Vulnerability Engineer
Job description
About the role
Domino Data Lab is hiring a Vulnerability Engineer to strengthen the security posture of its data science and model management platform. This role is part of the security team and focuses on identifying, assessing, and remediating vulnerabilities across the company's data science products and supporting infrastructure. The position is based in Remote India and involves working closely with engineering and operations groups to ensure that security is integrated throughout the software development lifecycle. The Vulnerability Engineer will play a central part in protecting customer data and maintaining the trust that Domino Data Lab's users place in the platform.
Key facts
What you'll do
Conduct thorough vulnerability assessments across Domino Data Lab's platform and its supporting cloud infrastructure
Identify and classify security weaknesses in application code, REST APIs, and cloud-hosted services
Work directly with development teams to reproduce, validate, and document reported security findings
Develop and maintain automated scanning pipelines that enable continuous vulnerability detection across all environments
Produce clear, actionable reports that document risk levels, affected assets, and recommended remediation steps
Coordinate with product managers to prioritize security fixes based on severity, exploitability, and business impact
Actively participate in threat modeling sessions for new features and upcoming product releases
Review third-party dependencies and open-source software components for known security vulnerabilities and license risks
Assist with incident response activities when security events are detected in staging or production systems
Document security processes, runbooks, and long-term improvement plans for the broader engineering organization
Collaborate with the security operations team to refine detection rules and improve the overall vulnerability management workflow
Requirements
Proven experience performing vulnerability assessments and penetration testing on web applications or cloud platforms
Strong understanding of common vulnerability types such as injection flaws, broken access controls, and cryptographic failures
Familiarity with security testing frameworks and both static and dynamic application analysis tools is essential
Ability to write clear technical reports that communicate findings to both technical and non-technical stakeholders
Experience working in a fast-paced software development environment with agile or continuous delivery practices
Knowledge of cloud infrastructure concepts, including containerized workloads, orchestration platforms, and microservices architectures
Bachelor's degree in computer science, information security, or a closely related technical field
Self-motivated approach to learning new technologies and adapting to evolving security threats and attack vectors
Familiarity with regulatory and compliance frameworks relevant to data security, including GDPR and SOC 2 requirements
Nice to have
Professional security certifications such as Offensive Security Certified Professional, Certified Ethical Hacker, or equivalent
Hands-on experience with container security scanning, Kubernetes cluster hardening, and runtime protection tools
Familiarity with DevOps toolchains and CI/CD pipeline integration for automated security checks and gates
Background in data platform, machine learning infrastructure security, or compliance frameworks such as SOC 2
Experience with infrastructure-as-code security scanning and policy enforcement using tools like Terraform or CloudFormation
Skills & tools
Proficiency in vulnerability scanning and penetration testing methodologies for web and cloud environments
Experience with tools such as Burp Suite, Nessus, or equivalent security assessment platforms
Comfortable with scripting languages such as Python or Bash for building automated security workflows and tooling
Understanding of OWASP Top Ten and related web application security standards and guidelines
Familiarity with cloud security services and controls on major platforms such as AWS or Azure
Knowledge of secure coding practices across multiple programming languages including Python, Java, and Go
Experience with vulnerability management platforms and ticketing systems for tracking remediation progress across teams
Practical notes
This is a fully remote position based in Remote India, requiring strong written communication skills for asynchronous collaboration with global teams
The Vulnerability Engineer will report to the security leadership team and coordinate with engineering offices across multiple time zones
Expected work hours align with overlapping business hours across time zones to enable real-time coordination and effective incident response
Domino Data Lab offers a remote-first work culture with flexible scheduling, home office stipend, and collaborative tooling
Candidates should be prepared to travel occasionally to Domino Data Lab offices or customer sites when required for security reviews or audits