--- title: 'Security Engineer - Vulnerability Management at Endor Labs' canonical: 'https://feeny.ai/job/security-engineer-vulnerability-management-endor-labs-bengaluru-pphhmsbqdyy2' type: 'job' last_seen: '2026-09-12' --- # Security Engineer - Vulnerability Management at Endor Labs - **Company:** Endor Labs - **Location:** Bengaluru, India - **Posted:** 2026-08-31 - **Last confirmed live:** 2026-09-12 - **Apply:** https://job-boards.greenhouse.io/endorlabs/jobs/4728305005 ## Job description ## Who we are Our mission is to help developers and AppSec teams spend more time accelerating development and less time dealing with security issues. Watch our 3 min pitch from our Founder & CEO here: https://www.youtube.com/watch?v=B0wmZBcPkFE Endor Labs has been recognized as a Gartner Cool Vendor, a RSA Innovation Sandbox finalist, and a Black Hat Innovation Spotlight finalist, all in its first year from launch. The company was founded by [Varun Badhwar](https://www.linkedin.com/in/vbadhwar/) and [Dimitri Stiliadis](https://www.linkedin.com/in/stiliadis/), who have created multiple category-defining cloud security companies. We have raised $70M in Series A funding and assembled a team of the world’s leading static analysis experts and enterprise software veterans to increase developer productivity and open source software adoption. ## What you’ll do - The primary focus of this position is to help the team further advance Endor Labs'proprietary vulnerability database — extending and improving our existing AI pipelines, e.g., in the areas of automated vulnerability validation, reachability analysis, and exploit generation. - Day-to-day work includes monitoring and managing pipelines that triage, enrich, and prioritize vulnerabilities at scale, working with the standards and data sources the ecosystem is built on (CVE, CWE, CVSS, EPSS, PURL, NVD, OSV, GHSA, VEX) and continuously improving the accuracy, coverage, and timeliness of our data. - You will work hand-in-hand with our world-class 0-day researchers to scale automated vulnerability discovery — turning manual research workflows into repeatable, production-grade systems. - You will investigate high-impact vulnerabilities and the vulnerability landscape at large, and author external-facing content — blog posts, technical write-ups, and advisories — communicating findings clearly to both technical and non-technical audiences. - You will collaborate with internal teams to feed findings into detection and analysis pipelines, enrich our vulnerability database, and help improve automated coverage over time ## What we're looking for - Bachelor's degree in engineering or a related field, with at least 3 years of hands-on professional experience in vulnerability research, vulnerability management, product security, or application security - Extensive knowledge of software vulnerabilities, triage, and prioritization, including deep familiarity with the associated standards and technologies (CVE, CWE, CVSS, EPSS, PURLs, NVD, OSV, VEX, SBOM formats) - Hands-on experience building production-grade solutions at enterprise scale — e.g., CI/CD automation, management of SAST/SCA findings, or comparable security tooling deployed across large engineering organizations - Demonstrated experience shipping AI/agentic systems to production — LLM pipelines, agent frameworks, tool use, prompt and eval design — with a clear track record of measuring output quality and a sound sense of where these approaches hold up and where they don't - Proficiency in reading and analyzing code across multiple languages (Python, JavaScript/TypeScript, Java, Go), and comfort reasoning about patches, root causes, and exploitability - Experience producing external security communications: blog posts, advisories, or technical reports intended for a public or customer-facing audience ## Nice to have - Experience writing proof-of-concept exploits, or with fuzzing, static analysis, or automated vulnerability discovery - Contributions to open source vulnerability databases, scanners, or related tooling (OSV, osv-scanner, OpenVEX, etc.) - Familiarity with SAST, SCA, and DAST tooling and the realities of triaging their output at scale - Understanding of software supply chain security standards and frameworks (SLSA, SSDF, etc.) - Prior public research, CVE credits, or published vulnerability findings - Security certifications such as OSCP, OSCE, or equivalent At Endor Labs, we: - Strive for excellence in everything we do, prioritizing quality, speed, and impactful outcomes. - Engage in first principles thinking to debate ideas, test assumptions, and make decisions. - Put data above opinions, seeking truth and clarity in all our endeavors. - Embrace a culture of feedback and continuous improvement, assuming good intent in all interactions. - Celebrate wins as a team, understanding that our collective success is intertwined with the success of our customers. ## About Endor Labs ## Company Overview - **One-liner**: Endor Labs provides an agentic application security platform that helps teams find, prioritize, and fix the most critical risks in code—whether written by humans or AI—faster. - **Entity Type**: Private (Series B); total funding $188M - **Headquarters**: Palo Alto, California, United States - **Founded**: 2021 - **Founders**: Varun Badhwar and Dimitri Stiliadis ## Core Business - **Primary industry/industries**: Application security, software supply chain security, AI security - **Target customers**: B2B, enterprise AppSec and development teams (including Fortune 500) - **Mission or purpose statement**: “Eliminating developer frustrations and security risks from the modern software development process” ([endorlabs.com/about](https://www.endorlabs.com/about)) ## Products & Services - **AURI (Agentic AI AppSec Platform)**: Combines agentic reasoning with deterministic program analysis to deliver verifiable, audit-ready security findings across AI-generated and human-written code. Integrates with AI coding agents via Hooks, Skills, MCP, or CLI. - **Secrets Detection**: Detects and validates exposed secrets in code. - **Malware Prevention**: Prevents malware from infiltrating the software supply chain. - **SCA Reachability**: Reachability-based analysis of direct and transitive open-source dependencies. - **Container Reachability**: Reachability-based scanning of container images. - **AI SAST**: AI-native detection, triage, and remediation of flaws in source code. - **AI Security Code Review**: Continuous AI-powered security reviews for pull requests. ## Market Standing - **Valuation/Market Cap**: Not disclosed (private company) - **Key Metric**: Annual revenue $55.0M (LinkedIn estimate); total funding $188.0M across 4 rounds (Series A $70M in 2024, Series B $93M in 2025) - **Notable Investors/Partners**: DFJ Growth, Lightspeed Venture Partners, Coatue, Dell Technologies Capital, and over 40 industry leading operators and executives - **Growth Signals**: Fastest-growing AppSec company ever (per company); headcount 162 (+32.2% YoY); operates in 10 countries; launched agentic AI platform for the “vibe coding” era; expanded from reachability-based SCA to a full AppSec platform in 2024 ## Competitive Advantages - **Reachability & exploitability analysis** cuts through noise by showing only vulnerabilities that actually affect the codebase. - **Deterministic program analysis + agentic reasoning** provides verifiable, reproducible findings with audit-ready evidence. - **Full-stack reachability** across source code, open-source dependencies, containers, and secrets. - **Integrated but independent security layer** for AI coding agents – enforces policy-as-code across all agents without blocking developer velocity. ## Strategic Focus - Leading security for the “vibe coding” era where most code will be AI-generated. - Continuing to expand the platform beyond software composition analysis into full application security (SAST, secrets, container, malware). - Deepening integrations with AI coding assistants (via Hooks, Skills, MCP, CLI) to embed security without friction. ## Why Work Here - **Culture**: Values include “Be Human,” “Have Fun,” “Own It,” “Think Big, Start Small, Learn Fast.” Described as “smart, funny, nerds.” Global annual offsites, company-wide events, hackathons, and departmental team-buildings. - **Remote/Hybrid/Office**: Globally distributed team with flexibility to work from anywhere. Home office equipment stipend and cell phone/internet reimbursement. Offices in Palo Alto (HQ), Delft (Netherlands), and Bengaluru (India). - **Notable perks**: Competitive medical, dental, vision; Flexible Spending Account and Health Savings Account; 401k; parental leave; flexible PTO; diverse holiday observance; life insurance. - **Engineering culture**: Deep investment in AI, ML, and static analysis research – founders and team hail from Amazon, Cisco, Meta, GitHub, Microsoft, Palo Alto Networks, Splunk, Uber. Research regularly appears in top venues (ICSE, ASE, IEEE TSE). ## Sources 1. [endorlabs.com](https://www.endorlabs.com/) 2. [Endor Labs About Page](https://www.endorlabs.com/about) 3. [Endor Labs Careers](https://www.endorlabs.com/careers) 4. [LinkedIn Company Profile](https://www.linkedin.com/company/endorlabs) 5. [Greenhouse Job Board](http://job-boards.greenhouse.io/endorlabs) ## Other roles at Endor Labs - [Staff Backend Software Engineer](https://feeny.ai/job/staff-backend-software-engineer-endor-labs-palo-alto-50bpr9hbs49v) — Palo Alto, CA - [Enterprise Account Executive - TOLA](https://feeny.ai/job/enterprise-account-executive-tola-endor-labs-texas-q0qq77r54fh0) — Texas - [Senior Quality Engineer(SDET)](https://feeny.ai/job/senior-quality-engineer-sdet-endor-labs-bengaluru-91fbs97mgvjf) — Bengaluru, India - [IT Engineer](https://feeny.ai/job/it-engineer-endor-labs-bengaluru-dv9gxwkbwkyk) — Bengaluru, India - [Senior Technical Recruiter](https://feeny.ai/job/senior-technical-recruiter-endor-labs-united-states-hahpv5rzt5vp) — United States - [Technical Success Engineer](https://feeny.ai/job/technical-success-engineer-endor-labs-panama-vfh564wgz10y) — Panama - [Senior Product Security Engineer](https://feeny.ai/job/senior-product-security-engineer-endor-labs-bengaluru-neqdd04t1r6g) — Bengaluru, India - [Technical Success Architect](https://feeny.ai/job/technical-success-architect-endor-labs-united-states-h898w7etqxe2) — United States - [Solutions Architect - East](https://feeny.ai/job/solutions-architect-east-endor-labs-united-states-rv3f5sav9t7j) — United States - [Enterprise Account Executive - Southeast](https://feeny.ai/job/enterprise-account-executive-southeast-endor-labs-atlanta-p45p79ky5dq3) — Atlanta, GA