Posted today · be early
Lead Vulnerability Intelligence Analyst (Europe or LATAM, Remote)
Intel 471
WorldwideremotePosted today
Skill Required
Vulnerability-IntelligenceThreat-Intelligence-AnalystSecurity-ResearcherVulnerability-ResearcherCybersecurity-AnalystVulnerability-Assessment-LeadSenior-Cyber-Threat-Intelligence-AnalystVulnerability-Management-AnalystVulnerability-AnalystPrincipal-Threat-And-Vulnerability-Management-EngineerCyber-Threat-Intelligence-LeadCybersecurityEngineeringR ProgrammingautomationObservabilitysimilar)securitybuildingTestNGPythonTCP/IPdesignC++Design PatternsDNSandCryptographyGoContract
Key highlights
- Competitive compensation
- Remote-friendly culture
- Team lead role
- Subject-matter-expert-level depth required
- Proficiency in at least one programming language (Python, Go, C/C++, or similar) required
Role overview
Intel 471 empowers enterprises, government agencies, and other organizations to win the cybersecurity war using near-real-time insights into the latest malicious actors, relationships, threat patterns, and imminent attacks relevant to their businesses. Founded in 2014, Intel 471 provides comprehensive intelligence and monitoring on threat actors through its centralized TITAN platform, which enables intelligence and security professionals to access structured information, dashboards, timely alerts, and intelligence reporting via web portal or API integration. The team has experience operating in intelligence services, military, law enforcement, and private threat intelligence companies across nearly every continent.
Responsibilities
- Own the technical depth of the vulnerability intelligence practice; determine what is actually true when a new CVE drops and decide what customers should do about it
- Set the technical standard for how the team validates, assesses, and communicates vulnerability risk as a team lead
- Design, build, and deploy honeypot systems to monitor for exploitation activity
- Acquire, test, and validate proof-of-concept exploits in virtual environments to confirm or refute claims about exploitability
- Develop practical mitigations for cases where patching is delayed, impossible, or insufficient, including configuration hardening, network segmentation, ACLs, disabling features, or other controls
- Devise techniques for detecting both attempted and successful exploitation by illuminating the artifacts defenders should hunt for
- Write vulnerability reports such as Vulnerability Spotlights that dive into details about an exploit including how it works, who is using it, and who is being targeted
- Build and maintain tooling that lets a small team cover the ever-growing world of vulnerability research
- Identify new sources of vulnerability intelligence
- Train and mentor junior team members
Requirements
- Validate and test PoCs to verify the validity of exploitation claims
- Devise mitigation techniques beyond patching
- Devise techniques for detecting exploit activity, attempted or successful
- Write vulnerability reports such as Vulnerability Spotlights
- Identify new sources of vulnerability intelligence
- Train and mentor junior team members
- Proficiency with at least one programming language (Python, Go, C/C++, or similar) sufficient to read exploit code, modify PoCs, and build tooling
- Hands-on fluency with virtual machines, containers, and re-usable lab environments for safe detonation and analysis
- Solid computer science fundamentals
- Thorough understanding of computing and internet fundamentals: TCP/IP, HTTP, DNS, TLS, authentication and authorization models, and how real systems are actually deployed
- Demonstrated subject-matter-expert-level depth
- A working bias toward automation
Nice to have
- Experience building honeypot or sensor systems to monitor real-world exploitation activity
- Experience building systems that streamline or automate PoC testing and validation
- Demonstrated ability to integrate a new intelligence source end-to-end, from evaluation and ingestion to normalization, enrichment and delivery
- Original vulnerability research or CVE credits
- Reverse engineering skills
- Detection engineering (Sigma, Snort/Suricata, YARA)
- SOC experience
- Familiarity with CVSS, CWE, EPSS, and the KEV catalog
- Public speaking or published writing
Benefits
- Competitive compensation
- Remote-friendly culture
- Wellness programs
- A variety of professional development opportunities
- Inclusive culture focused on people, customers and innovation
Additional details
- This is a team lead role
- Automation is a key component of the role; you will build and maintain the systems used to streamline vulnerability assessment and automate triage of vulnerability alerts
- The Intel 471 team is constantly growing and is always on the lookout for talented professionals who seek to operate on the forefront of the fight against threat actors impacting customers and partners
- Culture of humility and quiet professionalism; collaborative, supportive, fast-paced, and mission-driven
- Looking for talented, 'can-do' minded people with a passion for always doing the right thing
- Culture founded on core values of openness, inclusion, integrity and client focus
- Originally posted on Himalayas