Apply with hirly
Threat & Exposure Management Platform Engineer
Citi · Irving Texas United States
Upload your resume to see how well you match this job — free, in seconds, no account needed.
Your resume is used only to score it against this job. If you don't create an account, it is deleted within 24 hours.
We are looking for a highly experienced Threat & Exposure Management Platform Engineer to design, build, and operate the data platform and architecture that unifies threat, vulnerability, and exposure signal across the enterprise. This is a foundational, high-impact platform engineering role at the core of our organization's evolution toward a next-generation, AI-enabled security operations capability. You will own the architecture connecting security tooling, threat intelligence, vulnerability data, and adversary validation results into a single, continuously updated substrate — enabling faster, more accurate, and increasingly automated risk prioritization and response across the business. This role calls for someone with deep platform engineering expertise and strong architectural judgment , comfortable owning complex, mission-critical systems end-to-end rather than working on isolated components. Key Responsibilities
- Data Pipeline Engineering: Design, build, and operate scalable, resilient data pipelines that ingest, normalize, and enrich threat and exposure signals from a wide range of security, IT, and cloud platforms (e.g., vulnerability scanners, EDR/XDR, CSPM, CMDB, threat intelligence feeds, identity systems).
- Platform Integration: Develop and maintain robust API integrations connecting security tooling, data lakes, and correlation/analytics engines to create a single, unified view of the organization's threat and exposure posture.
- Correlation Engine Development: Architect and implement correlation logic and data models that link vulnerabilities, threats, assets, and business context to support automated, evidence-based risk prioritization.
- Data Substrate & Architecture Ownership: Build and evolve the underlying data substrate (schemas, storage layers, streaming infrastructure) that serves as the authoritative source of truth for enterprise risk and exposure data, and own its long-term architectural direction.
- API & Interface Development: Expose clean, well-documented, secure APIs enabling downstream systems, dashboards, and analyst tooling to consume unified threat and exposure data programmatically.
- Continuous Exposure Lifecycle Support: Build and operate the platform capabilities that support an ongoing, iterative approach to discovering, prioritizing, and validating exposures across the environment — from initial scoping through to remediation tracking.
- Adversary-Informed Validation Integration: Integrate outputs from adversary emulation, control validation, and simulation exercises into the correlation engine, enriching risk prioritization with real-world evidence of exploitability and defensive effectiveness.
- Coverage & Gap Analysis: Architect data models and pipelines that continuously assess defensive coverage against real-world attack techniques, surfacing prioritized gaps for remediation.
- Operational Reliability: Own the uptime, performance, scalability, and data quality of production pipelines and integrations; implement monitoring, alerting, and self-healing mechanisms.
- Cross-Platform Normalization: Establish common taxonomies and data standards to reconcile inconsistent data formats, severity scoring, and asset identifiers across heterogeneous security tools.
- Cross-Functional Collaboration: Partner with security operations, threat intelligence, detection engineering, red/purple team, and data science functions to ensure platform outputs meet operational and analytical needs.
- Security & Compliance: Ensure all data handling, storage, and access adhere to enterprise security, privacy, and regulatory requirements, given the sensitivity of threat and exposure data.
- Automation & Scale: Drive automation of data onboarding for new tools and platforms to reduce integration lead time as the environment and tool ecosystem grow.
- Documentation & Knowledge Transfer: Maintain architecture diagrams, runbooks, and integration documentation to support platform sustainability and team scaling. Required Skills & Experience
- Strong architecture skills — demonstrated ability to design end-to-end platform architectures spanning data ingestion, correlation, validation, and delivery layers, with sound judgment on scalability, extensibility, and long-term maintainability.
- Deep platform engineering expertise — a proven track record owning and operating complex, production-grade security data platforms end-to-end.
- Hands-on experience building large-scale data pipelines (batch and streaming) using tools such as Kafka, Spark, Airflow, Flink, or equivalent.
- Strong expertise in API design and development (REST/GraphQL), including authentication, rate limiting, and versioning for high-throughput data.
- Proven experience integrating heterogeneous security platforms (vulnerability management, EDR/XDR, CSPM, SIEM, CMDB, threat intelligence platforms, simulation/emulation tooling).
- Strong background in data modeling and correlation engine design — able to reconcile asset, vulnerability, threat, and adversary-behavior data into unified risk views.
- Practical understanding of how to operationalize an ongoing exposure discovery, prioritization, and validation process within a technical platform.
- Familiarity with mapping known attacker techniques and behaviors to defensive controls and detection coverage.
- Familiarity with simulation or emulation-based control validation approaches and how their outputs feed into broader risk models.
- Proficiency in at least one major programming language (Python, Go, or Java) for pipeline and integration development.
- Experience with cloud-native data infrastructure (AWS/Azure/GCP), including data lakes, warehouses, and event-driven architectures.
- Solid understanding of core cybersecurity concepts: vulnerability management, threat intelligence, exposure management, attack surface management, and risk scoring frameworks (e.g., CVSS, EPSS).
- Experience with database technologies spanning relational, NoSQL, graph, and time-series stores for correlation and attack-path use cases.
- Strong software engineering fundamentals: CI/CD, infrastructure-as-code, version control, testing, and observability practices.
- Excellent cross-functional collaboration skills, able to work with security operations, detection engineering, and platform architecture teams in a fast-paced, mission-critical environment. Preferred Qualifications
- 10+ yrs of experience leading a continuous exposure management program or initiative end-to-end, from architecture through operational rollout.
- Familiarity with graph-based attack path analysis or asset/risk graphs.
- Hands-on experience with adversary simulation or emulation frameworks and purple-team tooling.
- Experience supporting AI/ML-driven security operations or automation-first security initiatives.
- Relevant certifications (e.g., GIAC, cloud security or data certifications) are a plus but not required in lieu of hands-on expertise. What We're Looking For A builder who thrives on architecting and operating complex, high-stakes data platforms — someone equally comfortable in deep technical design discussions and hands-on implementation, who wants to shape the data foundation behind the next generation of automated, intelligence-driven security operations. Education:
- Bachelor’s degree/University degree or equivalent experience
- Master’s degree preferred This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required. ------------------------------------------------------ Job Family Group: Technology ------------------------------------------------------ Job Family: Information Security ------------------------------------------------------ Time Type: Full time ------------------------------------------------------ Primary Location: Irving Texas United States ------------------------------------------------------ Primary Location Full Time Salary Range: $156,160.0