vulnerability security tester - 12+ years Local

PARSOFT LLC
New York, NY, United States
10 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Part-time (≤ 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$123,760.0 - $135,200.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Airflow Bash Shell Computer Programming Continuous Integration Github JSON Python (Programming Language) SQL Databases Systems Integration Tripwire Management of Software Versions
+8 more
Large Language Models Prompt Engineering Deep Learning Mttr Tenable Nessus Docker Jenkins Artifactory

Job description

Builds and operates a system that scans GitHub/Artifactory repos for vulnerabilities and EOL libraries, then uses AI-driven automation to remediate findings - cutting manual triage and patch time firm-wide.

Requirements

Its Related to vulnerability, security and application of AI for detection and remediation experience is required Experience with ML/Deep Learning, * Programming: Strong Python (scanners, orchestration, API integration); basic Bash for CI/CD glue

  • Source & Artifact Systems: GitHub (Actions, Advanced Security, PR workflows) and JFrog Artifactory/Xray; ability to scale across multi-repo, multi-language codebases
  • Scanning Tools: Hands-on with Snyk, Xray, CodeQL / Dependabot, Trivy, or Semgrep; understanding of CVE/CVSS scoring and EOL-detection sources (e.g., endoflife.date)
  • AI-Driven Remediation: Building agentic workflows (LLM-based) that interpret findings, generate patch PRs, run tests, and summarize fixes; prompt engineering for code-editing agents
  • CI/CD & Orchestration: Integrating scan-and-fix pipelines into GitHub Actions/Jenkins; Docker for isolated fix-testing; scheduling via Airflow/cron
  • Reporting: Structuring findings (JSON/SQL) into dashboards for tracking coverage and trends

Supporting Skills

  • Security fundamentals (injection, auth flaws, supply-chain/SBOM risk)
  • Risk-based prioritization beyond raw CVSS scores
  • Semantic versioning awareness for safe auto-upgrades
  • Testing discipline - regression validation before auto-merge

Communication Skills

  • Translating vulnerability data into concise, risk-framed leadership updates (exposure counts, MTTR, fix-rate trends)

Benefits & conditions

$59.50 - $65.00 an hour - Contract

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:14 min

Automating vulnerability detection across diverse development ecosystems

Vandana Verma Sehgal · LIVE

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

3:08 min

Aligning engineering processes with core business impact metrics

Chris Riley · World Congress 2021

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · World Congress 2026 Europe

3:07 min

Establishing service level agreements directly for internal platforms

Pawel Piwosz · LIVE

Videos

See all

Related articles

See all