> Markdown version of [/jobs/ext/2736262-senior-software-engineer-patch-engineering-vulnerability-remediation](https://www.wearedevelopers.com/jobs/ext/2736262-senior-software-engineer-patch-engineering-vulnerability-remediation). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Software Engineer, Patch Engineering & Vulnerability Remediation - **Company:** Domino Data Lab, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Build Automation, Python (Programming Language), Open Source Technology, Software Maintenance, Software Vulnerability Management, Kubernetes, Build Tools, Vulnerability Analysis - **Published:** September 5, 2026 - **Apply:** https://arc.dev/remote-jobs/j/redirect/phpy0kvc2u ## About the Role * Experience shipping and maintaining software or container images into regulated, on-premises, or air-gapped environments where you cannot simply redeploy to fix a problem * Deep fluency with container build systems, base image strategy, and reproducible builds, plus working knowledge of Kubernetes and Helm packaging * Hands-on experience with vulnerability scanning and provenance tooling, and the judgment to distinguish a real risk from scanner noise * Go and/or Python strong enough to build automation and to patch upstream open-source dependencies when no fix exists * Clear technical writing. You will produce evidence that external auditors and customer security teams read and act on * A bias toward removing whole classes of problems rather than closing tickets ## Description * A hardened release pipeline that produces container images meeting strict scan thresholds, with reproducible builds and minimal attack surface * An automated vulnerability triage system that ingests scanner output, deduplicates findings across images and releases, routes to owners, and tracks SLA compliance-without manual triage * Provenance and exploitability tooling that generates SBOMs and VEX statements on every release, so customer security questions are answered from standing artifacts rather than one-off investigations * A scalable remediation practice that uses AI and automation to keep pace with the volume of findings, rather than throwing engineers at each CVE individually This is foundational work. The tooling and runbooks you build will define how Domino operates in regulated markets for years to come. What Your Impact Will Be In your first year, you will * In your first year, you will own the hardened image pipeline for our most demanding deployments and cut time-to-remediate for critical and high findings to a published, defensible SLA. * You will replace one-off vulnerability firefighting with an automated path from scan to fix, including SBOM and exploitability statements generated on every release. * You will make "we are not fixing this, and here is why" a documented engineering position backed by evidence, rather than a conversation repeated with every customer. * You will set the technical direction and tooling that the next engineers on this team build on. ## Related Videos - [The perfect CI/CD React Native pipeline with Fastlane](https://www.wearedevelopers.com/videos/556-the-perfect-ci-cd-react-native-pipeline-with-fastlane) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Modern Data Architectures need Software Engineering](https://www.wearedevelopers.com/videos/1030-modern-data-architectures-need-software-engineering) - [Stranger Danger: Your Java Attack Surface Just Got Bigger](https://www.wearedevelopers.com/videos/346-stranger-danger-your-java-attack-surface-just-got-bigger) - [Instant KAI Sandboxes with vCluster: Multi-Tenant, Multi-Scheduler GPU Sharing](https://www.wearedevelopers.com/videos/100333-instant-kai-sandboxes-with-vcluster-multi-tenant-multi-scheduler-gpu-sharing) - [Answering the Million Dollar Question: Why did I Break Production?](https://www.wearedevelopers.com/videos/1171-answering-the-million-dollar-question-why-did-i-break-production) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)