Security Engineer 3 - Vulnerability Management
This role supports Tide's vulnerability management programme by validating findings, prioritising risks, automating remediation workflows, verifying fixes, partnering with engineering and IT teams, and improving remediation operations.
Responsibilities
- Triage and validate vulnerabilities from security tooling
- Prioritise findings by severity, exploitability, asset criticality, and business context
- Automate routing, ticketing, deduplication, and escalation workflows
- Verify vulnerability fixes through rescanning or manual checks
- Advise engineering and IT teams on practical remediation
- Build vulnerability posture and remediation dashboards
- Design nudging strategies to improve remediation behaviours
- Monitor ageing findings and stalled remediation items
- Improve remediation processes, SLAs, taxonomies, and tooling configuration
Requirements
- Hands-on experience in vulnerability management or a similar analytical security role
- Familiarity with Wiz, Semgrep, CrowdStrike, EASM platforms, or comparable scanners
- Understanding of CVSS, EPSS, CISA KEV exploitability, and asset context
- Experience with risk acceptance and exception management workflows
- Experience with workflow automation and orchestration
- Ability to build reports and dashboards
- Strong communication and stakeholder skills
- Experience in fintech, regulated financial services, or a high-assurance environment is preferred
Benefits
- Competitive compensation and share options
- Generous annual leave
- Paid maternity, paternity, and adoption leave
- Paid and unpaid sabbatical options
- Private family health insurance with additional OPD coverage and top-up options
- Life and accident insurance
- Therapy sessions, courses, meditations, and workshops
- Paid volunteering and development days
- Annual learning and development budget
- Work from abroad for up to 90 days annually
- Home office setup contribution
- Laptop ownership and replacement program
- Office snacks, coffee, tea, and lunch