Senior Vulnerability Analyst (US)
Core
Analyze and map discovered vulnerabilities to MITRE ATT&CK techniques, CAPEC attack patterns, and CWE IDs while calculating CVSS scores and curating CVE Records.
Role type
Senior Vulnerability Analyst (Threat Intelligence)
Builds
Structured exploit intelligence for data lakes, ETL pipelines, automation, and AI/LLM workflows
Domain
Cybersecurity / Vulnerability Management / Threat Intelligence
Deliverable
production ML models | dashboards & analysis
Required skills
CVE Program expertise, MITRE ATT&CK mapping, CAPEC analysis, CWE assignment, CVSS v3/v4 calculation, vulnerability research, data quality rigor, standards community engagement
Preferred skills
CVE Editorial Board participation, automation scripting (Python/Golang), published research in vulnerability analysis
Technologies
MITRE ATT&CK, CAPEC, CWE, CVSS v3/v4, CVE Program
Responsibilities
Map vulnerabilities to MITRE ATT&CK and CAPEC frameworks; Assign accurate CWE IDs with documented rationales; Calculate CVSS v3/v4 base scores; Review and curate CVE Records; Liaise with researchers and standards bodies; Develop vulnerability triage workflows; Mentor junior analysts
Seniority
Senior, hands-on IC with mentorship responsibilities