or apply directly on VulnCheck's site. We never take the application ourselves.
Is this posting real?
- This role has been open
- 55 days VulnCheck's roles stay open a median of 55 days
- Reposted
- No
- Salary listed
- No 0% of VulnCheck's roles list one
- Ghost-job risk at VulnCheck
- high 14 stale, 0 reposted of 15 open
- Hiring momentum
- 25 roles opened in the last 90 days ↑ up vs. the prior 90 days
- Last confirmed on the employer's board
- 2026-09-27
Measured from postings appearing on and disappearing from VulnCheck's own greenhouse board since 2026-08-03. Full hiring picture for VulnCheck.
About this role
As a Senior Vulnerability Analyst at VulnCheck, you will be responsible for assessing and validating vulnerability reports, coordinating disclosures with software suppliers and researchers, and populating CVE metadata. Your role will involve developing workflows for vulnerability triage and sharing your expertise with internal teams and the broader community. This position is fully remote, with a preference for candidates in specific locations.
- benefits
- 4/5
- freshness
- 1/5
- career value
- 4/5
- role clarity
- 4/5
- pay transparency
- 0/5
Scored from the posting itself — how clearly the role is described, how much it says about pay and benefits, and how recently it was listed. Not a judgement of VulnCheck as an employer.
What you need
- 2+ years of coordinated vulnerability disclosure (CVD) experience at a PSIRT, government agency, researcher or bug bounty CNA, or other coordinating body in the vulnerability disclosure ecosystem
- Prior experience writing, reviewing, and updating CVE records; familiarity with CVE record structure and tooling (e.g., CVE services, Vulnogram)
- Prior experience analyzing unstructured vulnerability reports and product documentation to determine whether reported issues cross security boundaries and demonstrate sufficient impact to confidentiality, integrity, and availability
- Prior experience reporting and coordinating vulnerability reports with third-party organizations, including commercial and open-source projects and products
- Exceptionally strong written and verbal communication skills
- Knowledge of MITRE ATT&CK, CAPEC, and CWE, and working experience mapping vulnerability reports to these frameworks
Nice to have
- Experience engaging with community initiatives, standards bodies, or open-source projects in the vulnerability or threat intelligence space
- Familiarity with automation tools or programming/scripting languages (Python, Golang, etc.) for data enrichment or workflow improvement
- Published research, whitepapers, or presentations in the field of vulnerability analysis, mapping, or threat intelligence
What you get
- Unlimited PTO
- 401k plan with company match
- Comprehensive healthcare coverage
- Generous paid parental leave
- Remote friendly environment with flexibility
- Expense reimbursement for Cell Phone & Internet
Worth weighing
- No salary listed
- The role involves significant communication and coordination, which may require strong interpersonal skills and adaptability to different audiences.
- The position may involve access to technology subject to U.S. export control regulations, which could impact employment eligibility.
Summarised from VulnCheck's posting. Read the full original.
Listed by VulnCheck on their greenhouse job board, last confirmed open on 2026-09-27. PitchMeAI is not the employer.
More roles at VulnCheck
- Engineering Manager, Rapid Response Assignment - USMA / Austin TX / MD
- Senior Cloud Infrastructure Engineer (US)Massachusetts, Maryland, or Greater Austin, TX (Remote)
- Senior Sales Engineer (East)Boston, MA
- Product Marketing Lead (US)Boston, MA / Austin, TX
- Sales Director - IsraelTel Aviv Israel
- Software Engineer, Rapid Response Assignment - USMassachusetts OR Maryland OR Greater Austin, TX.
- Sr. Vulnerability Researcher (US)US Remote