Senior Software Engineer, Patch Engineering & Vulnerability Remediation

Domino Data Lab, Inc.
United States
21 days ago
Apply on arc.dev
Prepare application

Role details

Contract type
Permanent contract
Employment type
Part-time (≤ 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Build Automation Python (Programming Language) Open Source Technology Software Maintenance Software Vulnerability Management Kubernetes Build Tools Vulnerability Analysis

Job description

  • A hardened release pipeline that produces container images meeting strict scan thresholds, with reproducible builds and minimal attack surface
  • An automated vulnerability triage system that ingests scanner output, deduplicates findings across images and releases, routes to owners, and tracks SLA compliance-without manual triage
  • Provenance and exploitability tooling that generates SBOMs and VEX statements on every release, so customer security questions are answered from standing artifacts rather than one-off investigations
  • A scalable remediation practice that uses AI and automation to keep pace with the volume of findings, rather than throwing engineers at each CVE individually

This is foundational work. The tooling and runbooks you build will define how Domino operates in regulated markets for years to come.

What Your Impact Will Be

In your first year, you will

  • In your first year, you will own the hardened image pipeline for our most demanding deployments and cut time-to-remediate for critical and high findings to a published, defensible SLA.
  • You will replace one-off vulnerability firefighting with an automated path from scan to fix, including SBOM and exploitability statements generated on every release.
  • You will make “we are not fixing this, and here is why” a documented engineering position backed by evidence, rather than a conversation repeated with every customer.
  • You will set the technical direction and tooling that the next engineers on this team build on.

Requirements

  • Experience shipping and maintaining software or container images into regulated, on-premises, or air-gapped environments where you cannot simply redeploy to fix a problem
  • Deep fluency with container build systems, base image strategy, and reproducible builds, plus working knowledge of Kubernetes and Helm packaging
  • Hands-on experience with vulnerability scanning and provenance tooling, and the judgment to distinguish a real risk from scanner noise
  • Go and/or Python strong enough to build automation and to patch upstream open-source dependencies when no fix exists
  • Clear technical writing. You will produce evidence that external auditors and customer security teams read and act on
  • A bias toward removing whole classes of problems rather than closing tickets

Benefits & conditions

  • We value a growth mindset. High-performing creative individuals who dig into problems and see the opportunities for success
  • We believe in individuals who seek truth and speak the truth and can be their whole selves at work
  • We value all of you that believe improving is always possible At Domino Everything is a work in progress - we can do better at everything
  • We emphasize an environment of teaching and learning to equip employees with the tools needed to be successful in their function and the company
  • We strongly believe in the value of growing a diverse team and encourage people of all backgrounds, genders, ethnicities, abilities, and sexual orientations to apply

About the company

Domino Data Lab powers model-driven businesses with its leading Enterprise AI platform trusted by over 20% of the Fortune 100. Domino accelerates the development and deployment of data science work while increasing collaboration and governance. With Domino, enterprises worldwide can develop better medicines, grow more productive crops, build better cars, and much more. Founded in 2013, Domino is backed by Coatue Management, Great Hill Partners, Highland Capital, Sequoia Capital and other leading investors. For more information, visit www.domino.ai

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on arc.dev
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:14 min

Automating vulnerability detection across diverse development ecosystems

Vandana Verma Sehgal · LIVE

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · World Congress 2022

48 sec

Exploring alternative build tools and experimental web components

Sasha Shynkevich · LIVE

6:37 min

Evolution of build systems and Gradle basics

Amanda Martin · LIVE

4:29 min

Automating vulnerability remediation and container builds using AI agents

Jim Clark Jim Clark +3 · World Congress 2025

4:04 min

Overview of Kubernetes operators and custom resource definitions

Philipp Krenn · World Congress 2022

Videos

See all

Related articles

See all