Skip to main content
Sony Interactive Entertainment
Sony Interactive Entertainment

Senior Security Research Engineer

RemoteUnited States only
Published
Role
Security
Experience
Lead
Company size
Enterprise
$175.5k–$263.3k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior security researcher/engineer with 8+ years in information security, vulnerability management, security research, or exposure management. Must lead cross-team technical workstreams and do hands-on vulnerability research, validation, risk-based prioritization, remediation guidance, scripting/API automation, and security data analysis. US remote role with background checks; Seattle example pay range given.

Core skills

Vulnerability ManagementThreat Exposure ManagementSecurity Validation

Required skills

MITRE ATT&CKAPIsPython/SQL/Bash/PowerShell/JavaScriptversion controltestingcode reviewCI/CD

Optional skills

SnowflakeDomo

What you'll do

  • Lead complex Global Vulnerability Management workstreams that advance SIE’s Threat Exposure Management capability and transition toward a Continuous Threat Exposure Management operating model across discovery, prioritization, validation, and mobilization.
  • Translate annual TEM goals into defined delivery plans, milestones, success measures, dependencies, and repeatable operating practices.
  • Monitor progress, identify barriers, and adjust execution to improve outcomes.
  • Lead hands-on vulnerability research and technical analysis to confirm security conditions, eliminate false positives, characterize exploitability and business impact, and provide actionable remediation or mitigation guidance.
  • Improve the discovery and assessment of vulnerabilities across SIE network, cloud, endpoint, application, container, and other technology environments.
  • Develop risk-based prioritization using vulnerability and threat intelligence, exploitation evidence, asset and business context, control effectiveness, and remediation considerations.
  • Lead security validation activities and develop proofs of concept when appropriate to distinguish material risk, evaluate defensive controls, and support informed decisions.
  • Partner with Information Security teams and technology owners to mobilize remediation, clarify ownership, establish effective handoffs, resolve barriers, and measure progress through remediation, mitigation, or accepted disposition.
  • Evolve GVM platforms, integrations, data, analytics, automation, and AI-enabled workflows to improve coverage, data quality, consistency, decision speed, and operational scale.
  • Communicate vulnerability trends, material risks, remediation progress, and program outcomes to technical, operational, and leadership audiences through clear reports and recommendations.
  • Mentor engineers and partner teams, contribute to technical standards and procedures, and improve the quality of vulnerability analysis, validation, documentation, and delivery.
  • Maintain current knowledge of relevant vulnerabilities, exploitation techniques, threat activity, security technologies, and industry practices.
  • Some travel may be required.

What they require

  • 8+ years of relevant experience in information security, information technology, systems engineering, or a related field, including substantial experience in vulnerability management, security research, or exposure management.
  • Bachelor’s degree or equivalent in computer science, information security, or a related discipline.
  • Experience leading complex technical workstreams across multiple teams, translating objectives into delivery plans, and achieving measurable outcomes without relying on direct reporting authority.
  • Hands-on experience with vulnerability research, technical analysis, security validation, risk-based prioritization, and remediation or mitigation guidance.
  • Experience assessing vulnerabilities across several technology domains, such as operating systems, networks, cloud services, applications, endpoints, containers, databases, or hybrid infrastructure.
  • Experience with vulnerability discovery, assessment, validation, or exposure-management platforms and their supporting integrations.
  • Knowledge of adversarial tactics, exploitation techniques, threat intelligence, and attack frameworks such as MITRE ATT&CK, with the ability to apply that information to vulnerability prioritization.
  • Experience using scripting, programming, APIs, or automation to improve security analysis and operational workflows. Relevant technologies may include Python, SQL, Bash, PowerShell, JavaScript, or comparable languages.
  • Experience analyzing and contextualizing security data to connect technical findings with asset, service, business, threat, control, and remediation information.
  • Familiarity with software engineering practices such as version control, testing, code review, CI/CD, reusable components, and controlled production releases.
  • Ability to communicate complex security conditions, priorities, tradeoffs, and recommendations clearly to technical, operational, and leadership audiences.
  • Experience mentoring engineers or analysts and influencing technical practices across teams.
  • Preferred: Experience helping evolve a traditional vulnerability-management function toward a TEM or CTEM operating model.
  • Preferred: Experience with continuous security validation, adversarial exposure validation, exploit research, or proof-of-concept development.
  • Preferred: Experience securing cloud, container, application, or build-pipeline environments and integrating security capabilities into engineering workflows.
  • Preferred: Experience applying automation, advanced analytics, or AI-enabled capabilities to vulnerability analysis, prioritization, validation, or remediation workflows.
  • Please note, Sony Interactive Entertainment conducts background checks at the offer stage for all new employees.

Benefits

  • Medical
  • Dental
  • Vision
  • Matching 401(k)
  • Paid time off
  • Wellness program
  • Employee discounts for Sony products
  • This role also may be eligible for a bonus package.
  • Flexible role that can be remote

Sony Interactive Entertainment is the company behind PlayStation, offering consoles, accessories, games, services, and related gaming and digital entertainment experiences worldwide. The company also conducts R&D in areas such as AI, neural networks, machine learning for game rendering, and entertainment technologies.

🇺🇸 United StatesTechnologyEnterprisesonyinteractive.com/en/

Details

Apply routeGreenhouse
$175.5k–$263.3k/yr