Hi,
If you find yourself comfortable with the requirement, please reply with your updated resume and I will get back to you or I would really appreciate if you can give me a call back at my contact number
Role Product Security Engineer (Contract) – Vulnerability Management
Duration 6+ Months
Location Hybris - Newton, MA or Mounds view, MN or Cleveland, OH
(Need local)
Phone then video interview
Job Description
Product Security Engineer (Contract) – Vulnerability Management
Candidates must also have prior experience working with SBOM tools.
A Python coding challenge will be part of the interview process
A contract Product Security Engineer is needed to support vulnerability management initiatives within a product security organization. This role is ideal for a security professional who enjoys hands‑on analysis, structured problem‑solving, and strengthening security processes through automation and cross‑team collaboration. You will work closely with engineering and security groups to identify, assess, and prioritize security risks across software components.
The primary focus of this project is vulnerability management through Software Bill of Materials (SBOM) analysis. Responsibilities include reviewing and triaging vulnerabilities discovered through SBOM scanning tools, evaluating severity and risk, and supporting remediation in partnership with cross‑functional teams. The role also involves enhancing workflow efficiency through scripting and automation, as well as maintaining clear documentation to support traceability and compliance.
- Review, analyze, and triage vulnerabilities identified through SBOM scanning tools
- Assess vulnerability severity and support risk‑based prioritization
- Collaborate with engineering, product, and security teams to drive resolution
- Monitor and track vulnerability remediation progress
- Develop or utilize scripts and automation to improve vulnerability management workflows
- Maintain accurate documentation of findings, actions taken, and outcomes
- Demonstrated experience in product security
- Proficiency in Python
- Strong analytical skills and attention to detail
- Ability to effectively collaborate with cross‑functional technical teams
- Experience with vulnerability management programs
- Experience working in a regulated industry
- Familiarity with SBOM management tools, such as Dependency Track or similar platforms
Work Environment & Expectations
-
This is an onsite hybrid role (3 days per week) at one of several designated office locations.
-
The role requires strong interpersonal and communication skills, including the ability to clearly articulate technical concepts without over‑explaining.
Questions for candidates may include: