CybersecurityJobs.io
← Back to all jobs

Job Description

Verily is looking for a Senior Product Security Engineer based in Boston, MA (onsite) to strengthen Information Security and Privacy Risk Management. In this role, you will help establish and maintain contractual compliance for vulnerability management, supporting ongoing reporting needs tied to FedRAMP certifications.

You will manage vulnerability management tooling, coordinate remediation progress with relevant owners, and contribute to regulator-ready status reporting for continual authorization activities. The position also includes validating risk associated with newly reported threats using scanning and red team operations, grounded in federal compliance practices such as FISMA and FedRAMP.

Responsibilities

  • Manage the tools and inputs used across the Vulnerability Management program.
  • Track remediation tasks and work with systems and service owners and other stakeholders to ensure vulnerability management compliance.
  • Provide regulator weekly/monthly reports to support continued FedRAMP certifications and, when necessary, required remediations such as POA&M.
  • Use prior experience with federal government compliance (for example, FISMA and FedRAMP) to report on process and operational readiness on a regular basis.
  • Stay current on emerging threats and vulnerabilities, then validate the risk of reported threats using vulnerability management, scanning, and red team operations.

Requirements

  • BA/BS degree in Computer Science, Engineering, or Management Information Systems.
  • 5 years of experience in Information Security or related domain(s).
  • 3 years of experience with NIST/FedRAMP compliance audits.
  • Strong knowledge of cloud security architecture, web application security, vulnerability management, and security engineering.
  • Excellent written and verbal communication skills.

Technologies

  • NIST
  • FedRAMP
  • FISMA
  • GCP
  • AWS
  • Kubernetes

Preferred qualifications

  • Experience with FedRAMP Moderate or higher.
  • Experience with GCP (preferred) or AWS, plus containerized environments such as Kubernetes.
  • Experience with vulnerability management tooling, including bug bounty programs, scanning, and offensive security frameworks.

Compensation: USD 165,500 - 185,500 per yearly.

Similar Jobs