Akraya, Inc. is an award-winning IT staffing firm recognized for its commitment to excellence and a thriving work environment. They are seeking a Product Security Incident Response Engineer (PSIRT) to investigate and respond to product security vulnerabilities, collaborating across various teams to ensure timely remediation and disclosure.
Responsibilities:
- Investigate, reproduce, and analyze reported product security vulnerabilities
- Perform vulnerability triage, impact analysis, exploitability assessment, and CVSS scoring
- Lead root cause analysis and partner with engineering teams to validate remediation efforts
- Collaborate with Product, Engineering, Legal, Privacy, and Threat Intelligence teams on vulnerability response
- Engage with customers and security researchers throughout the vulnerability disclosure process
- Draft and publish security advisories and coordinate responsible disclosure activities
- Improve PSIRT processes, automation, and tooling to accelerate vulnerability response
Requirements:
- 4+ years of experience in Product Security, Application Security, Vulnerability Research, or PSIRT
- Strong experience with Vulnerability Assessment, Vulnerability Triage, and Penetration Testing
- Expertise in reverse engineering, debugging, and secure software development practices
- Strong understanding of CVSS, CVE, NIST, FIRST, and CNA vulnerability management standards
- Experience reproducing, analyzing, and assessing complex security vulnerabilities
- Proficiency in scripting and automation using Python, Go, Bash, or PowerShell
- Excellent analytical, troubleshooting, and cross-functional collaboration skills
- BS/MS degree in Computer Science, Engineering, Cybersecurity, or a related field
- Experience working within a Product Security Incident Response Team (PSIRT)
- Familiarity with vulnerability disclosure programs and coordination with external security researchers
- Experience developing security automation tools and workflow improvements
- Knowledge of enterprise software, cloud platforms, and secure development lifecycle (SDLC)
- Security certifications such as OSCP, GSEC, CISSP, or GIAC are a plus