Senior Security Engineer, Customer Transparency
Tanium · Remote, US
About this role
**Senior Security Engineer, Customer Transparency** ## The Basics Tanium is looking for a **Senior Security Engineer** to join the **Customer Transparency** team within the **R&D Security** organization. This team protects the software and cloud services customers depend on. The Customer Transparency team helps make Tanium’s security posture something customers can **understand and act on**—not something they have to blindly trust. As a Senior Security Engineer, you’ll represent Tanium’s R&D Security organization to external stakeholders. You’ll own the **vulnerability disclosure program**, build a deep understanding of customer security needs, and drive those needs to resolution. ## What you’ll do - Build and maintain security tooling, leveraging **AI where possible** to streamline security processes - Identify what customers can’t see about their Tanium deployment and partner with Engineering and Product to close gaps - Oversee the **SBOM** and **vulnerability management** program, providing visibility to internal and external stakeholders - Collaborate with customers, partners, and Tanium’s Customer organization to understand real needs, treat recurring questions as engineering problems, and build systems that solve them - Serve as a technical security resource for customer-facing teams: answer inbound security inquiries and escalations, maintain a reusable answers library, and interface directly with customers when needed - Administer Tanium’s **bug bounty program**: triage reports against SLA, assess exploitability and severity, adjudicate duplicates/out-of-scope submissions, recommend awards, and foster relationships with researchers - Author and publish **Security Advisories** and **CVE records** (including **CWE** classification and **CVSS** scoring) - Coordinate disclosure timing and embargoes across researchers, customers, partners, and external coordinating bodies ## We’re looking for someone with ### Education - Bachelor’s Degree in Computer Science (or other relevant degree) or equivalent experience ### Experience - **5+ years** industry experience (**7+ preferred**) - Experience in product/application security, vulnerability research, or software engineering with a substantial security focus - Experience interacting with customers and external security researchers - Experience applying **AI tooling** to security work, with an informed view of where it helps vs. creates noise - Experience building tools or data interfaces used by external stakeholders (including support and customers) - Experience with modern software engineering and automation tools such as **git** and **CI/CD pipelines** - Experience determining vulnerability **severity** and **exploitability** and their business impact ### Nice to have - Familiarity with **SCA/SBOM** tooling and third-party dependency vulnerability management - Experience with coordinated vulnerability disclosure and CVE mechanics (CVSS/CWE); **CNA operations** experience - Experience running (or substantially supporting) a **bug bounty program** or **VDP** - Published vulnerability research, credited CVEs, bug bounty findings, open-source security tooling, or conference talks - Working knowledge of Tanium’s products and services - Strong understanding of applied cryptography (encryption, hashing, secure key management) ### Core Competencies - Demonstrates initiative and motivation - Excellent oral and written communication skills - Team player - High ethics and integrity - Abili
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.