AppSec Jobs
← Back to all jobs

SolarWinds

Senior Security Operations & Vulnerability Management Engineer

Remote
Brno, South Moravia, CzechiaPosted 1 week agoWebsite
Apply on LinkedIn →

At a Glance

AWSAzureGCPPythonCI/CDNIST

About This Role

We are looking for a Senior Engineer who views Vulnerability Management as a risk-reduction craft, not a compliance checkbox. While you will be involved in high-level security operations, your primary focus is to evolve our Threat & Vulnerability Management (TVM) program from "running scans" to "driving impactful remediation of real risk." This isn't a role for someone who just forwards PDF reports. We need a technical leader who can cut through the noise of thousands of alerts, translate CVSS scores into actual business risk, and work as a peer with our Engineering and IT teams to get things fixed. You'll be the bridge between technical telemetry and executive-level risk decisions.

Responsibilities

  • Own the full lifecycle of vulnerability discovery and remediation, moving beyond "Critical/High" labels to prioritize based on reachability, exploitability-in-the-wild (EPSS/KEV), and the specific context of the environment
  • Act as the primary technical point of contact for Engineering and DevOps, explaining the "why" behind a fix, helping teams navigate technical debt, and negotiating remediation timelines that balance security with product velocity
  • Use MITRE ATT&CK® to pivot from vulnerability data to proactive hunting, identifying exposure surface and drafting briefs within hours when new Zero-Days emerge
  • Build and tune detection logic and design SOAR playbooks to automate ticket routing, asset tagging, and evidence collection
  • Act as a Tier 3 escalation point and Incident Commander for major security events, leading deep dives after incidents to ensure root causes are addressed in the TVM roadmap
  • Develop and report on KPIs that matter to executive leadership, such as Mean Time to Remediation (MTTR) for exploited flaws and burn-down rates on mission-critical assets

Requirements

CI/CDAWSAzureGCPPythonNISTCISSP
  • 5–7+ years in SecOps and Threat & Vulnerability Management (TVM)
  • Deep, hands-on experience with enterprise-grade scanners (Qualys, Tenable, or Rapid7) and the ability to integrate them into CI/CD pipelines and cloud workflows
  • Fluency in AWS/Azure/GCP security and understanding of container image scanning versus VM scanning
  • Proficiency in Python, PowerShell, or SQL to pull data from APIs and identify meaningful outliers
  • Ability to explain vulnerabilities and exploits to both technical engineers and executive leadership
  • Strong command of NIST CSF and MITRE ATT&CK frameworks and their practical application
  • Understanding of exploit development and penetration testing methodologies with the ability to identify "low hanging fruit" for attackers
  • Professional certifications like CISSP, GCIH, or GEVA (GIAC Enterprise Vulnerability Assessor) highly regarded
  • Cloud certifications (CCSP, AWS Security) or degree in Cybersecurity/CS a plus

Benefits & Perks

25 days of vacation per year
3 sick days per year
10 study days per year
2 volunteering days per year
4 weeks' holidays after 5-year tenure, Sabbatical Leave
Up to 48,300 CZK personal education budget per year
Pension or life insurance matching donation up to 3% of salary or 4,000 CZK per month
Cash allowance for meals of 95 CZK per working day
Unlimited access to LinkedIn Learning
English/Czech classes
Multisport card
Solarian Referral Program
SolarWinds Appreciation Program
Giving – Donation Matching
Employee Assistance
Competitive Race Reimbursement
Breakfast on Wednesdays
Fresh fruits and snacks on Mondays
On-site gym
Twice-weekly workout classes at the office
Once a week yoga sessions at the office

About SolarWinds

SolarWinds is a prominent provider of observability and IT management software, aimed at helping organizations monitor, analyze, and optimize their IT infrastructure in hybrid and multi-cloud environments. Founded in 1999 in Tulsa, Oklahoma, the company has grown significantly, relocating its headquarters to Austin, Texas, and expanding internationally. The company offers a comprehensive suite of IT management solutions, including network management, systems and database monitoring, application performance monitoring, and IT service management. Their SolarWinds Platform integrates these solutions to enhance performance, reliability, and security for enterprises. With over 300,000 customers worldwide, SolarWinds serves a diverse range of businesses, from small and mid-sized companies to large enterprises. The company also fosters a strong user community through THWACK®, which has nearly 200,000 members.

Industry

information technology & services

Employees

2,000

765 engineers

Revenue

$797M

Website

Visit →

Security at SolarWinds

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

  • SolarWinds' AppSec philosophy is centered on the 'Secure by Design' principle, which serves as the guiding framework for cyber resiliency.
  • The approach prioritizes fixing security issues prior to release, viewing security as a mechanism that enables speed ('Brakes make you go faster').
  • The team follows a defined software development methodology aligned with NIST SSDF controls and emphasizes an 'assume-breach' mindset.

Security Team

SolarWinds employs a dedicated product security function, as evidenced by active recruitment for leadership roles such as 'Lead Product Security Engineer'. The security organization is led by CISO Tim Brown, who oversees the Trust Center and the 'Secure by Design' initiative. Specific reporting lines (e.g., whether the team is centralized or embedded) and the precise team size are not publicly disclosed.

Key Initiatives

Key initiatives include the implementation of a 'Secure by Design' build system characterized by parallel builds and verified steps. SolarWinds has conducted a gap analysis against NIST SSDF controls to harden their development process. They maintain an active Vulnerability Disclosure Policy (VDP) managed by a PSIRT that commits to acknowledging reports within three business days. There is no public evidence of a formal 'Security Champions' program.

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.

Interested in this role?

Apply on LinkedIn