Senior Security Engineer - Vulnerability Research
Tanium · Remote, US · United States · Remote
Pay: USD 191,000 – 293,000 a year
Posted Oct 8, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
The Basics
Tanium is looking for a security engineer to join the Vulnerability Research team within the R&D Security organization, which protects the software and cloud services our customers depend on.
Tanium's customers secure some of the most consequential networks in the world and they extend us a great deal of trust. The Vulnerability Research team is responsible for hunting for previously-unknown vulnerabilities in our software and driving them to remediation before attackers can exploit them.
In this role, you will continuously raise the bar for attackers, making vulnerabilities in Tanium software harder and more expensive to find. Tanium is leveraging frontier models and developing agentic security workflows to scale and accelerate the find-and-fix loop. You will apply your deep security expertise to decide what to hunt for and streamline the vulnerability discovery, triage, and remediation processes.
What you’ll do
Decide which attack surfaces and bug classes to go after and build the capability needed to discover new vulnerabilities
Triage newly discovered vulnerabilities quickly and accurately, ranking them by exploitability and actual impact
Make remediation easy for engineering by providing high-quality patch guidance and working pull requests in addition to the vulnerability reports
Maintain a threat model of Tanium software and services and use it to direct future vulnerability research projects
Drive vulnerability research with frontier AI capabilities by evaluating what is possible using in-house and third-party tooling and building agentic workflows around what works
Build and maintain reliable tooling to support vulnerability research efforts including AI skills, fuzzing harnesses and static and dynamic analyzers
Shorten the time from detection to remediation by driving down false positive rate and improving finding quality
Perform source code review and targeted security assessment of high-risk components
We’re looking for someone with
Education
Bachelor's Degree in Computer Science, or other relevant degree or equivalent experience
Experience
5+ years industry experience, 7+ preferred
Strong understanding of web and native application security
Experience with hands-on vulnerability research via source code review, manual application penetration testing, or fuzzing
Expertise in determining the severity and exploitability of a vulnerability and its impact to the business
Able to read and write code in at least one of: Go, C++, TypeScript/JavaScript, or Python
Experience with the process of developing, building, and shipping secure code
Nice to have:
Experience applying frontier models to vulnerability research, and an informed view of where AI accelerates outcomes and where it manufactures noise
Experience with reachability or exploitability analysis to separate real findings from theoretical ones at scale
Experience with native code security (C/C++) in privileged or…