远程工作雷达

高级漏洞开发工程师(美国)

Sr. Exploit Developer (US)

开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差
公司VulnCheck
薪资未公开
工作地点United States
地域资格限定地区(需当地身份)
时区要求与中国几乎无重叠,需长期倒时差
用工类型permanent
发布时间2026-05-09
数据来源4dayweek.io
前往 4dayweek.io 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:与中国几乎无重叠,需长期倒时差。

**关于VulnCheck**

漏洞防御的强度取决于驱动这些努力的情报,而大多数行业仍在使用缺乏利用上下文的情报。VulnCheck,一家专注于利用情报的公司,提供结构化的利用情报,展示当前野外被武器化的攻击,专为您的基础设施已运行的数据湖、ETL流水线、自动化以及AI和LLM工作流而设计,提升其支持的一切能力。

**职位描述**

VulnCheck正在寻找一位具有逆向工程和利用开发背景的高级利用开发者。该职位属于我们的初始访问情报团队,负责交付利用及相关成果,帮助VulnCheck客户从暴露到执行和检测的整个过程中获得对利用的可见性。您将与经验丰富的黑客和威胁研究人员团队合作,帮助全球企业、政府和情报机构防范新兴威胁,走在攻击者前面。

虽然初始访问漏洞是我们的主要关注领域,您还将有机会参与各种本地和其他利用,以及我们的开源 [go-exploit](https://github.com/vulncheck-oss/go-exploit) 框架。_**尽管这是一个100%远程的工作,但我们优先考虑位于马萨诸塞州、马里兰州或德克萨斯州奥斯汀的候选人。**_

**为什么加入VulnCheck?**

VulnCheck致力于影响全球组织对安全漏洞的理解、评估和修复方式,并提供基于情报的解决方案来改变世界。

您将加入一个协作、支持的环境,重视求知欲、技术精湛和个人成长。(更多内容如下)

- 发挥您的专长:与该领域的顶级专家一起,参与具有重要意义的前沿威胁情报项目。
- 影响行业:在企业客户和整个网络安全行业中,影响漏洞的分类、评分、映射和修复方式。
- 扩大影响力:与全球合作伙伴合作,领导高可见度的项目,并推动安全社区的标准。
- 创新与探索:进行研究并开发工具,用于自动化和改进漏洞丰富和映射。

**您将负责**

- 对软件进行逆向工程,以发现漏洞的根本原因分析(RCA)

查看英文原文

**About VulnCheck**

Exploitation prevention is only as strong as the intelligence driving those efforts, and most of the industry is still running on intelligence that lacks exploit context. VulnCheck, The Exploit Intelligence Company, delivers structured exploit intelligence on what is actively weaponized in the wild, purpose-built for the data lakes, ETL pipelines, automation, and AI and LLM workflows your infrastructure already runs on, raising the capability of everything it powers.

**About the Role**

VulnCheck is looking for a Senior Exploit Developer with a background in reverse engineering and exploit development. This role is on our Initial Access Intelligence team, which delivers exploits and related artifacts designed to give VulnCheck customers visibility into exploitation from exposure through execution and detection. You’ll work with a seasoned team of hackers and threat researchers to help global enterprises, governments, and intelligence firms defend against emerging threats and get ahead of the attacker curve.

While initial access vulnerabilities are our main focus area, you’ll also have the opportunity to work on a variety of local and other exploits, as well as our open-source [go-exploit](https://github.com/vulncheck-oss/go-exploit) framework. _**Although this is a 100% remote role, we will prioritize candidates based in one of our U.S. hubs in Massachusetts, Maryland, or Austin, TX.**_

**Why Join VulnCheck?**

VulnCheck stands behind its mission to influence how organizations worldwide understand, assess, and remediate security vulnerabilities - and to deliver intelligence-based solutions that change the world.

You’ll be joining a collaborative, supportive environment that values intellectual curiosity, technical mastery, and personal growth. (And more - below)

- Leverage your expertise: Work on cutting-edge threat intelligence initiatives that matter, alongside the top domain experts in the field.
- Shape the industry: Influence how vulnerabilities are classified, scored, mapped, and remediated at scale for enterprise customers and for the entire cybersecurity industry.
- Grow your impact: Collaborate with global partners, lead high-visibility projects, and drive standards across the security community.
- Innovate and explore: Conduct research and develop tools for automating and improving vulnerability enrichment and mapping.

**What You'll Do**

- Reverse engineering software to discover the root cause analysis (RCA) of vulnerabilities.
- Authoring original software exploits for initial access vulnerabilities, when little or no publicly-available proof of concept code for exploiting such vulnerabilities exists.
- Implementing detections (such as Suricata & Snort signatures, YARA rules, etc.) for identifying such initial access vulnerabilities being exploited on the wire
- Writing Attack Surface Management (ASM) queries (e.g., Shodan, Census, FOFA, & ZoomEye) for finding vulnerable systems likely to be targeted

**Why You'll Bring**

- Prior experience with writing exploit code for RCE / initial access vulnerabilities (that do not require authentication to exploit)
- Experience working on technical projects remotely, alone, and on small teams

**Preferred Qualifications**

- Prior Cybersecurity work experience (at a vendor or in Government).
- Able to share example exploit code written.

***IMPORTANT NOTE:** This position may involve access to technology subject to U.S. export control regulations. Employment is contingent upon the company's ability to authorize access under applicable export control, sanctions, and any other applicable legal or contractual requirements. The company does not guarantee and is under no obligation to seek such authorization if it would be necessary.

### **What We Offer**

We believe people do their best work when they feel supported, trusted, and valued. VulnCheck offers benefits designed to meet a wide range of needs and lifestyles:

#### **Benefits and Perks**

- Unlimited PTO
- 401k plan with company match
- Comprehensive healthcare coverage
- Generous paid parental leave
- Remote friendly environment with flexibility
- Expense reimbursement for Cell Phone & Internet
- Ongoing professional development, coaching, and learning resources
- Opportunities for career advancement within a fast-growing team

#### **Why Join Us**

Built on over two decades of cybersecurity experience, our team of experts understands the intricacies of vulnerabilities, their exploitation in the wild, and how to leverage this data to build more effective cybersecurity products that produce better outcomes for organizations.

VulnCheck gives organizations a tactical advantage by providing best-in-class exploit & vulnerability intelligence information. We have a sense of duty to protect the critical infrastructure we rely on including medical devices, power grids and telecommunication networks. We were founded in 2021 in Lexington, Massachusetts.

VulnCheck has a transparent, collaborative, and supportive culture - we are looking for people who have a growth mindset, are curious and innovative. Our team is smart, but humble, hardworking, and supportive.

VulnCheck is proud to be an Equal Employer Opportunity employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. VulnCheck is committed to working with and providing reasonable accommodations to applicants with physical and mental disabilities. *Even if your experience doesn’t perfectly align with the job description, we encourage you to apply—we value potential just as much as a perfect resume.

本页面信息整理自 4dayweek.io,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

销售赋能经理

VulnCheckUnited Statespermanent今天
市场运营限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

高级漏洞研究员(美国)

VulnCheckUnited Statespermanent7 天前
开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

销售工程师

VulnCheckIsraelpermanent2026-08-04
开发工程市场运营限定地区(需当地身份)

销售总监

VulnCheckIsraelpermanent2026-08-04
市场运营限定地区(需当地身份)

← 返回全部职位