPU-intensive infrastructure landscapes.
- Partner with cross-functional engineering groups to establish rational risk-based remediation roadmaps for security findings.
- Construct and optimize automated security scanning, detection, and reporting pipelines to maintain continuous system health visibility.
- Perform in-depth analysis of complex security telemetry and vulnerability data to uncover emerging trends, root causes, and latent systemic risks.
- Author, publish, and uphold stringent security standards and baselines for both hardware and software configurations across all environments.
- Evaluate and integrate emerging vulnerability assessment and security tooling to enhance the efficiency and coverage of existing workflows.
- Lead incident response coordination efforts specific to vulnerabilities, working closely with engineering and operations teams during critical events.
- Translate intricate security vulnerabilities and technical findings into clear, actionable guidance for engineering and technical stakeholders.
- Mentor and elevate the security practices of other engineers through code reviews, technical guidance, and collaborative problem-solving initiatives.
- Design and execute validation testing to confirm the effectiveness of remediation efforts and verify the integrity of deployed security controls.
- Collaborate with product and infrastructure teams to embed security considerations into the architectural design of new systems and features.
- Monitor industry security advisories and threat intelligence to proactively identify potential impacts to CoreWeave's infrastructure and services.
- Develop and maintain detailed documentation for vulnerability management processes, procedures, and identified security baselines.
- Measure and report on key vulnerability management metrics to track program effectiveness and demonstrate tangible security improvements.
Requirements
- Demonstrate proven, hands-on experience in vulnerability management within demanding cloud environments or large-scale distributed systems.
- Exhibit deep proficiency in identifying, classifying, and mitigating security risks specifically within Linux-based operating systems and Kubernetes container orchestration platforms.
- Possess a strong ability to effectively communicate and collaborate, bridging the gap between rigorous security requirements and practical operational engineering constraints.
- Show concrete experience leveraging automated security tooling, advanced vulnerability assessment platforms, and continuous monitoring solutions.
- Cultivate a comprehensive and up-to-date understanding of infrastructure security fundamentals, including robust network security controls and host-based protection mechanisms.
- Hold a strong working knowledge of security frameworks, compliance requirements, and industry best practices relevant to cloud infrastructure.
- Bring exceptional analytical and problem-solving skills to dissect complex security issues and determine appropriate mitigation strategies.
- Thrive in a fast-paced, dynamic environment where priorities shift rapidly and adaptability is essential for success.
Skills & tools
- Kubernetes
- Linux
- Industry-standard vulnerability scanning tools and security information and event management platforms.
- Automation scripting using common programming and shell scripting languages.
- Infrastructure security monitoring, log analysis, and telemetry correlation tools.
- Container security tools and image scanning technologies.
- Cloud provider security services and infrastructure-as-security tooling.
- Security orchestration, automation, and response (SOAR) platforms.
Practical notes
CoreWeave provides specialized GPU infrastructure designed to accelerate AI training and inference workloads. This role is focused on maintaining the security posture and resilience of our production compute clusters and associated infrastructure. CoreWeave maintains a drug-free workplace. Employment is contingent on successful completion of a background check. Please submit your application through the official CoreWeave careers portal to be considered for this position. The role may require occasional travel to client sites or partner locations as needed. CoreWeave is an equal opportunity employer.