Product Security Engineer - Vulnerability Management Research and Automation - Cork, Ireland at Qualcomm

Cork, [object Object]

on-site · full_time · Visa sponsorship

Apply for this role at Qualcomm

Responsibilities:
- Own the end‑to‑end vulnerability lifecycle: intake, triage, applicability analysis, prioritisation and remediation tracking.
- Run and tune vulnerability scanning and SCA tooling, maintain SBOMs/VEX and integrate findings into ticketing systems and dashboards.
- Build and maintain automation (scripts, pipelines, AI-assisted tooling) to scale triage, analysis and reporting workflows.
- Perform exploitability and applicability analysis to assess real product risk beyond severity scores.
- Work closely with development, infrastructure and incident response teams to recommend fixes, mitigations and secure coding patterns.
- Monitor external advisories, CVEs and threat intelligence and drive timely response and compliance reporting.

Requirements:
- Bachelor's degree in Computer Science, Engineering or equivalent and ~2+ years experience in product/app security or vulnerability management.
- Hands‑on programming skills (Python preferred) and familiarity with C/C++ codebases.
- Experience with vulnerability scanners, SCA tools, SBOM/VEX workflows and CI/CD integration of security checks.
- Strong risk‑based prioritisation skills, exploitability analysis experience and practical remediation guidance for developers.
- Good communication and collaboration skills; experience building automation to scale security operations is a plus.