Senior Vulnerability Analyst (US)

VulnCheck

$100K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in vulnerability management and analysis.
  • Hands-on experience with the CVE process as an analyst or contributor.
  • Expert understanding of MITRE ATT&CK, CAPEC, CWE, and CVSS frameworks.
  • Strong analytical and technical skills focused on data quality and process rigor.
  • Excellent communication skills for translating technical details for various audiences.
  • Experience with community initiatives in vulnerability or threat intelligence.

Responsibilities

  • Map vulnerabilities to MITRE ATT&CK techniques and CAPEC patterns.
  • Assign and document CWE IDs accurately.
  • Calculate CVSS v3/v4 base scores with justifications.
  • Curate and draft CVE records maintaining data quality.
  • Collaborate with researchers and product security teams for knowledge transfer.
  • Develop workflows for vulnerability triage and reporting.
  • Mentor junior analysts and lead knowledge-sharing initiatives.

Benefits

  • Unlimited PTO
  • 401k plan with company match
  • Comprehensive healthcare coverage
  • Generous paid parental leave
  • Remote friendly environment with flexibility
  • Expense reimbursement for Cell Phone & Internet
  • Ongoing professional development and learning resources
  • Opportunities for career advancement within a fast-growing team
Full Job Description
Senior Vulnerability Analyst

Location: MA / Austin TX / MD
Team: Research
Employment Type: Full-Time, Remote
About the Role

Are you passionate about advancing the science of vulnerability analysis and threat intelligence? Do you want to join a mission-driven team that delivers real-world impact-and has the resources and technical culture to fuel your curiosity?

We're searching for a Senior Vulnerability Analyst with a deep understanding of the vulnerability management ecosystem, hands-on experience with the CVE process, and expert knowledge in standard frameworks like MITRE ATT&CK, CAPEC, CWE, and CVSS. This is a rare opportunity to leverage your skills and experience as a contributor to, or expert user of, CVE and related MITRE capabilities-while taking your career in vulnerability research to the next level.

We are expanding our Threat Intelligence team and are looking for a detail-oriented analyst to join VulnCheck. This is a 100% remote role with preference for candidates located in Massachusetts, Maryland, OR Greater Austin TX.
What You'll Do
  • Map vulnerabilities: Analyze and map discovered vulnerabilities to MITRE ATT&CK techniques and CAPEC attack patterns with precision and consistency.
  • CWE assignment: Determine and assign accurate CWE (Common Weakness Enumeration) IDs, producing well-documented rationales.
  • CVSS calculation: Authoritatively calculate CVSS v3/v4 base scores, providing transparent, defensible justifications.
  • CVE Processing: Review, draft, and curate CVE Records, ensuring data quality, fidelity, and consistency with CVE Program standards.
  • Collaboration: Liaise with vulnerability researchers, product security teams, and standards communities to ensure best practices and knowledge transfer.
  • Process improvement: Develop and refine workflows and playbooks for vulnerability triage, mapping, and reporting.
  • Mentorship: Share your expertise by mentoring junior analysts and driving team knowledge-sharing initiatives.
What You'll Bring
  • Proven experience with the CVE Program-either as an analyst, CNA, or significant contributor in a major software or security organization.
  • Expert knowledge of MITRE ATT&CK, CAPEC, CWE, and working experience mapping vulnerabilities to these frameworks.
  • Advanced understanding of CVSS (v3 and v4), including real-world application to vulnerability scoring and risk communication.
  • Strong analytical, technical, and research skills, with a passion for data quality and process rigor.
  • Exceptional written and verbal communication skills-including the ability to translate complex technical details for diverse audiences.
  • Experience engaging with community initiatives, standards bodies, or open-source projects in the vulnerability or threat intelligence space is highly desirable.

Preferred Qualifications
  • Experience contributing to the evolution of vulnerability standards (e.g., participation in CVE Editorial Boards, CAPEC Working Groups, or similar).
  • Familiarity with automation tools or programming/scripting languages (Python, Golang, etc.) for data enrichment or workflow improvement.
  • Published research, whitepapers, or presentations in the field of vulnerability analysis, mapping, or threat intelligence.

IMPORTANT NOTE: This position may involve access to technology subject to U.S. export control regulations. Employment is contingent upon the company's ability to authorize access under applicable export control, sanctions, and any other applicable legal or contractual requirements. The company does not guarantee and is under no obligation to seek such authorization if it would be necessary.
What We Offer

We believe people do their best work when they feel supported, trusted, and valued. VulnCheck offers benefits designed to meet a wide range of needs and lifestyles:
Benefits and Perks
  • Unlimited PTO
  • 401k plan with company match
  • Comprehensive healthcare coverage
  • Generous paid parental leave
  • Remote friendly environment with flexibility
  • Expense reimbursement for Cell Phone & Internet
  • Ongoing professional development, coaching, and learning resources
  • Opportunities for career advancement within a fast-growing team

Similar Jobs

More Jobs at VulnCheck

More Information Technology Jobs

Find similar Senior Vulnerability Analyst (US) jobs: