> Markdown version of [/jobs/ext/3674773-senior-security-engineer-vulnerability-research](https://www.wearedevelopers.com/jobs/ext/3674773-senior-security-engineer-vulnerability-research). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - Vulnerability Research - **Company:** Tanium Inc. - **Location:** Chicago, IL, United States - **Experience:** Expert - **Salary:** $45,760.0 - $56,160.0 - **Contract:** Temporary contract - **Skills:** JavaScript (Programming Language), Artificial Intelligence, Amazon Web Services, Data Analysis, Software System Penetration Testing, Microsoft Azure, C++ (Programming Language), Mobile Application Development, Cloud Computing, Code Review, Fuzz Testing, Python (Programming Language), Key Management, Open Source Technology, Cloud Services, Secure Coding, TypeScript, Software Security, Tanium Platform Expertise, Information Technology, Vulnerability Analysis, Golang - **Published:** October 10, 2026 - **Apply:** https://www.jofdav.com/jobs/60063324-senior-security-engineer-vulnerability-research ## About the Role * Bachelor's Degree in Computer Science, or other relevant degree or equivalent experience, * 5+ years industry experience, 7+ preferred * Strong understanding of web and native application security * Experience with hands-on vulnerability research via source code review, manual application penetration testing, or fuzzing * Expertise in determining the severity and exploitability of a vulnerability and its impact to the business * Able to read and write code in at least one of: Go, C++, TypeScript/JavaScript, or Python * Experience with the process of developing, building, and shipping secure code Nice to have: * Experience applying frontier models to vulnerability research, and an informed view of where AI accelerates outcomes and where it manufactures noise * Experience with reachability or exploitability analysis to separate real findings from theoretical ones at scale * Experience with native code security (C/C++) in privileged or agent-based software * Experience with cloud platforms (AWS or Azure preferred) * Published vulnerability research, credited CVEs, bounty findings, open-source security tooling, or conference talks * Strong understanding of applied cryptography, including encryption, hashing, and secure key management ## Description The Basics Tanium is looking for a security engineer to join the Vulnerability Research team within the R&D Security organization, which protects the software and cloud services our customers depend on. Tanium's customers secure some of the most consequential networks in the world and they extend us a great deal of trust. The Vulnerability Research team is responsible for hunting for previously-unknown vulnerabilities in our software and driving them to remediation before attackers can exploit them. In this role, you will continuously raise the bar for attackers, making vulnerabilities in Tanium software harder and more expensive to find. Tanium is leveraging frontier models and developing agentic security workflows to scale and accelerate the find-and-fix loop. You will apply your deep security expertise to decide what to hunt for and streamline the vulnerability discovery, triage, and remediation processes. What you'll do * Decide which attack surfaces and bug classes to go after and build the capability needed to discover new vulnerabilities * Triage newly discovered vulnerabilities quickly and accurately, ranking them by exploitability and actual impact * Make remediation easy for engineering by providing high-quality patch guidance and working pull requests in addition to the vulnerability reports * Maintain a threat model of Tanium software and services and use it to direct future vulnerability research projects * Drive vulnerability research with frontier AI capabilities by evaluating what is possible using in-house and third-party tooling and building agentic workflows around what works * Build and maintain reliable tooling to support vulnerability research efforts including AI skills, fuzzing harnesses and static and dynamic analyzers * Shorten the time from detection to remediation by driving down false positive rate and improving finding quality * Perform source code review and targeted security assessment of high-risk components, This link leads to the machine readable files that are made available in response to the federal Transparency in Coverage Rule and includes negotiated service rates and out-of-network allowed amounts between health plans and healthcare providers. The machine-readable files are formatted to allow researchers, regulators, and application developers to more easily access and analyze data.