1

Vulnerability Security Engineer Jobs in California

Lead vulnerability management, coordinate bug bounty responses, and drive remediation priorities ... security engineering or application security * Strong hands‑on experience securing AWS ...

Application Security Engineer

Sunnyvale, CA · On-site

$70 - $93.50/hr

You will own and evolve key parts of our vulnerability management program from vulnerability ... Help integrate security controls into CI/CD and developer workflows while minimizing unnecessary ...

Application Security Engineer

Sunnyvale, CA · On-site

$69 - $92.25/hr

You will own and evolve key parts of our vulnerability management program from vulnerability ... Help integrate security controls into CI/CD and developer workflows while minimizing unnecessary ...

Position Summary As a Security Engineer at HeyGen, you will own the security posture of one of the ... Cloud & Vulnerability Management: Own the strategy and execution for hardening our AWS/Python ...

Company Description About the Host Security Engineer Opportunity Talent Connection is partnering ... Support vulnerability management initiatives by identifying risks and assisting with remediation ...

Company Description About the Host Security Engineer Opportunity Talent Connection is partnering ... Support vulnerability management initiatives by identifying risks and assisting with remediation ...

The Cyber Defense team manages security controls spanning vulnerability scanning, security patching ... You will join a DevOps team of Information Security professionals responsible for developing ...

Company Description About the Host Security Engineer Opportunity Talent Connection is partnering ... Support vulnerability management initiatives by identifying risks and assisting with remediation ...

Vulnerability management: Lead proactive vulnerability assessments, pen tests, and remediation ... DevSecOps integration: Partner with DevOps teams to embed security into the CI/CD pipeline ...

Security Engineer

San Francisco, CA · On-site

$110K - $193K/yr

Conduct vulnerability scanning, penetration testing, and security assessments to detect weaknesses ... Work with DevOps to integrate security into CI/CD pipelines and automate security testing.

Senior Security Engineer

Palo Alto, CA · On-site

$134K - $185K/yr

The Senior Security Engineer, reporting to the Associate Director of Security Engineering, will be ... Support Vulnerability Management activities, including scanner operations, asset coverage ...

Application Security Engineer

San Francisco, CA · On-site

$69.25 - $92.50/hr

Zof AI is seeking an Application Security Engineer to own the security posture of a platform that ... Working knowledge of application security and common vulnerability classes. * Experience with cloud ...

Security Engineer Location: Sunnyvale, CA (Hybrid 3 days On-Site and 2 days Remote) We are seeking ... Vulnerability Assessment -- Conduct vulnerability scans of supplier environments to ensure secure ...

Own penetration tests, vulnerability scans, remediation programs, and practical security policies ... A software engineering or computer science foundation before moving into security. * Strong ...

Application Security Engineer

San Francisco, CA · On-site

$69.25 - $92.50/hr

Drive vulnerability identification using SAST, DAST, SCA and in-house AI tooling and manage ... externally about security projects valued. * Programming Skills - Experience writing and ...

Showing results 21-40

Vulnerability Security Engineer information

What cities in California are hiring for Vulnerability Security Engineer jobs?

Cities in California with the most Vulnerability Security Engineer job openings:

Infographic showing various Vulnerability Security Engineer job openings in California as of August 2026, with employment types broken down into 82% Full Time, 14% Part Time, and 4% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution.

Security Engineer

San Francisco, CA • On-site

Other

This job post has expired today. Applications are no longer accepted.


Job description

We're building the creative layer for modern communication. Every month, over a billion people make presentations — but the tools they use to make them haven't evolved in decades. We're changing that, using AI to disrupt a massive market.

Millions of people rely on Gamma to create, teach, and persuade, creating more than 1 million gammas every day.

We see Gamma as the next great workplace tool, combining viral B2C love with a massive B2B opportunity. We believe AI can be a true creative partner: one that understands context, clarity, and taste.

We’ve reached a $2.1B valuation, crossed $100M in annual recurring revenue, and have been profitable since 2023.

We're an imaginative, passionate team who takes our work seriously, but not ourselves. Our culture is warm, a little quirky, and fueled by curiosity.

Why this role matters now

AI is fundamentally changing the cybersecurity landscape. Frontier AI models are rapidly reducing the time, resources, and skill required to find and exploit software vulnerabilities. This works both ways: defenders who adopt AI tools can move just as fast. At Gamma, we believe security engineering must evolve to meet this moment. That means closing patch gaps faster, scanning our own code with the same frontier models an attacker would use, designing systems that hold even when an adversary has unlimited patience, and building incident response capabilities that can handle simultaneous, AI-accelerated threats.

About the role

You’ll protect Gamma’s platform, infrastructure, and data as we scale to serve hundreds of millions of users. That means building security tooling and automation, partnering with engineering teams to embed security into everything we ship, and helping shape how the company thinks about security as a practice. You’ll work across the organization to identify and mitigate risks without slowing down development velocity.

This role combines hands‑on security engineering with strategic influence. You’ll write code to solve security problems, conduct architecture reviews, lead vulnerability management, and drive initiatives for compliance frameworks like SOC 2 and ISO 27001. You’ll work closely with engineering, product, and compliance to make security foundational rather than reactive.

Our team has a strong in‑office culture and works in person 4–5 days per week in San Francisco. We love working together to stay creative and connected, with flexibility to work from home when focus matters most.

What you'll do
  • Design and implement security controls across Gamma’s AWS infrastructure and application layer
  • Build security tooling and automation to detect, prevent, and respond to threats at scale
  • Conduct security reviews of architecture designs, code, and infrastructure changes
  • Lead vulnerability management, coordinate bug bounty responses, and drive remediation priorities
  • Develop and maintain security monitoring, alerting, and incident response capabilities
  • Partner with engineering teams on secure coding practices and threat modeling
  • Deploy AI‑assisted vulnerability scanning across our codebase and infrastructure—scanning our own systems with frontier models before attackers do
  • Build automated triage workflows that use AI to deduplicate findings, estimate exposure, and draft remediation tickets
  • Drive adoption of memory‑safe languages and secure‑by‑design practices for new code, informed by current CISA and NCSC guidance
What you'll bring
  • 5+ years of software engineering experience with at least 2–3 years focused on security engineering or application security
  • Strong hands‑on experience securing AWS environments, including IAM, VPC, security groups, CloudTrail, and GuardDuty
  • Proficiency in at least one backend language (Python, TypeScript/Node.js, or Go preferred) with experience building security tools
  • Deep understanding of web application security including OWASP Top 10, common vulnerability classes, and authentication/authorization patterns, with experience implementing security controls in CI/CD pipelines and infrastructure‑as‑code (Terraform, CloudFormation)
  • Clear communicator who works well embedded with product engineering teams
  • Background in penetration testing, offensive security, and SIEM/log analysis
Nice to have
  • Experience at a high‑growth SaaS startup navigating rapid scaling and compliance
  • Familiarity with AI/ML security tooling, including using frontier models for code scanning, automated pentesting, or threat detection
  • Experience building zero‑trust architecture or identity‑aware access controls (FIDO2, short‑lived tokens, hardware‑bound credentials)
  • Knowledge of supply chain security frameworks like SLSA, OpenSSF Scorecard, or SBOM tooling
Compensation range

The base salary for this full‑time position, which spans multiple internal levels depending on qualifications, ranges between $180K – $310K plus benefits & equity. Final offer amounts are determined by multiple factors, including but not limited to experience and expertise in the requirements listed above.

If you’re interested in this role but don’t meet every requirement, we encourage you to apply anyway!

#J-18808-Ljbffr