高级漏洞分析师 (美国)
Senior Vulnerability Analyst (US)
## 高级漏洞分析师
**地点:** MA / 奥斯汀 TX / MD
**团队:** 研究
**雇佣类型:** 全职,远程办公
### **关于 VulnCheck**
漏洞防范的强度取决于驱动这些努力的情报,而大多数行业仍在使用缺乏利用上下文的情报。VulnCheck,一家专注于漏洞情报的公司,提供结构化的利用情报,展示当前在野外被武器化的内容,专为您的基础设施已运行的数据湖、ETL流水线、自动化以及AI和LLM工作流而设计,提升其所支持的一切能力。
#### **关于该职位**
你是否热衷于推动漏洞分析和威胁情报科学的发展?你是否希望加入一个以使命为导向的团队,带来真实世界的影响,并拥有资源和技术文化来激发你的求知欲?
我们正在寻找一位高级漏洞分析师,具备对漏洞管理生态系统的深入理解,有CVE流程的实际经验,并精通MITRE ATT&CK、CAPEC、CWE和CVSS等标准框架。这是一个难得的机会,让你运用技能和经验,作为CVE及相关MITRE功能的贡献者或专家用户——同时将你的职业生涯推向漏洞研究的新高度。
我们正在扩大威胁情报团队,寻找一位注重细节的分析师加入VulnCheck。_这是一份100%远程的工作,优先考虑马萨诸塞州、马里兰州或奥斯汀大区的候选人。_
##### **你将负责**
- 漏洞映射:精确且一致地分析并映射发现的漏洞到MITRE ATT&CK技术及CAPEC攻击模式。
- CWE分配:确定并分配准确的CWE(通用弱点枚举)ID,生成详细的解释说明。
- CVSS计算:权威地计算CVSS v3/v4基础分数,提供透明且可辩护的依据。
- CVE处理:审查、起草和整理CVE记录,确保数据质量、准确性和与CVE计划标准的一致性。
- 协作:与漏洞研究人员、产品安全团队和标准社区进行沟通,确保最佳实践和知识共享。
- 流程改进:开发和优化漏洞分类、映射和报告的工作流程和操作手册。
- 指导:通过指导初级分析师分享你的专业知识,推动团队的知识积累。
查看英文原文
## Senior Vulnerability Analyst
**Location:** MA / Austin TX / MD
**Team:** Research
**Employment Type:** Full-Time, Remote
### **About VulnCheck**
Exploitation prevention is only as strong as the intelligence driving those efforts, and most of the industry is still running on intelligence that lacks exploit context. VulnCheck, The Exploit Intelligence Company, delivers structured exploit intelligence on what is actively weaponized in the wild, purpose-built for the data lakes, ETL pipelines, automation, and AI and LLM workflows your infrastructure already runs on, raising the capability of everything it powers.
#### **About the Role**
Are you passionate about advancing the science of vulnerability analysis and threat intelligence? Do you want to join a mission-driven team that delivers real-world impact—and has the resources and technical culture to fuel your curiosity?
We’re searching for a Senior Vulnerability Analyst with a deep understanding of the vulnerability management ecosystem, hands-on experience with the CVE process, and expert knowledge in standard frameworks like MITRE ATT&CK, CAPEC, CWE, and CVSS. This is a rare opportunity to leverage your skills and experience as a contributor to, or expert user of, CVE and related MITRE capabilities—while taking your career in vulnerability research to the next level.
We are expanding our Threat Intelligence team and are looking for a detail-oriented analyst to join VulnCheck. _This is a 100% remote role with preference for candidates located in Massachusetts, Maryland, OR Greater Austin TX._
##### **What You’ll Do**
- Map vulnerabilities: Analyze and map discovered vulnerabilities to MITRE ATT&CK techniques and CAPEC attack patterns with precision and consistency.
- CWE assignment: Determine and assign accurate CWE (Common Weakness Enumeration) IDs, producing well-documented rationales.
- CVSS calculation: Authoritatively calculate CVSS v3/v4 base scores, providing transparent, defensible justifications.
- CVE Processing: Review, draft, and curate CVE Records, ensuring data quality, fidelity, and consistency with CVE Program standards.
- Collaboration: Liaise with vulnerability researchers, product security teams, and standards communities to ensure best practices and knowledge transfer.
- Process improvement: Develop and refine workflows and playbooks for vulnerability triage, mapping, and reporting.
- Mentorship: Share your expertise by mentoring junior analysts and driving team knowledge-sharing initiatives.
##### **What You’ll Bring**
- Proven experience with the CVE Program—either as an analyst, CNA, or significant contributor in a major software or security organization.
- Expert knowledge of MITRE ATT&CK, CAPEC, CWE, and working experience mapping vulnerabilities to these frameworks.
- Advanced understanding of CVSS (v3 and v4), including real-world application to vulnerability scoring and risk communication.
- Strong analytical, technical, and research skills, with a passion for data quality and process rigor.
- Exceptional written and verbal communication skills—including the ability to translate complex technical details for diverse audiences.
- Experience engaging with community initiatives, standards bodies, or open-source projects in the vulnerability or threat intelligence space is highly desirable.
**Preferred Qualifications**
- Experience contributing to the evolution of vulnerability standards (e.g., participation in CVE Editorial Boards, CAPEC Working Groups, or similar).
- Familiarity with automation tools or programming/scripting languages (Python, Golang, etc.) for data enrichment or workflow improvement.
- Published research, whitepapers, or presentations in the field of vulnerability analysis, mapping, or threat intelligence.
**IMPORTANT NOTE:** This position may involve access to technology subject to U.S. export control regulations. Employment is contingent upon the company's ability to authorize access under applicable export control, sanctions, and any other applicable legal or contractual requirements. The company does not guarantee and is under no obligation to seek such authorization if it would be necessary.
### **What We Offer**
We believe people do their best work when they feel supported, trusted, and valued. VulnCheck offers benefits designed to meet a wide range of needs and lifestyles:
#### **Benefits and Perks**
- Unlimited PTO
- 401k plan with company match
- Comprehensive healthcare coverage
- Generous paid parental leave
- Remote friendly environment with flexibility
- Expense reimbursement for Cell Phone & Internet
- Ongoing professional development, coaching, and learning resources
- Opportunities for career advancement within a fast-growing team
#### **Why Join Us**
Built on over two decades of cybersecurity experience, our team of experts understands the intricacies of vulnerabilities, their exploitation in the wild, and how to leverage this data to build more effective cybersecurity products that produce better outcomes for organizations.
VulnCheck gives organizations a tactical advantage by providing best-in-class exploit & vulnerability intelligence information. We have a sense of duty to protect the critical infrastructure we rely on including medical devices, power grids and telecommunication networks. We were founded in 2021 in Lexington, Massachusetts.
VulnCheck has a transparent, collaborative, and supportive culture - we are looking for people who have a growth mindset, are curious and innovative. Our team is smart, but humble, hardworking, and supportive.
VulnCheck is proud to be an Equal Employer Opportunity employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. VulnCheck is committed to working with and providing reasonable accommodations to applicants with physical and mental disabilities. *Even if your experience doesn’t perfectly align with the job description, we encourage you to apply—we value potential just as much as a perfect resume.