> Markdown version of [/jobs/ext/2719400-search-security-engineering-pod](https://www.wearedevelopers.com/jobs/ext/2719400-search-security-engineering-pod). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Search Security Engineering Pod - **Company:** Nmk Global Inc. - **Location:** San Francisco, CA, United States - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Artificial Intelligence, Unit Testing, C++ (Programming Language), Profiling, Code Review, Software Debugging, Python (Programming Language), Open Web Application Security, Secure Coding, Data Streaming, Software Vulnerability Management, Software Security, Software Coding, Golang, Microservices - **Published:** September 4, 2026 - **Apply:** https://www.dice.com/job-detail/37d8648c-6fc8-4c4c-b0c4-7446c575f3d4 ## About the Role Strong knowledge of CWE, CVE, OWASP Top 10, severity classification, vulnerability scoring, remediation SLAs, and scanner findings. * Vulnerability Reproduction & PoC Validation Engineers Hands-on coding experience in at least two languages: C++, Go, Java, or Python. Must be able to build test harnesses, mock dependencies, create PoCs, and validate vulnerabilities versus false positives. * Automated/Agentic Remediation QA Engineer Strong secure code-review skills, automated patch validation, unit and integration testing, regression identification, and experience reviewing AI/agent-generated code fixes. * Security Remediation & Product Coordination Engineer Experience coordinating with product code owners, tracking remediation SLAs, supporting code reviews and deployments, and verifying production closure. * Candidates must be comfortable working onsite and should have strong application security, secure coding, debugging, vulnerability management, and stakeholder coordination experience. ## Description The pod will work as the operational bridge between automated security scanning/remediation systems and Google's product code owners. The team will focus on threat modeling, vulnerability triage, exploitability validation, automated patch verification, and driving security issues through production closure. * Threat Modeling & Asset Profiling Engineer Experience with trust boundaries, attack surfaces, data flows, STRIDE/PASTA, and distributed or microservice architectures. * Vulnerability Triage & Policy Engineer ## Related Videos - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Profiling Symfony & PHP apps with Blackfire](https://www.wearedevelopers.com/videos/265-profiling-symfony-php-apps-with-blackfire) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) - [Stranger Danger: Your Java Attack Surface Just Got Bigger](https://www.wearedevelopers.com/videos/346-stranger-danger-your-java-attack-surface-just-got-bigger) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)