VulnCheck logo
VulnCheck
Posted 74 days agoVerified live 2d ago

Vulnerability & Threat Analyst (US)

Brief overview

Remote
Exploit Proof-of-Concept (PoC) EvaluationScripting LanguagesOSINT ToolsIndicators of Compromise (IOCs) IdentificationCVE Assignment and ValidationCommon Platform Enumeration (CPE)Scoring Methodologies for VulnerabilitiesStructured Data Formats (JSON)Developer/Security Tooling VS CodeDeveloper/Security Tooling ExtensionsPackage Ecosystems NPMPackage Ecosystems NuGetPackage Ecosystems PyPIPython ScriptingAnalytical RigorCredibility Assessment

About the company

VulnCheck logo
VulnCheck

Provides vulnerability intelligence for security teams.

Job description

Summary

VulnCheck is a company that specializes in exploit intelligence, aimed at improving cybersecurity efforts. They are seeking a Vulnerability & Threat Intelligence Analyst to analyze threat intelligence data and validate exploited vulnerabilities, active exploits, and indicators of compromise.

Responsibilities

  • Analyze diverse threat intelligence sources to identify and confirm:
  • Exploited vulnerabilities (KEVs)
  • Exploits and proof-of-concepts (PoCs)
  • Threat actors, Botnets and Ransomware campaigns
  • Malicious hosts, domains and infrastructure
  • Indicators of compromise (IOCs)
  • Validate the accuracy and credibility of sources and findings
  • Assess evidence of real-world exploitation
  • Maintain structured, high-quality intelligence outputs

Skills

  • Ability to evaluate exploit PoCs; familiarity with scripting languages
  • Experience with OSINT tools and resources
  • Understanding of IOCs and how to identify them
  • Ability to assess the credibility and validity of intelligence sources
  • Strong understanding of CVEs, including:
  • CVE assignment and validation
  • Familiarity with CPE and scoring methodologies
  • Experience working with structured data formats (e.g., JSON)
  • High attention to detail and analytical rigor
  • Familiarity with end-of-life (EOL) software data
  • Experience with developer/security tooling (e.g., VS Code and extensions)
  • Familiarity with package ecosystems (NPM, NuGet, PyPI)
  • Python scripting skills preferred
  • Experience with prompt engineering is a plus

Qualifications

Must Haves

  • Ability to evaluate exploit PoCs; familiarity with scripting languages
  • Experience with OSINT tools and resources
  • Understanding of IOCs and how to identify them
  • Ability to assess the credibility and validity of intelligence sources
  • Strong understanding of CVEs, including:
  • CVE assignment and validation
  • Familiarity with CPE and scoring methodologies
  • Experience working with structured data formats (e.g., JSON)
  • High attention to detail and analytical rigor
  • Familiarity with end-of-life (EOL) software data
  • Experience with developer/security tooling (e.g., VS Code and extensions)
  • Familiarity with package ecosystems (NPM, NuGet, PyPI)

Nice to Haves

  • Python scripting skills preferred
  • Experience with prompt engineering is a plus

Benefits

  • Unlimited PTO
  • 401k plan with company match
  • Comprehensive healthcare coverage
  • Generous paid parental leave
  • Remote friendly environment with flexibility
  • Expense reimbursement for Cell Phone & Internet
  • Ongoing professional development, coaching, and learning resources
  • Opportunities for career advancement within a fast-growing team

More jobs like this