Threat & Exposure Management Platform Engineer

Citi•Irving, TX
•$156,160 - $234,240•Onsite

About The Position

We are looking for a highly experienced Threat & Exposure Management Platform Engineer to design, build, and operate the data platform and architecture that unifies threat, vulnerability, and exposure signal across the enterprise. This is a foundational, high-impact platform engineering role at the core of our organization's evolution toward a next-generation, AI-enabled security operations capability. You will own the architecture connecting security tooling, threat intelligence, vulnerability data, and adversary validation results into a single, continuously updated substrate — enabling faster, more accurate, and increasingly automated risk prioritization and response across the business. This role calls for someone with deep platform engineering expertise and strong architectural judgment, comfortable owning complex, mission-critical systems end-to-end rather than working on isolated components.

Requirements

  • Strong architecture skills — demonstrated ability to design end-to-end platform architectures spanning data ingestion, correlation, validation, and delivery layers, with sound judgment on scalability, extensibility, and long-term maintainability.
  • Deep platform engineering expertise — a proven track record owning and operating complex, production-grade security data platforms end-to-end.
  • Hands-on experience building large-scale data pipelines (batch and streaming) using tools such as Kafka, Spark, Airflow, Flink, or equivalent.
  • Strong expertise in API design and development (REST/GraphQL), including authentication, rate limiting, and versioning for high-throughput data.
  • Proven experience integrating heterogeneous security platforms (vulnerability management, EDR/XDR, CSPM, SIEM, CMDB, threat intelligence platforms, simulation/emulation tooling).
  • Strong background in data modeling and correlation engine design — able to reconcile asset, vulnerability, threat, and adversary-behavior data into unified risk views.
  • Practical understanding of how to operationalize an ongoing exposure discovery, prioritization, and validation process within a technical platform.
  • Familiarity with mapping known attacker techniques and behaviors to defensive controls and detection coverage.
  • Familiarity with simulation or emulation-based control validation approaches and how their outputs feed into broader risk models.
  • Proficiency in at least one major programming language (Python, Go, or Java) for pipeline and integration development.
  • Experience with cloud-native data infrastructure (AWS/Azure/GCP), including data lakes, warehouses, and event-driven architectures.
  • Solid understanding of core cybersecurity concepts: vulnerability management, threat intelligence, exposure management, attack surface management, and risk scoring frameworks (e.g., CVSS, EPSS).
  • Experience with database technologies spanning relational, NoSQL, graph, and time-series stores for correlation and attack-path use cases.
  • Strong software engineering fundamentals: CI/CD, infrastructure-as-code, version control, testing, and observability practices.
  • Excellent cross-functional collaboration skills, able to work with security operations, detection engineering, and platform architecture teams in a fast-paced, mission-critical environment.

Nice To Haves

  • 10+ yrs of experience leading a continuous exposure management program or initiative end-to-end, from architecture through operational rollout.
  • Familiarity with graph-based attack path analysis or asset/risk graphs.
  • Hands-on experience with adversary simulation or emulation frameworks and purple-team tooling.
  • Experience supporting AI/ML-driven security operations or automation-first security initiatives.
  • Relevant certifications (e.g., GIAC, cloud security or data certifications) are a plus but not required in lieu of hands-on expertise.

Responsibilities

  • Design, build, and operate scalable, resilient data pipelines that ingest, normalize, and enrich threat and exposure signals from a wide range of security, IT, and cloud platforms (e.g., vulnerability scanners, EDR/XDR, CSPM, CMDB, threat intelligence feeds, identity systems).
  • Develop and maintain robust API integrations connecting security tooling, data lakes, and correlation/analytics engines to create a single, unified view of the organization's threat and exposure posture.
  • Architect and implement correlation logic and data models that link vulnerabilities, threats, assets, and business context to support automated, evidence-based risk prioritization.
  • Build and evolve the underlying data substrate (schemas, storage layers, streaming infrastructure) that serves as the authoritative source of truth for enterprise risk and exposure data, and own its long-term architectural direction.
  • Expose clean, well-documented, secure APIs enabling downstream systems, dashboards, and analyst tooling to consume unified threat and exposure data programmatically.
  • Build and operate the platform capabilities that support an ongoing, iterative approach to discovering, prioritizing, and validating exposures across the environment — from initial scoping through to remediation tracking.
  • Integrate outputs from adversary emulation, control validation, and simulation exercises into the correlation engine, enriching risk prioritization with real-world evidence of exploitability and defensive effectiveness.
  • Architect data models and pipelines that continuously assess defensive coverage against real-world attack techniques, surfacing prioritized gaps for remediation.
  • Own the uptime, performance, scalability, and data quality of production pipelines and integrations; implement monitoring, alerting, and self-healing mechanisms.
  • Establish common taxonomies and data standards to reconcile inconsistent data formats, severity scoring, and asset identifiers across heterogeneous security tools.
  • Partner with security operations, threat intelligence, detection engineering, red/purple team, and data science functions to ensure platform outputs meet operational and analytical needs.
  • Ensure all data handling, storage, and access adhere to enterprise security, privacy, and regulatory requirements, given the sensitivity of threat and exposure data.
  • Drive automation of data onboarding for new tools and platforms to reduce integration lead time as the environment and tool ecosystem grow.
  • Maintain architecture diagrams, runbooks, and integration documentation to support platform sustainability and team scaling.

Benefits

  • medical, dental & vision coverage
  • 401(k)
  • life, accident, and disability insurance
  • wellness programs
  • paid time off packages, including planned time off (vacation), unplanned time off (sick leave), and paid holidays
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service