> Markdown version of [/jobs/ext/2702582-security-software-engineer-vulnerability-operations](https://www.wearedevelopers.com/jobs/ext/2702582-security-software-engineer-vulnerability-operations). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Software Engineer, Vulnerability Operations - **Company:** NVIDIA Corporation - **Location:** Santa Clara, CA, United States (Remote available) - **Experience:** Starter - **Salary:** $170,000.0 - $190,000.0 - **Contract:** Internship / Graduate position - **Skills:** Artificial Intelligence, Relational Databases, Software Debugging, Linux, Github, Python (Programming Language), PostgreSQL, Octopus Deploy, OpenShift, Perforce, Redis, Standard Sql, Security Software, Software Engineering, SQL Databases, TypeScript, Software Vulnerability Management, Web Applications, Gerrit, ReactJS, Delivery Pipeline, Large Language Models, Multi-Agent Systems, Backend, Gitlab, Git, Fastapi, Kubernetes, Celery, Front End Software Development, Docker - **Published:** September 4, 2026 - **Apply:** https://www.jofdav.com/jobs/59554630-security-software-engineer-vulnerability-operations ## About the Role * Bachelor's degree in CS/Engineering or equivalent experience * 1-3 years of software engineering experience (internships count), with solid Python fundamentals * Working knowledge of SQL and relational databases * Comfort in a Linux/Git environment and a willingness to debug across unfamiliar systems * Interest in security - you don't need to be a security expert yet, but you should want to become one * Strong ownership instincts: you follow problems to root cause and communicate clearly along the way Ways to stand out from the crowd: * Frontend experience with React and TypeScript * Exposure to containers and orchestration (Docker, Kubernetes, ArgoCD/GitOps) or job-queue/worker architectures (Redis, Celery/ARQ) * Hands-on experience with LLM APIs, agent frameworks, or coding agents (Claude Code, Codex, opencode, or similar) * Security fundamentals: CTF participation, security coursework, bug bounty writeups, or certifications like Security+ or eJPT * Contributions to open-source projects or a portfolio of shipped side projects ## Description NVIDIA's Vulnerability Operations organization is looking for a Security Software Engineer to help operate and improve our AI-powered vulnerability operations platform. This platform uses LLM agents to scan tens of thousands of repositories and live web applications across NVIDIA, then unifies, verifies, and routes those findings to the engineers who can fix them. You'll join a small, fast-moving team and own real production responsibilities from day one - keeping the scanning fleet healthy, improving the triage experience, and making the data trustworthy. What you'll be doing: * Supporting day-to-day operations of our vulnerability management hub and its two AI scanning engines: monitoring scan fleets and worker queues, investigating stuck or failed scans, and shipping fixes. * Building and maintaining features across the stack - Python/FastAPI backend services, React/TypeScript frontends, and Postgres data models Triaging platform feedback from security engineers and repo owners: reproducing bugs, running data reconciliations in SQL, and closing the loop with users * Operating our GitOps deployment pipeline (Kubernetes/OpenShift, ArgoCD, Vault) - shipping releases to staging and production, rotating secrets, and validating rollouts * Improving scan coverage and data quality: asset inventory across GitLab/GitHub/Gerrit/Perforce, ownership attribution, finding lifecycle and dedup logic * Working alongside senior engineers on the LLM agent harnesses that power scanning and verification, and learning how agentic security tooling is built and operated ## Related Videos - [The weekly developer show: Boosting Python with CUDA, CSS Updates & Navigating New Tech Stacks](https://www.wearedevelopers.com/videos/1293-the-weekly-developer-show-boosting-python-with-cuda-css-updates-navigating-new-tech-stacks) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Reducing LLM Calls with Vector Search Patterns - Raphael De Lio (Redis)](https://www.wearedevelopers.com/videos/1714-reducing-llm-calls-with-vector-search-patterns-raphael-de-lio-redis) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) ## Related Articles - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 129 - Now that's what I call private data!](https://www.wearedevelopers.com/magazine/468-dev-digest-129-now-that-s-what-i-call-private-data) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)