Senior Vulnerability Researcher (Pentesting)

Reposted 8 Days Ago
Be an Early Applicant
2 Locations
In-Office or Remote
Senior level
Big Data • Information Technology • Security • Software • Analytics • Cybersecurity
The Role
As a Staff Vulnerability Researcher, you will analyze emerging threats, develop vulnerability detection techniques, mentor junior researchers, and drive innovation in cybersecurity efforts.
Summary Generated by Built In

Bitsight is a cyber risk management leader transforming how companies manage exposure, performance, and risk for themselves and their third parties. Companies rely on Bitsight to prioritize their cybersecurity investments, build greater trust within their ecosystem, and reduce their chances of financial loss.
Built on over a decade of technological innovation, its integrated solutions deliver value across enterprise security performance, digital supply chains, cyber insurance, and data analysis.

  • We invented the cyber ratings industry in 2011
  • Over 3000 customers trust Bitsight
  • Over 750 teammates are dispersed throughout Boston, Raleigh, New York, Lisbon, Singapore, and remote

The Vulnerability Research team within Bitsight’s Security Research department develops and deploys techniques to remotely detect the presence of recently disclosed vulnerabilities.  These techniques are integrated into the company’s Internet scanning infrastructure which enables Bitsight to measure the rate at which organizations patch and remediate vulnerabilities.  This function is a critical input into Bitsight’s capability to assess the effectiveness of organizational security programs as well as the ability to identify third party vulnerability exposures in organizations’ digital supply chains.  The team also enables a unique form of “vulnerability epidemiology” research in tracking the scale, impact, and organizational response for high-profile vulnerabilities.  This role will work alongside an international team of vulnerability researchers in the research and development of new vulnerability detection and inference tools and techniques as well as the integration and operationalization of those techniques within Bitsight’s telemetry collection infrastructure.

Objectives & Responsibilities

  • Research and analyze emerging threats as well as newly published, high-profile vulnerabilities and contribute to the development of vulnerability intelligence tooling

  • Conduct in-depth assessments of vulnerabilities to assess viability of remote, network-based detection methods

  • Reverse engineer software and software patches to identify new detection methods

  • Develop plugins, tools, and techniques to implement newly researched vulnerability detection and product fingerprinting capabilities

  • Drive innovation by researching and developing new tools and techniques

  • Provide technical leadership on research projects to include mentoring junior researchers and providing regular updates to stakeholders

  • Identify opportunities for automation and process improvement within Bitsight workflows

  • Develop vulnerability detection techniques, and communicate potential techniques, and the associated risk, with senior leadership

Qualifications:

  • Bachelors degree in Computer Science or related field; Master’s degree preferred

  • Experience in vulnerability research, penetration testing, and exploit development

  • In depth knowledge of tactics, techniques, and procedures commonly used by threat actors

  • Proven track record of innovation in the field of vulnerability research

  • Experience in leading technical projects and mentoring junior team members

  • Broad knowledge of information security principles and network protocols

  • Experience in network-based vulnerability detection capability development

  • Experience in source code analysis

  • Familiarity software reverse engineering and patch diffing

  • Strong communication and interpersonal skills

  • Strong analytical and problem solving skills and a track record of solving ambiguous problems

  • Machine learning experience is a plus

  • Ownership mindset

  • Proficient in python programming

Belonging & Inclusion. Bitsight is proud to be an equal opportunity employer. This means we do not tolerate discrimination of any kind and are committed to providing equal employment opportunities regardless of your gender identity, race, nationality, religion, sexual orientation, status as a protected veteran, or status as an individual with a disability.

Culture. We put our people first. Bitsight offers best in class benefits. We devote the same energy to nurturing our company's inclusive culture as we apply to serving our customers' needs. Working at Bitsight will give you the opportunity to fulfill your professional goals and expand your skills.

Open-minded. If you got to this point, we hope you’re feeling excited about the job description you just read.  Even if you don’t feel that you meet every single requirement, we still encourage you to apply.  We’re eager to meet people that believe in Bitsight’s mission and can contribute to our team in a variety of ways.

Bitsight also provides reasonable accommodations to qualified individuals with disabilities or based on a sincerely held religious belief in accordance with applicable laws. If you need to inquire about a reasonable accommodation, or need assistance with completing the application process, please email [email protected]. This contact information is for accommodation requests only, and cannot be used to inquire about the status of applications.

Additional Information for United States of America Applicants:

Bitsight is committed to compliance with all fair employment practices regarding citizenship and immigration status.

Bitsight will not discharge, discipline or in any other manner discriminate against any employee or applicant for employment because such employee or applicant has inquired about, discussed, or disclosed the compensation of the employee or applicant or another employee or applicant.

Massachusetts Applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Qualified applicants with criminal histories will be considered for employment consistent with applicable law.

This position may be considered a promotional opportunity pursuant to the Colorado Equal Pay for Equal Work Act.

Top Skills

Python
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Boston, MA
800 Employees
Year Founded: 2011

What We Do

Bitsight is a cyber risk management leader transforming how companies manage exposure, performance, and risk for themselves and their third parties.

Founded in 2011, Bitsight Security Ratings Platform applies sophisticated algorithms, producing daily security ratings that range from 250 to 900, to help manage third party risk, underwrite cyber insurance policies, benchmark performance, conduct M&A due diligence and assess aggregate risk. Organizations worldwide, including seven of the top 10 cyber insurers, 20% of Fortune 500 companies, and 3 of the top 5 investment banks use BitSight’s proven Security Ratings technology on a daily basis to make integral risk and business decisions. With over 3,000 customers and the largest ecosystem of users and information, BitSight is the most widely used Security Ratings Service.

Why Work With Us

Grow your career with the company that's building the future of cybersecurity with the brightest minds working together to solve tomorrow’s challenges.

Gallery

Gallery

Similar Jobs

Navan Logo Navan

Consultant

Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
Easy Apply
Remote or Hybrid
Portugal
3300 Employees

Coinbase Logo Coinbase

Technical Account Manager

Artificial Intelligence • Blockchain • Fintech • Financial Services • Cryptocurrency • NFT • Web3
Remote
28 Locations
4000 Employees

Zapier Logo Zapier

Artificial Intelligence Engineer

Artificial Intelligence • Productivity • Software • Automation
Remote
30 Locations
760 Employees

MacPaw Logo MacPaw

Director of Data & Analytics

Information Technology • Security • Software • Cybersecurity • App development • Data Privacy
Remote or Hybrid
28 Locations
550 Employees

Similar Companies Hiring

Standard Template Labs Thumbnail
Software • Information Technology • Artificial Intelligence
New York, NY
10 Employees
PRIMA Thumbnail
Travel • Software • Marketing Tech • Hospitality • eCommerce
US
15 Employees
Scotch Thumbnail
Software • Retail • Payments • Fintech • eCommerce • Artificial Intelligence • Analytics
US
25 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account