> Markdown version of [/jobs/ext/2643134-vulnerability-security-tester-12-years-local](https://www.wearedevelopers.com/jobs/ext/2643134-vulnerability-security-tester-12-years-local). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # vulnerability security tester - 12+ years Local - **Company:** PARSOFT LLC - **Location:** New York, NY, United States - **Experience:** Experienced - **Salary:** $123,760.0 - $135,200.0 - **Contract:** Temporary contract - **Skills:** Artificial Intelligence, Airflow, Bash Shell, Computer Programming, Continuous Integration, Github, JSON, Python (Programming Language), SQL Databases, Systems Integration, Tripwire, Management of Software Versions, Large Language Models, Prompt Engineering, Deep Learning, Mttr, Tenable Nessus, Docker, Jenkins, Artifactory - **Published:** August 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=146a22bfe37cb2e6 ## About the Role Its Related to vulnerability, security and application of AI for detection and remediation experience is required Experience with ML/Deep Learning, * Programming: Strong Python (scanners, orchestration, API integration); basic Bash for CI/CD glue * Source & Artifact Systems: GitHub (Actions, Advanced Security, PR workflows) and JFrog Artifactory/Xray; ability to scale across multi-repo, multi-language codebases * Scanning Tools: Hands-on with Snyk, Xray, CodeQL / Dependabot, Trivy, or Semgrep; understanding of CVE/CVSS scoring and EOL-detection sources (e.g., endoflife.date) * AI-Driven Remediation: Building agentic workflows (LLM-based) that interpret findings, generate patch PRs, run tests, and summarize fixes; prompt engineering for code-editing agents * CI/CD & Orchestration: Integrating scan-and-fix pipelines into GitHub Actions/Jenkins; Docker for isolated fix-testing; scheduling via Airflow/cron * Reporting: Structuring findings (JSON/SQL) into dashboards for tracking coverage and trends Supporting Skills * Security fundamentals (injection, auth flaws, supply-chain/SBOM risk) * Risk-based prioritization beyond raw CVSS scores * Semantic versioning awareness for safe auto-upgrades * Testing discipline - regression validation before auto-merge Communication Skills * Translating vulnerability data into concise, risk-framed leadership updates (exposure counts, MTTR, fix-rate trends) ## Description Builds and operates a system that scans GitHub/Artifactory repos for vulnerabilities and EOL libraries, then uses AI-driven automation to remediate findings - cutting manual triage and patch time firm-wide. ## Related Videos - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Surviving the Vulnpocalypse: Open Source and Supply Chain Security in a Post Mythos World](https://www.wearedevelopers.com/videos/100279-surviving-the-vulnpocalypse-open-source-and-supply-chain-security-in-a-post-mythos-world) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)