VulnCheck logo

Senior Vulnerability Analyst

VulnCheck

Remote
Full-time
Senior
Salary not listedPosted 2mo ago

Real job — pulled straight from VulnCheck’s careers page · Verified July 23, 2026 · No reposts.

Job description

VulnCheck is hiring a Senior Vulnerability Analyst — a full-time, remote role. Apply directly on VulnCheck's careers page below.

Senior Vulnerability Analyst (US)

Location: MA / Austin TX / MD

Department: Research

Senior Vulnerability Analyst

Location: MA / Austin TX / MD
Team: Research
Employment Type: Full-Time, Remote

About VulnCheck

Exploitation prevention is only as strong as the intelligence driving those efforts, and most of the industry is still running on intelligence that lacks exploit context. VulnCheck, The Exploit Intelligence Company, delivers structured exploit intelligence on what is actively weaponized in the wild, purpose-built for the data lakes, ETL pipelines, automation, and AI and LLM workflows your infrastructure already runs on, raising the capability of everything it powers.

About the Role

The VulnCheck CNA (CVE Numbering Authority) processes thousands of vulnerability reports and issues thousands of CVEs a year, collaborating with community researchers, open-source projects, commercial software suppliers, the CVE community, and global security organizations to get vulnerabilities fixed and properly disclosed. 

We’re looking for a Senior Vulnerability Analyst with hands-on experience conducting coordinated vulnerability disclosure (CVD) and publishing CVEs to join VulnCheck’s CNA team. In this role, you’ll triage and validate vulnerability reports submitted to VulnCheck’s Report a Vulnerability service, coordinate disclosures across suppliers and researchers, and populate high-quality CVE and advisory data for global consumption. This is an opportunity to be part of a fast-growing CNA with a community-driven mission to get vulns fixed and make better vulnerability data accessible to everyone. 

This is a 100% remote role with preference for candidates located in Massachusetts, Maryland, OR Greater Austin TX.

What You’ll Do

  • Assess vulnerability reports submitted through VulnCheck’s Report a Vulnerability service for overall validity and CVE eligibility
  • Conduct vulnerability disclosure conversations with software suppliers, security researchers (vulnerability reporters), and standards communities, guiding all parties toward mutually beneficial outcomes
  • Where needed, follow CNA Operational Rules for submitting disputes or conducting escalations to get CVE records assigned and published appropriately (e.g., by following formal dispute processes)
  • Populate CVE metadata accurately, including calculating correct CVSS scores, assigning CWEs, and mapping discovered vulnerabilities to MITRE ATT&CK techniques and CAPEC attack patterns
  • Develop and refine workflows and playbooks for vulnerability triage, mapping, and reporting; track key metrics across CVD and CVE publication caseloadsg
  • Share your expertise and perspective on vulnerability disclosure with internal teams, VulnCheck customers, and the broader vulnerability research community

What You’ll Bring

  • 2+ years of coordinated vulnerability disclosure (CVD) experience at a PSIRT, government agency, researcher or bug bounty CNA, or other coordinating body in the vulnerability disclosure ecosystem
  • Prior experience writing, reviewing, and updating CVE records; familiarity with CVE record structure and tooling (e.g., CVE services, Vulnogram)
  • Prior experience analyzing unstructured vulnerability reports and product documentation to determine whether reported issues cross security boundaries and demonstrate sufficient impact to confidentiality, integrity, and availability
  • Prior experience reporting and coordinating vulnerability reports with third-party organizations, including commercial and open-source projects and products
  • Exceptionally strong written and verbal communication skills: You will use these every day to translate technical concepts to different audiences, often across different languages and levels of vulnerability disclosure understanding
  • Knowledge of MITRE ATT&CK, CAPEC, and CWE, and working experience mapping vulnerability reports to these frameworks
  • Advanced understanding of CVSS (v3 and v4), including real-world application to vulnerability scoring and risk communication
  • Strong analytical, technical, and research skills, with a passion for data quality and process rigor

Preferred Qualifications

  • Experience engaging with community initiatives, standards bodies, or open-source projects in the vulnerability or threat intelligence space
  • Familiarity with automation tools or programming/scripting languages (Python, Golang, etc.) for data enrichment or workflow improvement
  • Published research, whitepapers, or presentations in the field of vulnerability analysis, mapping, or threat intelligence

IMPORTANT NOTE: This position may involve access to technology subject to U.S. export control regulations. Employment is contingent upon the company's ability to authorize access under applicable export control, sanctions, and any other applicable legal or contractual requirements. The company does not guarantee and is under no obligation to seek such authorization if it would be necessary.

What We Offer

We believe people do their best work when they feel supported, trusted, and valued. VulnCheck offers benefits designed to meet a wide range of needs and lifestyles:

Benefits and Perks

  • Unlimited PTO
  • 401k plan with company match
  • Comprehensive healthcare coverage
  • Generous paid parental leave
  • Remote friendly environment with flexibility
  • Expense reimbursement for Cell Phone & Internet 
  • Ongoing professional development, coaching, and learning resources
  • Opportunities for career advancement within a fast-growing team

Why Join Us

Built on over two decades of cybersecurity experience, our team of experts understands the intricacies of vulnerabilities, their exploitation in the wild, and how to leverage this data to build more effective cybersecurity products that produce better outcomes for organizations.

VulnCheck gives organizations a tactical advantage by providing best-in-class exploit & vulnerability intelligence information. We have a sense of duty to protect the critical infrastructure we rely on including medical devices, power grids and telecommunication networks. We were founded in 2021 in Lexington, Massachusetts.

VulnCheck has a transparent, collaborative, and supportive culture - we are looking for people who have a growth mindset, are curious and innovative. Our team is smart, but humble, hardworking, and supportive.

VulnCheck is proud to be an Equal Employer Opportunity employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. VulnCheck is committed to working with and providing reasonable accommodations to applicants with physical and mental disabilities. *Even if your experience doesn’t perfectly align with the job description, we encourage you to apply—we value potential just as much as a perfect resume.

Get Senior Vulnerability Analyst jobs like this→

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
ABB logo

ABB

New

Infrastructure Monitoring Expert

Krakow, Lesser Poland
✓ From careers page· 22h ago
ABB logo

ABB

New

Research and Development Software Engineer

Bartlesville, OK
✓ From careers page· 22h ago
Saviynt logo

Senior SDET

Bengaluru
✓ From careers page· 22h ago
BPCS logo

BPCS

New

Principal Data Lead

$174k–$206kWashington, DC
✓ From careers page· 22h ago

Frequently asked questions

Is Senior Vulnerability Analyst at VulnCheck a remote job?

Yes, Senior Vulnerability Analyst at VulnCheck is a remote position. Candidates in Boston, MA, Austin, TX, Baltimore, MD may be preferred.

What skills are required for Senior Vulnerability Analyst at VulnCheck?

The required skills for Senior Vulnerability Analyst at VulnCheck include: Python, Go.

What is the seniority level for Senior Vulnerability Analyst at VulnCheck?

Senior Vulnerability Analyst at VulnCheck is a Senior level position.

How do I apply for Senior Vulnerability Analyst at VulnCheck?

You can view the full description and apply for Senior Vulnerability Analyst at VulnCheck on EchoJobs: https://echojobs.io/job/vulncheck-senior-vulnerability-analyst-us-tvi01.