Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Cloudflare

Lead Vulnerability Management Engineer

Cloudflare

Lead vulnerability engineer architecting Cloudflare’s global vulnerability management program. Automating remediation workflows with AI and supporting enterprise compliance across Cloudflare’s Internet infrastructure.

Posted 8/19/2026full-timeAustin • Texas • 🇺🇸 United StatesSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Vulnerability Management, including advanced vulnerability scanning, risk assessment methodologies, and compliance with security frameworks. Capable of leading technical teams, designing AI-driven solutions, and translating regulatory requirements into actionable scanning policies.

Highest-signal resume keywords
Vulnerability Management ExperienceVulnerability Scanning PlatformsSecurity Frameworks (SOC-2, NIST, PCI)AI-Driven Solutions DevelopmentGRC Compliance Support

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Vulnerability Risk Scoring (CVSS, EPSS)Advanced Vulnerability ScanningRisk Assessment MethodologiesTechnical ReportingInfrastructure Pentesting Tools
Soft Skills
Strong Communication SkillsInterpersonal SkillsAnalytical Skills
Tools & Technologies
QualysNessusRapid7 InsightVMJIRAAI-Development Tooling (Opencode, Windsurf)
Certifications & Qualifications
Bachelor's Degree in Computer ScienceInformation Security Certifications
Industry Keywords
Vulnerability Management ProgramCompliance ContextRegulatory RequirementsRemediation BacklogSecurity Standards and Procedures

Tech Stack

Tools & technologies
Python

About the role

Key responsibilities & impact
  • Serve as the primary technical lead for the Vulnerability Management team and provide architectural guidance and mentoring
  • Lead architecture, systems design, technology evaluation, and systems integration for the global vulnerability management program
  • Conduct advanced vulnerability scanning and validate findings, filter false positives, and triage and prioritize critical risks
  • Collaborate with technology owners and engineering teams to drive remediation or mitigation of complex vulnerabilities
  • Manage and track the remediation backlog and report on systemic security trends
  • Design and implement AI-driven solutions to automate the vulnerability lifecycle and repetitive operational tasks
  • Improve global vulnerability management standards, procedures, and playbooks
  • Act as the technical liaison for the GRC team and translate vulnerabilities and mitigations into compliance context
  • Own technical reporting and evidence generation for internal and external audits
  • Interpret evolving regulatory requirements into technical scanning policies and integrate mandated checks into the scanning program

Requirements

What you’ll need
  • 5+ years of Vulnerability Management experience, with a proven track record in a senior or lead technical capacity
  • Bachelor's degree in Computer Science, Information Security, or security certifications in a related field
  • Solid understanding of modern security frameworks (e.g., SOC-2, NIST, PCI) and their application in enterprise environments
  • Strong communication (written and verbal) and interpersonal skills
  • Strong understanding of vulnerability risk scoring (e.g., CVSS, EPSS) and applying risk assessment methodologies in a business context
  • Hands-on experience with vulnerability scanning platforms (e.g., Qualys, Nessus, Rapid7 InsightVM)
  • Strong analytical skills to identify patterns in data and distinguish theoretical risk from actual exploitability
  • Demonstrated experience using AI to develop and manage complex workflows and applications
  • Proven experience supporting GRC or external audit cycles (e.g., PCI-DSS, SOC-2, ISO 27001)
  • Ability to translate high-level compliance policies and regulatory requirements into precise technical vulnerability scanning configurations and remediation SLAs
  • Flexibility to be on-call outside standard working hours as needed
  • Bonus: experience with scripting languages such as Python
  • Bonus: experience with AI-development tooling such as Opencode or Windsurf
  • Bonus: proficiency with ticketing tools such as JIRA
  • Bonus: hands-on experience with infrastructure pentesting tools

Benefits

Comp & perks
  • Medical/Rx Insurance
  • Dental Insurance
  • Vision Insurance
  • Flexible Spending Accounts
  • Commuter Spending Accounts
  • Fertility & Family Forming Benefits
  • On-demand mental health support and Employee Assistance Program
  • Global Travel Medical Insurance
  • Short and Long Term Disability Insurance
  • Life & Accident Insurance
  • 401(k) Retirement Savings Plan
  • Employee Stock Participation Plan
  • Flexible paid time off covering vacation and sick leave
  • Leave programs, including parental, pregnancy health, medical, and bereavement leave
  • Equity plan participation