cover image
Sandisk

Senior Vulnerability Management Engineer

On site

Milpitas, United states

Senior

Full Time

15-10-2025

Share this job:

Skills

Communication Leadership Python Bash PowerShell Vulnerability Assessment DevOps Ansible Prioritization Decision-making Attention to detail Training Architecture Systems Architecture Risk Assessment Risk Mitigation Organization Terraform Flash

Job Specifications

Company Description

Sandisk understands how people and businesses consume data and we relentlessly innovate to deliver solutions that enable today's needs and tomorrow's next big ideas. With a rich history of groundbreaking innovations in Flash and advanced memory technologies, our solutions have become the beating heart of the digital world we're living in and that we have the power to shape.

Sandisk meets people and businesses at the intersection of their aspirations and the moment, enabling them to keep moving and pushing possibility forward. We do this through the balance of our powerhouse manufacturing capabilities and our industry-leading portfolio of products that are recognized globally for innovation, performance and quality.

Sandisk has two facilities recognized by the World Economic Forum as part of the Global Lighthouse Network for advanced 4IR innovations. These facilities were also recognized as Sustainability Lighthouses for breakthroughs in efficient operations. With our global reach, we ensure the global supply chain has access to the Flash memory it needs to keep our world moving forward.

Job Description

We are seeking a highly skilled and experienced Senior Attack Surface Management Engineer to spearhead our vulnerability assessment, remediation, and attack surface reduction efforts. This position involves leading the identification, assessment, and mitigation of vulnerabilities across various platforms, networks, and applications, with a focus on reducing the organization's attack surface. The ideal candidate will have a proven track record in vulnerability management, with in-depth expertise in identifying, prioritizing, and mitigating vulnerabilities across complex enterprise environments.

Essential Duties And Responsibilities

Lead Vulnerability Management: Take ownership of the vulnerability management lifecycle, including identification, assessment, prioritization, remediation, and reporting of security vulnerabilities. Oversee regular vulnerability scans, penetration tests, and security assessments to identify weaknesses in systems, networks, and applications.
Attack Surface Reduction: Analyze and map the organization's attack surface, identifying potential entry points and areas of exposure. Develop and implement strategies to reduce the attack surface across all digital assets, ensuring proactive defense against emerging threats. Continuously monitor changes to the IT environment to ensure the attack surface remains minimized.
Collaboration & Mentorship: Work closely with cross-functional teams, including IT, DevOps, and security operations, to integrate vulnerability management practices into development and operational processes. Provide mentorship and training to junior security team members.
Stakeholder Communication: Effectively communicate vulnerability management activities, findings, and risk mitigation strategies to technical and non-technical stakeholders, including senior leadership.
Critical Decision-Making: Make informed, critical decisions in high-pressure situations, ensuring the protection of the organization's infrastructure and data.
Governance & Continuous Improvement: Stay current with the latest vulnerability management tools, technologies, and methodologies, and continuously improve the organization's vulnerability management program. Ensure that vulnerability and attack surface management processes comply with industry standards, regulations, and organizational policies.
Automation and Tooling: Evaluate and implement tools and technologies to automate vulnerability scanning, risk assessment, and remediation tracking. Develop and maintain scripts, tools, and processes to streamline and enhance the effectiveness of the vulnerability management program.

Qualifications

Technical Skills:

Deep understanding of vulnerability management tools (e.g., Nessus, Qualys, Tenable), systems architecture, and security technologies.
Extensive experience in vulnerability assessment and management within large-scale, complex IT environments.
Working with large eco systems with a number of security related tools such as Asset Management, Vulnerability Scanners (Nessus, Qualys), Endpoint Protection (CrowdStrike, Defender), SEIM etc...
Proficiency in scripting languages (e.g., Golang, Python, Bash, PowerShell) and experience with automation tools. (Ansible, Terraform)
Relevant certifications such as CISSP, CISM, or CEH are preferred

Soft Skills

Exceptional communication skills, with the ability to translate technical issues into business risks for stakeholders.
Ability to make critical decisions under pressure and in complex situations.
High level of integrity, professionalism, and attention to detail.
Prior experience in a global or large-scale SOC environment.

Additional Information

Sandisk is committed to providing equal opportunities to all applicants and employees and will not discriminate against any applicant or employee based on their race, color, ancestry, r

About the Company

We are the new SANDISK. Follow us for all company info. Don't Stop. Sandisk has been expanding the possibilities of data storage for more than 25 years--giving businesses and consumers the peace of mind that comes from knowing their data is readily available and reliable, even in the most challenging environments. Our products are used in the world's leading-edge data centers, embedded in game-changing smartphones, tablets, and laptops, and entrusted by consumers around the world. As a vertically-integrated storage solutio... Know more