Skip to main content
VulnCheck

Senior Vulnerability Analyst

RemoteUnited States only
Published
Role
Security
Experience
Senior
Employment
Full-time
Company size
Startup
Salary not disclosed
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior vulnerability analyst for a US remote role, preferably in Massachusetts, Maryland, or Greater Austin, TX. Needs hands-on CVE Program experience and expert MITRE ATT&CK, CAPEC, CWE, and CVSS v3/v4 knowledge. Vulnerability management, threat intelligence, standards/community experience, and strong technical writing are central.

Core skills

CVEMITRE ATT&CKCVSS

Required skills

CAPECCWECVSS v3CVSS v4

Optional skills

PythonGo

What you'll do

  • Map vulnerabilities: Analyze and map discovered vulnerabilities to MITRE ATT&CK techniques and CAPEC attack patterns with precision and consistency.
  • CWE assignment: Determine and assign accurate CWE (Common Weakness Enumeration) IDs, producing well-documented rationales.
  • CVSS calculation: Authoritatively calculate CVSS v3/v4 base scores, providing transparent, defensible justifications.
  • CVE Processing: Review, draft, and curate CVE Records, ensuring data quality, fidelity, and consistency with CVE Program standards.
  • Collaboration: Liaise with vulnerability researchers, product security teams, and standards communities to ensure best practices and knowledge transfer.
  • Process improvement: Develop and refine workflows and playbooks for vulnerability triage, mapping, and reporting.
  • Mentorship: Share your expertise by mentoring junior analysts and driving team knowledge-sharing initiatives.

What they require

  • Proven experience with the CVE Program—either as an analyst, CNA, or significant contributor in a major software or security organization.
  • Expert knowledge of MITRE ATT&CK, CAPEC, CWE, and working experience mapping vulnerabilities to these frameworks.
  • Advanced understanding of CVSS (v3 and v4), including real-world application to vulnerability scoring and risk communication.
  • Strong analytical, technical, and research skills, with a passion for data quality and process rigor.
  • Exceptional written and verbal communication skills—including the ability to translate complex technical details for diverse audiences.
  • Preferred: Experience engaging with community initiatives, standards bodies, or open-source projects in the vulnerability or threat intelligence space is highly desirable.
  • Preferred: Experience contributing to the evolution of vulnerability standards (e.g., participation in CVE Editorial Boards, CAPEC Working Groups, or similar).
  • Preferred: Published research, whitepapers, or presentations in the field of vulnerability analysis, mapping, or threat intelligence.
  • This position may involve access to technology subject to U.S. export control regulations.
  • Employment is contingent upon the company's ability to authorize access under applicable export control, sanctions, and any other applicable legal or contractual requirements.

Benefits

  • Unlimited PTO
  • 401k plan with company match
  • Comprehensive healthcare coverage
  • Generous paid parental leave
  • Remote friendly environment with flexibility
  • Expense reimbursement for Cell Phone & Internet
  • Ongoing professional development, coaching, and learning resources
  • Opportunities for career advancement within a fast-growing team

American cybersecurity company specializing in exploit intelligence and vulnerability intelligence

🇺🇸 United StatesCybersecurityStartupvulncheck.com/

Details

Apply routeGreenhouse
Salary not disclosed