Principal Vulnerability Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Principal Vulnerability Analyst (Cybersecurity): Identifying and analyzing novel security gaps in industrial control systems (ICS) with an accent on embedded systems reverse engineering and vulnerability reporting. Focus on developing detection signatures, mentoring researchers, and automating research workflows to protect critical infrastructure.
Location: Must be based in the United States
Salary: $170,000
Company
Global leader in xOT cybersecurity providing technology and threat intelligence to protect the world's critical infrastructure.
What you will do
- Identify novel vulnerabilities in industrial products and control systems through strategic acquisition and rigorous analysis.
- Coordinate responsible disclosure with vendors and author technically rigorous vulnerability reports for internal and public use.
- Develop detection signatures (Suricata, YARA) and collaborate with engineering to enhance the Platform's capabilities.
- Assess in-the-wild exploits and integrate findings into broader threat intelligence for IR and threat intel teams.
- Mentor researchers and penetration testers while representing the company through public reporting and industry presentations.
- Implement automated vulnerability analysis tools and processes using Python and C# to scale research.
Requirements
- 5+ years of experience developing or evaluating proof-of-concept code related to vulnerabilities.
- Expertise in embedded systems reverse engineering or binary reverse engineering of Windows/embedded applications.
- Strong knowledge of binary network protocols and low-level networking concepts.
- 3+ years of experience writing customer-facing technical materials for decision-makers.
- Proficiency in developing software tooling or analytical automation using Python, C#, or similar languages.
- Must be based in the United States.
Nice to have
- Experience in malware reverse engineering using static and dynamic analysis.
- Proficiency in developing YARA, Snort, Suricata, or Zeek detection rules.
- Familiarity with ICS protocols such as Modbus, DNP3, or Profibus.
- Experience working with operations centers and incident response teams during live engagements.
- Track record of discovering and responsibly disclosing novel vulnerabilities.
Culture & Benefits
- Remote-first, mission-driven environment built on authenticity, transparency, and trust.
- Competitive equity package.
- Comprehensive benefits plan.
- Opportunity to protect essential services like power, water, and healthcare.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →