高级漏洞开发工程师
Sr. Exploit Developer
**关于VulnCheck**
防御漏洞的强度取决于驱动这些努力的情报,而大多数行业仍在使用缺乏漏洞利用上下文的情报。VulnCheck,一家漏洞利用情报公司,提供结构化的漏洞利用情报,展示当前在野外被武器化的内容,专为您的基础设施已运行的数据湖、ETL流水线、自动化和AI及LLM工作流而设计,提升其所支持的一切能力。
**职位描述**
VulnCheck正在寻找一位具有逆向工程和漏洞开发背景的高级漏洞开发人员。该职位属于我们的初始访问情报团队,该团队提供漏洞利用及相关成果,帮助VulnCheck客户从暴露到执行和检测的整个过程中获得对漏洞利用的可见性。您将与经验丰富的黑客和威胁研究人员团队合作,帮助全球企业、政府和情报机构防范新兴威胁,走在攻击者前面。
虽然初始访问漏洞是我们的主要关注领域,您还将有机会参与各种本地和其他漏洞的开发,以及我们的开源 [go-exploit](https://github.com/vulncheck-oss/go-exploit) 框架。这是一个 **100% 远程** 的职位,但我们主要寻找位于英国切尔滕纳姆的候选人。
**为什么加入VulnCheck?**
VulnCheck致力于影响全球组织如何理解、评估和修复安全漏洞,并提供基于情报的解决方案来改变世界。
您将加入一个协作、支持的工作环境,重视求知欲、技术专长和个人成长。(更多内容请看下方)
- 发挥您的专业知识:与该领域的顶级专家一起,参与具有重要意义的前沿威胁情报项目。
- 影响行业:在企业客户和整个网络安全行业中,影响漏洞的分类、评分、映射和修复方式。
- 扩大影响力:与全球合作伙伴合作,领导高可见度项目,并推动安全社区的标准。
- 创新与探索:进行研究并开发工具,用于自动化和改进漏洞丰富和映射。
**您将负责**
- 对软件进行逆向工程,以发现漏洞的根本原因分析(RCA)。
- 编写原创软件
查看英文原文
**About VulnCheck**
Exploitation prevention is only as strong as the intelligence driving those efforts, and most of the industry is still running on intelligence that lacks exploit context. VulnCheck, The Exploit Intelligence Company, delivers structured exploit intelligence on what is actively weaponized in the wild, purpose-built for the data lakes, ETL pipelines, automation, and AI and LLM workflows your infrastructure already runs on, raising the capability of everything it powers.
**About the Role**
VulnCheck is looking for a Senior Exploit Developer with a background in reverse engineering and exploit development. This role is on our Initial Access Intelligence team, which delivers exploits and related artifacts designed to give VulnCheck customers visibility into exploitation from exposure through execution and detection. You’ll work with a seasoned team of hackers and threat researchers to help global enterprises, governments, and intelligence firms defend against emerging threats and get ahead of the attacker curve.
While initial access vulnerabilities are our main focus area, you’ll also have the opportunity to work on a variety of local and other exploits, as well as our open-source [go-exploit](https://github.com/vulncheck-oss/go-exploit) framework. This is a **100% remote** role but we're primarily looking for candidates in Cheltenham, United Kingdom.
**Why Join VulnCheck?**
VulnCheck stands behind its mission to influence how organizations worldwide understand, assess, and remediate security vulnerabilities - and to deliver intelligence-based solutions that change the world.
You’ll be joining a collaborative, supportive environment that values intellectual curiosity, technical mastery, and personal growth. (And more - below)
- Leverage your expertise: Work on cutting-edge threat intelligence initiatives that matter, alongside the top domain experts in the field.
- Shape the industry: Influence how vulnerabilities are classified, scored, mapped, and remediated at scale for enterprise customers and for the entire cybersecurity industry.
- Grow your impact: Collaborate with global partners, lead high-visibility projects, and drive standards across the security community.
- Innovate and explore: Conduct research and develop tools for automating and improving vulnerability enrichment and mapping.
**What You'll Do**
- Reverse engineering software to discover the root cause analysis (RCA) of vulnerabilities.
- Authoring original software exploits for initial access vulnerabilities, when little or no publicly-available proof of concept code for exploiting such vulnerabilities exists.
- Implementing detections (such as Suricata & Snort signatures, YARA rules, etc.) for identifying such initial access vulnerabilities being exploited on the wire
- Writing Attack Surface Management (ASM) queries (e.g., Shodan, Census, FOFA, & ZoomEye) for finding vulnerable systems likely to be targeted
**Why You'll Bring**
- Prior experience with writing exploit code for RCE / initial access vulnerabilities (that do not require authentication to exploit)
- Experience working on technical projects remotely, alone, and on small teams
**Preferred Qualifications**
- Prior Cybersecurity work experience (at a vendor or in Government).
- Able to share example exploit code written.
***IMPORTANT NOTE:** This position may involve access to technology subject to U.S. export control regulations. Employment is contingent upon the company's ability to authorize access under applicable export control, sanctions, and any other applicable legal or contractual requirements. The company does not guarantee and is under no obligation to seek such authorization if it would be necessary.
### **What We Offer**
We believe people do their best work when they feel supported, trusted, and valued. VulnCheck offers benefits designed to meet a wide range of needs and lifestyles.
#### **Benefits and Perks**
- Competitive salary with employee equity program
- Health, dental, and vision coverage
- Unlimited PTO
- Pension Contribution
- Remote friendly environment with flexibility
- Expense reimbursement for home internet and phone
- Ongoing professional development, coaching, and learning resources
- Opportunities for career advancement within a fast-growing team
#### **Why Join Us**
Built on over two decades of cybersecurity experience, our team of experts understands the intricacies of vulnerabilities, their exploitation in the wild, and how to leverage this data to build more effective cybersecurity products that produce better outcomes for organizations.
VulnCheck gives organizations a tactical advantage by providing best-in-class exploit & vulnerability intelligence information. We have a sense of duty to protect the critical infrastructure we rely on including medical devices, power grids and telecommunication networks. We were founded in 2021 in Lexington, Massachusetts.
VulnCheck has a transparent, collaborative, and supportive culture - we are looking for people who have a growth mindset, are curious and innovative. Our team is smart, but humble, hardworking, and supportive.
VulnCheck is proud to be an Equal Employer Opportunity employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. VulnCheck is committed to working with and providing reasonable accommodations to applicants with physical and mental disabilities.