Lead Vulnerability Intelligence Analyst (Europe or LATAM, Remote)

Posted 9 Days Ago
Be an Early Applicant
Hiring Remotely in Wilmington, DE, USA
In-Office or Remote
Expert/Leader
Security
The Role
Leads vulnerability intelligence by validating exploit claims, testing proof-of-concept exploits, building honeypots and automated assessment tooling, developing mitigations and detection techniques, and producing detailed vulnerability reports. The role also integrates intelligence sources, identifies exploitation activity, and mentors junior analysts.
Summary Generated by Built In

Company Overview:

Intel 471 empowers enterprises, government agencies, and other organizations to win the cybersecurity war using near-real-time insights into the latest malicious actors, relationships, threat patterns, and imminent attacks relevant to their businesses. Founded in 2014, Intel 471 provides comprehensive intelligence and monitoring on threat actors. The company’s centralized TITAN platform enables intelligence and security professionals to access structured information, dashboards, timely alerts and intelligence reporting via web portal or API integration.

Our pedigree is unmatched and we count upon a team with experience operating in the intelligence services, military, law enforcement and private threat intelligence companies in nearly every continent on earth.

The Role:

You own the technical depth of our vulnerability intelligence practice. When a new CVE drops, you're the person who determines what's actually true and decides what our customers should do about it.

This is a team lead role where you'll set the technical standard for how we validate, assess, and communicate vulnerability risk. You'll also build and maintain the tooling that lets a small team cover the ever-growing world of vulnerability research.

What You'll Do:

Design, build, and deploy honeypot systems to monitor for exploitation activity. Acquire, test, and validate proof-of-concept exploits in virtual environments to confirm or refute claims about exploitability. Develop practical mitigations for cases where patching is delayed, impossible, or insufficient. These mitigations could include configuration hardening, network segmentation, ACLs, disabling features, or other controls. You'll devise techniques for detecting both attempted and successful exploitation by illuminating the artifacts defenders should hunt for. You'll write vulnerability reports that dive into the details about an exploit such as how it works, who is using it and who is being targeted. Automation is a key component of the role; you will build and maintain the systems we use to streamline vulnerability assessment and automate triage of vulnerability alerts. 


Required Qualifications:

Every candidate must be able to:

    - Validate and test PoCs to verify the validity of exploitation claims.

    - Devise mitigation techniques beyond patching.

    - Devise techniques for detecting exploit activity, attempted or successful.

    - Write vulnerability reports such as Vulnerability Spotlights.

    - Identify new sources of vulnerability intelligence. 

    - Train and mentor junior team members. 


Technical foundation:

    - Proficiency with at least one programming language (Python, Go, C/C++, or similar) sufficient to read exploit code, modify PoCs, and build tooling. 

    - Hands-on fluency with virtual machines, containers, and re-usable lab environments for safe detonation and analysis.

    - Solid computer science fundamentals.

    - Thorough understanding of computing and internet fundamentals: TCP/IP, HTTP, DNS, TLS, authentication and authorization models, and how real systems are actually deployed.

    - Demonstrated subject-matter-expert-level depth.

    - A working bias toward automation.

Strong candidates additionally bring:

    

    - Experience building honeypot or sensor systems to monitor real-world exploitation activity.

    - Experience building systems that streamline or automate PoC testing and validation.

    - Demonstrated ability to integrate a new intelligence source end-to-end, from evaluation and ingestion to  normalization, enrichment and delivery. 

Also valuable: original vulnerability research or CVE credits; reverse engineering skills; detection engineering (Sigma, Snort/Suricata, YARA); SOC experience; familiarity with CVSS, CWE, EPSS, and the KEV catalog; public speaking or published writing.

 

Benefits:

  • Competitive compensation
  • Remote-friendly culture
  • Wellness programs
  • A variety of professional development opportunities
  • Inclusive culture focused on people, customers and innovation

Our Culture:

 

The Intel 471 team is constantly growing and is always on the lookout for talented professionals who seek to operate on the forefront of the fight against threat actors impacting our customers and partners. Our culture of humility and quiet professionalism is a core attribute of Intel 471 and everyone within it. Our culture is collaborative, supportive and fast-paced. We're a mission-driven company. We're looking for talented, 'can-do' minded people with a passion for always doing the right thing.

 

We believe in supporting a progressive culture that allows all our people to be themselves, enjoy exciting opportunities and grow with us. That's why our culture is founded on our core values of openness, inclusion, integrity and client focus, which set the tone for how we work together and treat each other in order to empower us all – and foster a unique team spirit.

Skills Required

  • Validate and test proof-of-concept exploits to verify exploitation claims
  • Develop mitigation techniques beyond patching
  • Develop techniques to detect attempted and successful exploitation
  • Write detailed vulnerability reports
  • Identify new sources of vulnerability intelligence
  • Train and mentor junior team members
  • Proficiency in at least one programming language such as Python, Go, C, or C++ sufficient to read exploit code, modify proof-of-concept exploits, and build tooling
  • Hands-on fluency with virtual machines, containers, and reusable lab environments
  • Solid computer science fundamentals
  • Thorough understanding of TCP/IP, HTTP, DNS, TLS, authentication, authorization, and real-world system deployments
  • Subject-matter-expert-level vulnerability intelligence depth
  • Bias toward automation
  • Experience building honeypot or sensor systems
  • Experience automating proof-of-concept testing and validation
  • Experience integrating intelligence sources from evaluation and ingestion through normalization, enrichment, and delivery
  • Original vulnerability research or CVE credits
  • Reverse engineering skills
  • Detection engineering experience with Sigma, Snort, Suricata, or YARA
  • SOC experience
  • Familiarity with CVSS, CWE, EPSS, and the KEV catalog
  • Public speaking or published writing experience
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Wilmington, DE
194 Employees
Year Founded: 2014

What We Do

Intel 471 is the premier provider of cybercrime intelligence. Intel 471 provides adversary and malware intelligence for leading intelligence, security and fraud teams. Our adversary intelligence is focused on infiltrating and maintaining access to closed sources where threat actors collaborate, communicate and plan cyber attacks. Our malware intelligence leverages our adversary intelligence and underground capabilities to provide timely data and context on malware and adversary infrastructure. Our team is comprised of intelligence operators and native speakers located where cybercriminals formerly operated with impunity and without consequence. Our pedigree is unmatched and we count upon a team with experience operating in the intelligence services, military, law enforcement and private threat intelligence companies in nearly every continent on earth. The mission of Intel 471 is to protect your organization, your products, your assets and your people.

Similar Jobs

Shield AI Logo Shield AI

Senior Lead, Enterprise Strategy and Operations (R5624)

Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software • Defense Technology
In-Office or Remote
4 Locations
160K-240K Annually
Remote or Hybrid
US
15100 Employees
91K-128K Annually

Bilt Logo Bilt

Customer Support - Remote

Fintech • Mobile • Real Estate • Financial Services • PropTech
Remote
USA
200 Employees
50K-55K Annually

Shield AI Logo Shield AI

Director, Enterprise Strategy and Operations (R5626)

Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software • Defense Technology
In-Office or Remote
4 Locations
190K-290K Annually

Similar Companies Hiring

Nisos Thumbnail
Artificial Intelligence • Security • Business Intelligence • Consulting • Cybersecurity
Arlington, VA
70 Employees
Nasuni Thumbnail
Artificial Intelligence • Big Data • Cloud • Security • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Boston, MA
550 Employees
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account