Primary Skills: Product Security (Expert), Vulnerability Assessment & Triage (Expert), Application Security (Expert), Penetration Testing (Advanced), Reverse Engineering & Secure Software Development (Advanced)
Contract Type: W2 Only
Duration: 6+ Months
Location: Remote (Anywhere in the US)
Pay Range: $70 - $74 on W2
Job Summary:We are seeking a Product Security Incident Response Engineer (PSIRT) to investigate, analyze, and coordinate the response to reported product security vulnerabilities across enterprise products. The ideal candidate will have strong expertise in product security, application security, vulnerability research, and secure software development, with the ability to collaborate across engineering, product, legal, and customer-facing teams to drive timely vulnerability remediation and disclosure.
Key Responsibilities:- Investigate, reproduce, and analyze reported product security vulnerabilities.
- Perform vulnerability triage, impact analysis, exploitability assessment, and CVSS scoring.
- Lead root cause analysis and partner with engineering teams to validate remediation efforts.
- Collaborate with Product, Engineering, Legal, Privacy, and Threat Intelligence teams on vulnerability response.
- Engage with customers and security researchers throughout the vulnerability disclosure process.
- Draft and publish security advisories and coordinate responsible disclosure activities.
- Improve PSIRT processes, automation, and tooling to accelerate vulnerability response.
Must-have Skills:- 4+ years of experience in Product Security, Application Security, Vulnerability Research, or PSIRT.
- Strong experience with Vulnerability Assessment, Vulnerability Triage, and Penetration Testing.
- Expertise in reverse engineering, debugging, and secure software development practices.
- Strong understanding of CVSS, CVE, NIST, FIRST, and CNA vulnerability management standards.
- Experience reproducing, analyzing, and assessing complex security vulnerabilities.
- Proficiency in scripting and automation using Python, Go, Bash, or PowerShell.
- Excellent analytical, troubleshooting, and cross-functional collaboration skills.
- BS/MS degree in Computer Science, Engineering, Cybersecurity, or a related field.
Nice-to-have Skills:- Experience working within a Product Security Incident Response Team (PSIRT).
- Familiarity with vulnerability disclosure programs and coordination with external security researchers.
- Experience developing security automation tools and workflow improvements.
- Knowledge of enterprise software, cloud platforms, and secure development lifecycle (SDLC).
- Security certifications such as OSCP, GSEC, CISSP, or GIAC are a plus.
ABOUT AKRAYAAkraya is an award-winning IT staffing firm consistently recognized for our commitment to
excellence and a thriving work environment.Â
Most recently, we were recognized Stevie Employer of the Year 2025, SIA Best Staffing Firm to work for 2025, Inc 5000 Best Workspaces in US (2025 & 2024) and Glassdoor's Best Places to Work (2023 & 2022)!Industry Leaders in Tech StaffingAs Talent solutions provider for Fortune 100 Organizations, Akraya's industry recognitions solidify our leadership position in the IT staffing space.Â
We don't just connect you with great jobs, we connect you with a workplace that inspires!Join Akraya Today!Let us lead you to your dream career and experience the Akraya difference. Browse our open positions and join our team!