Director, Vulnerability Engineering

13 hours ago

Toronto, Ontario, Canada Socket.dev Full-time

Job Description

What is the opportunity?

The Director of Vulnerability Engineering leads the application and data engineering teams responsible for building and operating the platform that enables application teams to manage vulnerabilities end-to-end. This platform will also serve as the home for Exposure Management and reporting. The team also supports internal automation, AI skills, and controls engineering. The role reports to the Sr. Principal, Vulnerability and Exposure Management.

This is a team full of initiative and momentum — we’re shipping a platform that will change how thousands of engineers interact with vulnerability data. You’ll have the rare opportunity to lead both application and data engineering in a space where AI, automation, and graph technologies are being applied to real security problems at enterprise scale. If you want to build products that matter, not just maintain systems, this is the role.

What will you do?

  • Oversees the execution of enterprise wide application security services, including secure design, testing, remediation, and training, ensuring alignment with organizational standards and objectives.
  • Provides strategic leadership in implementing security frameworks, tools, and processes to address complex security challenges and drive innovation.
  • Manages budgets and resource allocation to ensure operational efficiency, compliance with policies and adherence to regulatory requirements.
  • Cultivates stakeholder relationships to influence strategic decisions and promote the adoption of secure application practices across the organization.
  • Manages application security initiatives of significant complexity, applying advanced technical expertise to solve abstract problems, and making independent decisions across business units.
  • Makes independent decisions on program, technical or operational strategy for the department, providing leadership, coaching and mentorship through senior managers and managers. Sets strategic direction for the department or area receiving high level direction from senior leaders.
  • Drives innovation across areas of responsibility identifying opportunities for making operational changes and practices, solving highly complex problems broadly related to application security.
  • Leads cross functional collaboration efforts, fostering strong internal relationships across the organization and external relationships to drive business outcomes.
  • Lead and develop the application and data engineering teams delivering the vulnerability management platform.
  • Partner with product on the design of platform capabilities, then build and operationalize them to enable application teams to manage vulnerabilities end-to-end.
  • Define and execute the engineering roadmap for Exposure Management and reporting capabilities within the platform
  • Deliver internal automation and AI skills that accelerate vulnerability assessment, prioritization, and resolution
  • Manage the engineering lifecycle for the automation of controls validation, ensuring controls are working as expected
  • Partner across Technology and Operations to translate requirements into scalable engineering solutions
  • Establish engineering standards, delivery practices, and technical governance across the team
  • Attract, retain, and grow engineering talent across application development and data engineering disciplines.

What do you need to succeed?

Must Have

  • 6+ years of experience in software engineering with progressive leadership responsibility
  • Experience leading application and data engineering teams in an enterprise environment
  • Experience designing and delivering platforms that support end-to-end operational workflows
  • Working familiarity with data modeling, graph databases, or knowledge graph architectures
  • Experience building and operationalizing automation at scale
  • Ability to partner with product and translate business requirements into engineering delivery
  • Effective stakeholder management skills across technical and non-technical audiences
  • Experience working within regulated industries (financial services preferred)

Nice to have

  • Understanding of vulnerability management, exposure management, or cybersecurity operations
  • Experience with AI/ML integration, LLM-based tooling, or intelligent automation
  • Familiarity with security control frameworks and control validation methodologies
  • Experience with graph technologies such as Neo4j, Neptune, or similar
  • Prior experience in a financial institution or similarly regulated enterprise
  • Familiarity with agile delivery practices and engineering governance at scale

What’s in it for you?

We thrive on the challenge to b