Jobs · Information Technology

Vulnerability & Threat Analyst (US)

VulnCheck · Austin, TX · 1 mo ago
RemoteRemoteInformation TechnologyFull-time

About the role

Analyze diverse threat intelligence sources to identify and confirm:

  • Exploited vulnerabilities (KEVs)
  • Exploits and proof-of-concepts (PoCs)
  • Threat actors, Botnets and Ransomware campaigns
  • Malicious hosts, domains and infrastructure
  • Indicators of compromise (IOCs)

Validate the accuracy and credibility of sources and findings
Assess evidence of real-world exploitation
Maintain structured, high-quality intelligence outputs

Responsibilities

Analyze diverse threat intelligence sources to identify and confirm:

  • Exploited vulnerabilities (KEVs)
  • Exploits and proof-of-concepts (PoCs)
  • Threat actors, Botnets and Ransomware campaigns
  • Malicious hosts, domains and infrastructure
  • Indicators of compromise (IOCs)

Validate the accuracy and credibility of sources and findings
Assess evidence of real-world exploitation
Maintain structured, high-quality intelligence outputs

Requirements

  • Ability to evaluate exploit PoCs; familiarity with scripting languages
  • Experience with OSINT tools and resources
  • Understanding of IOCs and how to identify them
  • Strong understanding of CVEs, including: CVE assignment and validation, Familiarity with CPE and scoring methodologies
  • Experience working with structured data formats (e.g., JSON)
  • High attention to detail and analytical rigor
  • Familiarity with end-of-life (EOL) software data
  • Experience with developer/security tooling (e.g., VS Code and extensions)
  • Familiarity with package ecosystems (NPM, NuGet, PyPI)

Qualifications

  • Python scripting skills preferred
  • Experience with prompt engineering is a plus

Skills

  • Ability to evaluate exploit PoCs; familiarity with scripting languages
  • Experience with OSINT tools and resources
  • Understanding of IOCs and how to identify them
  • Strong understanding of CVEs, including: CVE assignment and validation, Familiarity with CPE and scoring methodologies
  • Experience working with structured data formats (e.g., JSON)
  • High attention to detail and analytical rigor
  • Familiarity with end-of-life (EOL) software data
  • Experience with developer/security tooling (e.g., VS Code and extensions)
  • Familiarity with package ecosystems (NPM, NuGet, PyPI)

Benefits

We offer:

  • Unlimited PTO
  • 401k plan with company match
  • Comprehensive healthcare coverage
  • Grossly paid parental leave
  • Remote friendly environment with flexibility
  • Expense reimbursement for Cell Phone & Internet
  • Ongoing professional development, coaching, and learning resources
  • Opportunities for career advancement within a fast-growing team

Pay

Salary range: $80,000 - $120,000 per year

Schedule

Full-time, remote position

Similar jobs

Vulnerability Analyst

Edgewater Federal Solutions, Inc.Bethesda, MD· 3 wk ago
Business Development$70k–$90k/yrapply on careers-edgewaterit.icims.com

Vulnerability Analyst

Y-12 National Security ComplexOak Ridge, TN· 4 wk ago
Salesapply on career-hcm03.ns2cloud.com