We are looking for a hands-on security practitioner who has lived the vulnerability and exposure management problem and wants to build a better way to solve it. You will help define how Unizo investigates exposures, reasons about impact, recommends remediation, and validates that risk has gone down.
This is not a role operating another vulnerability management program. You will build the product you wish you had while running one.
What you will do
- Define how Unizo identifies and explains exposure paths, rather than re-ranking individual findings.
- Investigate how vulnerabilities, identities, privileges, reachability, cloud access, code, and asset criticality combine into meaningful exposure.
- Decide what evidence establishes that an exposure is real, materially relevant, or successfully remediated.
- Judge whether the product's conclusions are technically sound, understandable, and actionable.
- Work directly with enterprise security teams, and turn recurring needs into durable product capability.
- Shape the behaviour and guardrails of an analyst operating inside consequential security workflows.
- Set the technical standards and operating practices for the security function as the team grows.
You might be doing this today as a
Senior or Staff Security EngineerVulnerability Management Engineer or Lead
Threat and Vulnerability Management EngineerCloud Security Engineer
Product or Application Security EngineerSecurity Automation Engineer
Offensive Security Engineer with remediation depth
What we are looking for
- Hands-on experience in vulnerability management, exposure management, cloud security, product security, or security operations.
- A habit of investigating findings beyond severity scores and scanner output.
- Understanding of how vulnerabilities, identities, permissions, reachability, and environmental context determine real risk.
- Experience driving remediation with engineering, infrastructure, cloud, identity, and application owners.
- Technical judgment strong enough to separate plausible exposure from theoretical risk, and the ability to explain the difference to practitioners and executives alike.
- Comfort moving between product definition, technical investigation, customer conversations, and implementation detail.
Useful but not required: vulnerability management, CNAPP, or endpoint platforms; AWS, Azure, or Google Cloud; IAM, privileged access, and service-account security; attack-path, reachability, or threat modelling; application and software supply chain security; Python, APIs, query languages, or graph-based investigation; ServiceNow, Jira, or remediation workflow systems.
You do not need previous startup experience. We care whether you have lived the problem, developed real practitioner judgment, and want to build a better operating model for exposure reduction.
About Unizo
Security teams have no shortage of findings. The harder problem is knowing which exposures matter in their environment, what to fix first, and whether remediation actually reduced risk.
Unizo is AI-native exposure management. We connect fragmented security signals into Live Security Context, a continuously updated model of assets, vulnerabilities, identities, access, cloud infrastructure, code, ownership, and controls. The Exposure Analyst reasons over that context to investigate exposures, explain why they matter, recommend evidence-backed actions, and verify outcomes, inside the controls and approval gates each customer sets.
Interested?
No cover letter needed. Send whatever shows how you think: a note about the problem, something you have built, or why this one is interesting to you.