Remote job
Senior Vulnerability Analyst (US)
Job details
About this role
Role overview A senior vulnerability analyst role on a Threat Intelligence team, focused on the science of vulnerability analysis rather than exploit writing. The analyst will map findings to industry-standard frameworks, score them accurately, and curate high-quality CVE records. It is a fully remote position, with preference for candidates located in Massachusetts, Maryland, or the Greater Austin, Texas area.
Responsibilities - Map vulnerabilities to MITRE ATT&CK techniques and CAPEC attack patterns with consistent, precise methodology. - Determine and assign CWE identifiers, documenting clear rationales for each decision. - Calculate CVSS v3 and v4 base scores with transparent, defensible justifications. - Review, draft, and curate CVE Records to ensure data quality and alignment with CVE Program standards. - Liaise with vulnerability researchers, product security teams, and standards communities to share knowledge and best practices. - Develop and refine triage, mapping, and reporting playbooks, and mentor junior analysts.
Requirements - Proven hands-on experience with the CVE Program, whether as an analyst, CNA, or significant contributor within a major software or security organization. - Expert knowledge of MITRE ATT&CK, CAPEC, and CWE, with practical experience mapping vulnerabilities to these frameworks. - Advanced understanding of CVSS v3 and v4 and how to apply it to real-world scoring and risk communication. - Strong analytical and research skills paired with clear written and verbal communication, including the ability to translate complex technical material for varied audiences.
Nice to have - Engagement with community initiatives, standards bodies, or open-source projects in the vulnerability or threat intelligence space. - Experience contributing to the evolution of vulnerability standards (for example, CVE Editorial Boards or CAPEC Working Groups). - Familiarity with automation tools or scripting languages such as Python or Golang for data enrichment or workflow improvement. - Published research, whitepapers, or presentations in vulnerability analysis, mapping, or threat intelligence.
Benefits and work setup - Fully remote within the United States, with geographic preferences noted above. - Unlimited paid time off, generous paid parental leave, and comprehensive healthcare coverage. - 401(k) plan with company match and reimbursement for cell phone and internet expenses. - Ongoing professional development, coaching, and learning resources, plus advancement opportunities within a growing research organization. - Note: employment is contingent on the ability to authorize access under applicable U.S. export control regulations.