Skip to main content
NEUN
Back to Careers

Vulncheck

Senior Vulnerability Analyst

NEW
MA / Austin TX / MDFull-timeGlobal
šŸ“Š MidšŸ  Remote
ActivePosted within the last 30 days

Job Description

[AI-summarized by JobStash]

You will analyze and map discovered vulnerabilities to MITRE ATT&CK techniques and CAPEC attack patterns with precision and consistency. You will determine and assign accurate CWE IDs with well-documented rationales, and authoritatively calculate CVSS v3/v4 base scores with transparent, defensible justifications. You will review, draft, and curate CVE Records, ensuring data quality and consistency with CVE Program standards. You will liaise with vulnerability researchers, product security teams, and standards communities to ensure best practices and knowledge transfer. You will develop and refine workflows and playbooks for vulnerability triage, mapping, and reporting, and you will share your expertise by mentoring junior analysts and driving team knowledge-sharing initiatives.

Requirements

  • ā—Proven experience with the CVE Program as an analyst, CNA, or significant contributor
  • ā—Expert knowledge of MITRE ATT&CK, CAPEC, and CWE with experience mapping vulnerabilities to these frameworks
  • ā—Advanced understanding of CVSS v3 and v4 including real-world vulnerability scoring and risk communication
  • ā—Strong analytical, technical, and research skills
  • ā—Exceptional written and verbal communication skills
  • ā—Experience engaging with community initiatives, standards bodies, or open-source projects in vulnerability or threat intelligence is highly desirable
  • ā—Experience contributing to vulnerability standards such as CVE Editorial Boards or CAPEC Working Groups is preferred
  • ā—Familiarity with automation tools or programming languages such as Python or Golang is preferred
  • ā—Published research, whitepapers, or presentations in vulnerability analysis or threat intelligence is preferred

Responsibilities

  • ā—Analyze and map discovered vulnerabilities to MITRE ATT&CK techniques and CAPEC attack patterns
  • ā—Determine and assign accurate CWE IDs with well-documented rationales
  • ā—Calculate CVSS v3/v4 base scores with transparent, defensible justifications
  • ā—Review, draft, and curate CVE Records ensuring data quality and consistency with CVE Program standards
  • ā—Liaise with vulnerability researchers, product security teams, and standards communities
  • ā—Develop and refine workflows and playbooks for vulnerability triage, mapping, and reporting
  • ā—Mentor junior analysts and drive team knowledge-sharing initiatives

Benefits & Perks

  • ā—Unlimited PTO
  • ā—401k plan with company match
  • ā—Comprehensive healthcare coverage
  • ā—Generous paid parental leave
  • ā—Remote friendly environment with flexibility
  • ā—Expense reimbursement for cell phone and internet
  • ā—Ongoing professional development, coaching, and learning resources

Tech Stack

automationCAPECCVECVSSCWEGolangmentoringMITRE ATT&CKPythonproject:Ten Eleven Ventures
Expired
Search