Vulncheck
Senior Vulnerability Analyst
NEWJob Description
[AI-summarized by JobStash]
You will analyze and map discovered vulnerabilities to MITRE ATT&CK techniques and CAPEC attack patterns with precision and consistency. You will determine and assign accurate CWE IDs with well-documented rationales, and authoritatively calculate CVSS v3/v4 base scores with transparent, defensible justifications. You will review, draft, and curate CVE Records, ensuring data quality and consistency with CVE Program standards. You will liaise with vulnerability researchers, product security teams, and standards communities to ensure best practices and knowledge transfer. You will develop and refine workflows and playbooks for vulnerability triage, mapping, and reporting, and you will share your expertise by mentoring junior analysts and driving team knowledge-sharing initiatives.
Requirements
- āProven experience with the CVE Program as an analyst, CNA, or significant contributor
- āExpert knowledge of MITRE ATT&CK, CAPEC, and CWE with experience mapping vulnerabilities to these frameworks
- āAdvanced understanding of CVSS v3 and v4 including real-world vulnerability scoring and risk communication
- āStrong analytical, technical, and research skills
- āExceptional written and verbal communication skills
- āExperience engaging with community initiatives, standards bodies, or open-source projects in vulnerability or threat intelligence is highly desirable
- āExperience contributing to vulnerability standards such as CVE Editorial Boards or CAPEC Working Groups is preferred
- āFamiliarity with automation tools or programming languages such as Python or Golang is preferred
- āPublished research, whitepapers, or presentations in vulnerability analysis or threat intelligence is preferred
Responsibilities
- āAnalyze and map discovered vulnerabilities to MITRE ATT&CK techniques and CAPEC attack patterns
- āDetermine and assign accurate CWE IDs with well-documented rationales
- āCalculate CVSS v3/v4 base scores with transparent, defensible justifications
- āReview, draft, and curate CVE Records ensuring data quality and consistency with CVE Program standards
- āLiaise with vulnerability researchers, product security teams, and standards communities
- āDevelop and refine workflows and playbooks for vulnerability triage, mapping, and reporting
- āMentor junior analysts and drive team knowledge-sharing initiatives
Benefits & Perks
- āUnlimited PTO
- ā401k plan with company match
- āComprehensive healthcare coverage
- āGenerous paid parental leave
- āRemote friendly environment with flexibility
- āExpense reimbursement for cell phone and internet
- āOngoing professional development, coaching, and learning resources