Citi
Threat & Exposure Management Platform Engineer
Irving Texas United States
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →hirly's read of this role
- Role family
- Engineering
- Seniority
- Mid level
- Country
- US
- Work mode
- On-site / unstated
- First seen by hirly
- 30 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
We are looking for a highly experienced Threat & Exposure Management Platform Engineer to design, build, and operate the data platform and architecture that unifies threat, vulnerability, and exposure signal across the enterprise. This is a foundational, high-impact platform engineering role at the core of our organization's evolution toward a next-generation, AI-enabled security operations capability.
You will own the architecture connecting security tooling, threat intelligence, vulnerability data, and adversary validation results into a single, continuously updated substrate — enabling faster, more accurate, and increasingly automated risk prioritization and response across the business.
This role calls for someone with deep platform engineering expertise and strong architectural judgment , comfortable owning complex, mission-critical systems end-to-end rather than working on isolated components.
Key Responsibilities
- Data Pipeline Engineering: Design, build, and operate scalable, resilient data pipelines that ingest, normalize, and enrich threat and exposure signals from a wide range of security, IT, and cloud platforms (e.g., vulnerability scanners, EDR/XDR, CSPM, CMDB, threat intelligence feeds, identity systems).
- Platform Integration: Develop and maintain robust API integrations connecting security tooling, data lakes, and correlation/analytics engines to create a single, unified view of the organization's threat and exposure posture.
- Correlation Engine Development: Architect and implement correlation logic and data models that link vulnerabilities, threats, assets, and business context to support automated, evidence-based risk prioritization.
- Data Substrate & Architecture Ownership: Build and evolve the underlying data substrate (schemas, storage layers, streaming infrastructure) that serves as the authoritative source of truth for enterprise risk and exposure data, and own its long-term architectural direction.
- API & Interface Development: Expose clean, well-documented, secure APIs enabling downstream systems, dashboards, and analyst tooling to consume unified threat and exposure data programmatically.
- Continuous Exposure Lifecycle Support: Build and operate the platform capabilities that support an ongoing, iterative approach to discovering, prioritizing, and validating exposures across the environment — from initial scoping through to remediation tracking.
- Adversary-Informed Validation Integration: Integrate outputs from adversary emulation, control validation, and simulation exercises into the correlation engine, enriching risk prioritization with real-world evidence of exploitability and defensive effectiveness.
- Coverage & Gap Analysis: Architect data models and pipelines that continuously assess defensive coverage against real-world attack techniques, surfacing prioritized gaps for remediation.
- Operational Reliability: Own the uptime, performance, scalability, and data quality of production pipelines and integrations; implement monitoring, alerting, and self-healing mechanisms.
- Cross-Platform Normalization: Establish common taxonomies and data standards to reconcile inconsistent data formats, severity scoring, and asset identifiers across heterogeneous security tools.
- Cross-Functional Collaboration: Partner with security operations, threat intelligence, detection engineering, red/purple team, and data science functions to ensure platform outputs meet operational and analytical needs.
- Security & Compliance: Ensure all data handling, storage, and access adhere to enterprise security, privacy, and regulatory requirements, given the sensitivity of threat and exposure data.
- Automation & Scale: Drive automation of data onboarding for new tools and platforms to reduce integration lead time as the environment and tool ecosystem grow.
- Documentation & Knowledge Transfer: Maintain architecture diagrams, runbooks, and integration documentation to support platform sustainability and team scaling.
Required Skills & Experience
- Strong architecture skills — demonstrated ability to design end-to-end platform architectures spanning data ingestion, correlation, validation, and delivery layers, with sound judgment on scalability, extensibility, and long-term maintainability.
- Deep platform engineering expertise — a proven track record owning and operating complex, production-grade security data platforms end-to-end.
- Hands-on experience building large-scale data pipelines (batch and streaming) using tools such as Kafka, Spark, Airflow, Flink, or equivalent.
- Strong expertise in API design and development (REST/GraphQL), including authentication, rate limiting, and versioning for high-throughput data.
- Proven experience integrating heterogeneous security platforms (vulnerability management, EDR/XDR, CSPM, SIEM, CMDB, threat intelligence platforms, simulation/emulation tooling).
- Strong background in data modeling and correlation engine design — able to reconcile asset, vulnerability, threat, and adversary-behavior data into unified risk views.
- Practical understanding of how to operationalize an ongoing exposure discovery, prioritization, and validation process within a technical platform.
- Familiarity with mapping known attacker techniques and behaviors to defensive controls and detection coverage.
- Familiarity with simulation or emulation-based control validation approaches and how their outputs feed into broader risk models.
- Proficiency in at least one major programming language (Python, Go, or Java) for pipeline and integration development.
- Experience with cloud-native data infrastructure (AWS/Azure/GCP), including data lakes, warehouses, and event-driven architectures.
- Solid understanding of core cybersecurity concepts: vulnerability management, threat intelligence, exposure management, attack surface management, and risk scoring frameworks (e.g., CVSS, EPSS).
- Experience with database technologies spanning relational, NoSQL, graph, and time-series stores for correlation and attack-path use cases.
- Strong software engineering fundamentals: CI/CD, infrastructure-as-code, version control, testing, and observability practices.
- Excellent cross-functional collaboration skills, able to work with security operations, detection engineering, and platform architecture teams in a fast-paced, mission-critical environment.
Preferred Qualifications
- 10+ yrs of experience leading a continuous exposure management program or initiative end-to-end, from architecture through operational rollout.
- Familiarity with graph-based attack path analysis or asset/risk graphs.
- Hands-on experience with adversary simulation or emulation frameworks and purple-team tooling.
- Experience supporting AI/ML-driven security operations or automation-first security initiatives.
- Relevant certifications (e.g., GIAC, cloud security or data certifications) are a plus but not required in lieu of hands-on expertise.
What We're Looking For
A builder who thrives on architecting and operating complex, high-stakes data platforms — someone equally comfortable in deep technical design discussions and hands-on implementation, who wants to shape the data foundation behind the next generation of automated, intelligence-driven security operations.
Education:
- Bachelor’s degree/University degree or equivalent experience
- Master’s degree preferred
This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required.
------------------------------------------------------
Job Family Group:
Technology ------------------------------------------------------
Job Family:
Information Security ------------------------------------------------------
Time Type:
Full time ------------------------------------------------------
Primary Location:
Irving Texas United States ------------------------------------------------------
Primary Location Full Time Salary Range:
$156,160.0
Similar jobs
- Systems & Platform Engineer - TS/SCI Sunayu · Bethesda, MarylandFirst seen today
- Platform EngineerBah · McLean, VAFirst seen today
- Salesforce Platform Engineer, MidBah · McLean, VAFirst seen today
- Platform EngineerNetdocuments · Lehi, Utah, United StatesFirst seen today
- Platform Engineer (Hybrid) Clearance RequiredPhoenix Operations Group · San Antonio, TXFirst seen today
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job