Senior Vulnerability Management Engineer
SolarWinds
| Company | SolarWinds |
| Category | Engineering |
| Location | Krakow |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Senior |
| Salary | Not stated by the employer |
| Posted | 9 Jun 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (greenhouse) |
Description
At SolarWinds, we’re a people-first company. Our purpose is to enrich the lives of the people we serve—including our employees, customers, shareholders, partners, and communities. Join us in our mission to help customers accelerate business transformation with simple, powerful, and secure solutions.
The ideal candidate thrives in an innovative, fast-paced environment and is collaborative, accountable, ready, and empathetic. We’re looking for individuals who believe they can accomplish more as a team and create lasting growth for themselves and others. We hire based on attitude, competency, and commitment. Solarians are ready to advance our world-class solutions in a fast-paced environment and accept the challenge to lead with purpose. If you’re looking to build your career with an exceptional team, you’ve come to the right place. Join SolarWinds and grow with us!
We work in hybrid mode 3+2 , at least 3 days at the office (with mandatory Wednesdays and Thursdays) and 2 days at the home office.
The location of our office is Puszkarska 7J/Building E, 30-644 Kraków, Polska .
We employ only via an employment contract – FTE.
Role Overview
We are looking for a Senior Engineer who views Vulnerability Management as a risk-reduction craft, not a compliance checkbox. While you will be involved in high-level security operations, your primary focus is to evolve our Threat & Vulnerability Management (TVM) program from "running scans" to "driving impactful remediation of real risk."
This isn't a role for someone who just forwards PDF reports. We need a technical leader who can cut through the noise of thousands of alerts, translate CVSS scores into actual business risk, and work as a peer with our Engineering and IT teams to get things fixed. You’ll be the bridge between technical telemetry and executive-level risk decisions.
Key Responsibilities
Risk-Based Vulnerability Management: Own the full lifecycle of vulnerability discovery and remediation. You’ll move beyond "Critical/High" labels to prioritize based on reachability, exploitability-in-the-wild (EPSS/KEV), and the specific context of our environment.
Stakeholder Diplomacy: Act as the primary technical point of contact for Engineering and DevOps. You’ll be responsible for explaining the "why" behind a fix, helping teams navigate technical debt, and negotiating remediation timelines that balance security with product velocity.
Threat Hunting & Intel: Use MITRE ATT&CK® to pivot from vulnerability data to proactive hunting. If a new Zero-Day drops, you’re the one identifying our exposure surface and drafting the "what this means for us" brief within hours.
Detection & Automation: We don't want you doing the same manual task twice. You’ll build and tune detection logic and design SOAR playbooks to automate ticket routing, asset tagging, and evidence collection.
Incident Leadership: Act as a Tier 3 escalation point and Incident Commander for major security events. You’ll lead the "deep dive" after an incident to ensure the root cause is addressed in the TVM roadmap.
Strategic Reporting: Stop reporting on "number of vulnerabilities" and start reporting on "risk reduction over time." You’ll develop KPIs that actually matter to executive leadership, such as Mean Time to Remediation (MTTR) for exploited flaws and burn-down rates on mission-critical assets.
Qualifications
5–7+ years in SecOps and TVM: You’ve lived through the "log4j" style fire drills and know how to keep a cool head when things get messy.
TVM Tooling Expertise: Deep, hands-on experience with enterprise-grade scanners (Qualys, Tenable, or Rapid7) and, more importantly, the ability to integrate them into CI/CD pipelines and cloud workflows.
Cloud Security Expertise: You’re fluent in AWS/Azure/GCP security and understand why scanning a container image is different from
You found the opening. Now track it.Tracker, radar and AI drafts in one place.erioun.com →