About this role
About the Role
Join our security team to help detect and remediate vulnerabilities in real time using CodeQL analysis and AI-powered fixes. You will scale security across repositories with Copilot Autofix and security campaigns to reduce security debt and enable developers to ship secure software faster. What You'll Do
-
Leverage CodeQL to detect data-flow vulnerabilities across applications in real time.
-
Use Copilot Autofix to generate precise, context-aware fixes within GitHub workflows.
-
Manage security campaigns to group vulnerabilities, assign ownership, and monitor remediation progress across multiple repositories.
-
Perform dependency analysis with dependency review scans to prevent introducing vulnerable packages.
-
Utilize Exploit Prediction Scoring System (EPSS) to prioritize vulnerability remediation.
-
Conduct Code Security Risk Assessments to identify code-level vulnerabilities and guide security improvements. What We're Looking For
-
Experience with static analysis and AI-powered remediation, especially GitHub Code Security, CodeQL, and Copilot Autofix.
-
Familiarity with dependency management, Dependabot, and vulnerability management workflows.
-
Ability to coordinate remediation across multiple repositories and teams at scale.
-
Knowledge of vulnerability risk scoring (EPSS) and prioritization.
-
Strong collaboration and communication skills and a passion for secure software delivery. Nice to Have
-
Experience running security campaigns and consolidating security debt across large codebases.
-
Prior experience with security risk assessments or whitepapers related to secure software practices.