- Home
- Jobs
- Engineering
- Security Engineer - Vulnerability

Security Engineer - Vulnerability at Endor Labs
Bengaluru, IndiaFull-timeEngineeringPosted about 1 month ago
Apply with PipelineAbout the Role
<h2><strong>Who we are</strong></h2>
<p>Our mission is to help developers and AppSec teams spend more time accelerating development and less time dealing with security issues. Watch our 3 min pitch from our Founder & CEO here: <a href="https://www.youtube.com/watch?v=B0wmZBcPkFE">https://www.youtube.com/watch?v=B0wmZBcPkFE</a></p>
<p>Endor Labs has been recognized as a Gartner Cool Vendor, a RSA Innovation Sandbox finalist, and a Black Hat Innovation Spotlight finalist, all in its first year from launch.</p>
<p>The company was founded by <a href="https://www.linkedin.com/in/vbadhwar/">Varun Badhwar</a> and <a href="https://www.linkedin.com/in/stiliadis/">Dimitri Stiliadis</a>, who have created multiple category-defining cloud security companies. We have raised $70M in Series A funding and assembled a team of the world’s leading static analysis experts and enterprise software veterans to increase developer productivity and open source software adoption.</p>
<h2><strong>What you’ll do</strong></h2>
<ul>
<li>The primary focus of this position is to help the team further advance Endor Labs'proprietary vulnerability database — extending and improving our existing AI pipelines,<br>e.g., in the areas of automated vulnerability validation, reachability analysis, and exploit generation.</li>
<li>Day-to-day work includes monitoring and managing pipelines that triage, enrich, and prioritize vulnerabilities at scale, working with the standards and data sources the<br>ecosystem is built on (CVE, CWE, CVSS, EPSS, PURL, NVD, OSV, GHSA, VEX) and continuously improving the accuracy, coverage, and timeliness of our data.</li>
<li>You will work hand-in-hand with our world-class 0-day researchers to scale automated vulnerability discovery — turning manual research workflows into repeatable,<br>production-grade systems.</li>
<li>You will investigate high-impact vulnerabilities and the vulnerability landscape at large, and author external-facing content — blog posts, technical write-ups, and advisories —<br>communicating findings clearly to both technical and non-technical audiences.</li>
<li>You will collaborate with internal teams to feed findings into detection and analysis pipelines, enrich our vulnerability database, and help improve automated coverage over<br>time</li>
</ul>
<h2><strong>What </strong><strong>we're looking for </strong></h2>
<ul>
<li>Bachelor's degree in engineering or a related field, with at least 3 years of hands-on professional experience in vulnerability research, vulnerability management, product<br>security, or application security</li>
<li>Extensive knowledge of software vulnerabilities, triage, and prioritization, including deep familiarity with the associated standards and technologies (CVE, CWE, CVSS, EPSS,<br>PURLs, NVD, OSV, VEX, SBOM formats)</li>
<li>Hands-on experience building production-grade solutions at enterprise scale — e.g., CI/CD automation, management of SAST/SCA findings, or comparable security tooling<br>deployed across large engineering organizations</li>
<li>Demonstrated experience shipping AI/agentic systems to production — LLM pipelines, agent frameworks, tool use, prompt and eval design — with a clear track record of<br>measuring output quality and a sound sense of where these approaches hold up and where they don't</li>
<li>Proficiency in reading and analyzing code across multiple languages (Python, JavaScript/TypeScript, Java, Go), and comfort reasoning about patches, root causes,<br>and exploitability</li>
<li>Experience producing external security communications: blog posts, advisories, or technical reports intended for a public or customer-facing audience</li>
</ul>
<h2><strong>Nice to have</strong></h2>
<ul>
<li>Experience writing proof-of-concept exploits, or with fuzzing, static analysis, or automated vulnerability discovery</li>
<li>Contributions to open source vulnerability databases, scanners, or related tooling (OSV, osv-scanner, OpenVEX, etc.)</li>
<li>Familiarity with SAST, SCA, and DAST tooling and the realities of triaging their output at scale</li>
<li>Understanding of software supply chain security standards and frameworks (SLSA, SSDF, etc.)</li>
<li>Prior public research, CVE credits, or published vulnerability findings</li>
<li>Security certifications such as OSCP, OSCE, or equivalent</li>
</ul>
<h2><strong>At Endor Labs, we:</strong></h2>
<ul>
<li style="font-weight: 400;">Strive for excellence in everything we do, prioritizing quality, speed, and impactful outcomes.</li>
<li style="font-weight: 400;">Engage in first principles thinking to debate ideas, test assumptions, and make decisions.</li>
<li style="font-weight: 400;">Put data above opinions, seeking truth and clarity in all our endeavors.</li>
<li style="font-weight: 400;">Embrace a culture of feedback and continuous improvement, assuming good intent in all interactions.</li>
<li style="font-weight: 400;">Celebrate wins as a team, understanding that our collective success is intertwined with the success of our customers.</li>
</ul>
Related Roles
Senior Backend Engineer (Golang)
Endor Labs
Bengaluru, IndiaSenior Quality Engineer(SDET)
Endor Labs
Bengaluru, IndiaStaff Backend Engineer (Golang)
Endor Labs
Bengaluru, IndiaBackend Software Engineer (Mid-Senior)
Endor Labs
Palo Alto, CAIT Engineer
Endor Labs
Bengaluru, IndiaSenior Product Security Engineer
Endor Labs
Bengaluru, India