Vulnerability Operations Engineer - Remote

Remote, USA
Posted Jun 14, 2026
Full-time

What We’re About

At CentralSquare, we don’t just build software - we power public servants and uplift communities with Hero-Grade Technology. Every line of code, every feature we deliver helps heroes across North America protect, serve, and save lives. When you join us, you become part of a mission-driven team creating technology that makes communities safer and stronger.

Your Growth Matters. We believe heroes deserve opportunities to rise. That’s why we invest in your career with mentorship, learning programs, and clear paths for advancement. If you’re motivated, there’s no limit to how far you can go.

Your Commitment Deserves Reward. We offer competitive compensation and a benefits package designed to support your life inside and outside of work—tuition reimbursement, parental leave, paid volunteer hours, and unlimited PTO. Plus, our flexible work environment gives you the freedom to balance your heroic work with personal well-being, whether you’re in the office or remote.

Join us and help build the tools that power real-life heroes. Together, we make a difference.

 

The Role

CentralSquare is seeking a Vulnerability Operations (VulnOps) Engineer to join our Security team. This is an individual contributor role purpose-built for the post-AI era of vulnerability discovery — where AI models can now find and exploit flaws at machine speed, and reactive patch cycles are no longer sufficient.

This role is not an advisory function. The VulnOps Engineer owns the full pipeline from discovery through fix delivery: running AI-powered scanning against CentralSquare's codebases and dependencies on a continuous basis, generating validated fixes, and submitting ready-to-merge pull requests into owning teams' Azure DevOps pipelines. App teams retain code review and merge authority; this role exists to ensure they are never handed a problem without also being handed a solution.

Job Duties Include:

Proactive Vulnerability Discovery

Operate and continuously improve an AI-powered scanning pipeline across CentralSquare's first-party codebases, open-source dependencies, and infrastructure components

Use Claude Code, Veracode, and Orca to conduct ongoing static analysis, software composition analysis (SCA), and cloud posture assessments

Apply reachability analysis to distinguish genuinely exploitable vulnerabilities from theoretical findings, reducing alert fatigue and focusing remediation effort where risk is real

Monitor threat intelligence feeds, CVE disclosures, and coordinated disclosure programs (including Project Glasswing patch releases) to identify newly disclosed vulnerabilities affecting CentralSquare's software supply chain

Fix Development and Delivery

Develop and validate fixes (code patches, dependency upgrades, configuration changes) using AI coding agents such as Claude Code, verifying resolution without regressions before submission

Submit validated fixes as pull requests into owning teams' Azure DevOps repositories, with clear documentation of the vulnerability, risk context, and fix rationale to support efficient review and merge

Collaborate with application and infrastructure teams during code review, providing technical context and responding to questions about proposed changes

SLA Ownership and Reporting

Own the end-to-end SLA lifecycle for all open findings, maintaining real-time tracking of detection, fix submission, and merge status in the vulnerability management system

Proactively escalate findings approaching SLA breach with remediation options and risk context

Produce regular reporting on pipeline health, SLA adherence, remediation velocity, and open risk posture for the security leadership team

Toolchain and Pipeline Maintenance

Own the configuration, tuning, and operational health of VulnOps tooling including Veracode, Orca, Claude Code, and Azure DevOps security integrations

Identify and reduce false positive rates through policy tuning and reachability filtering, ensuring signal quality remains high as scan volume increases

Contribute to the development of automated remediation pipelines, including AI-assisted fix generation integrated directly into CI/CD workflows

Evaluate and recommend new tools and capabilities as the AI security tooling landscape evolves

Cross-Functional Collaboration

Work closely with application engineering, DevOps, and infrastructure teams to ensure fix delivery is efficient and minimally disruptive to development velocity

Provide security guidance to engineering teams on secure coding practices and dependency management in the context of AI-accelerated vulnerability discovery

Partner with the Risk and Compliance team to ensure vulnerability data and SLA metrics align with audit and regulatory reporting requirements (NIST CSF, PCI DSS, CJIS)

Perform other duties as assigned

More Remote Jobs