Vulnerability Analyst
📍 Austin, United States
📍 New York City, United States
📍 Palo Alto, United States
Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
API
AWS @ 3
Communication @ 3
Dashboarding @ 2
Data Analysis
GCP @ 3
Grafana @ 2
JSON
Kibana @ 2
Python @ 3
Security @ 6
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
SpaceXAI's Vulnerability Management team assesses and mitigates security risks across the organization's portfolio. This role focuses on vulnerability analysis and risk assessment, helping protect the organization against emerging threats through vulnerability scoring, data analysis, and automation.
Responsibilities
- Conduct vulnerability assessments using the Common Vulnerability Scoring System (CVSS) standard as defined by First.org.
- Understand and implement vector strings and vector chaining for risk evaluation.
- Perform data analysis to assess security risks across the organization.
- Identify vulnerability reachability and impact to prioritize security responses.
- Write Python scripts to manage and manipulate data from CSV, Excel, JSON, and RESTful API sources.
- Apply the MITRE ATT&CK framework for attack path analysis.
- Create data reporting solutions, including simple dashboards.
- Engage with stakeholders across the organization to ensure security buy-in.
- Demonstrate strong critical analysis, problem-solving, and security expertise.
Requirements
- Deep expertise in vulnerability assessment, data management, and security frameworks.
- Strong analytical skills and the ability to evaluate risk.
- Mastery of CVSS and its environmental processing.
- Expertise in Python for security data manipulation.
- Strong understanding of vulnerability impact, risk assessment, and mitigation strategies.
- Proficiency with the MITRE ATT&CK framework for security analysis.
- Experience creating dashboard-based reports to communicate security findings.
- Excellent communication and stakeholder management skills.
Preferred Skills And Experience
- Experience with Elastic or OpenSearch.
- Familiarity with Kibana or Grafana dashboarding.
- Experience developing security automation playbooks.
- Experience with AWS and/or GCP.
- Experience building agentic workflows for vulnerability management.
Compensation And Benefits
The base salary range is $100,000–$258,000 USD. The total rewards package also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short- and long-term disability insurance, life insurance, and various other discounts and perks.
ITAR Requirements
To conform to U.S. Government export regulations, applicants must be U.S. citizens or nationals, U.S. lawful permanent residents, refugees under 8 U.S.C. § 1157, asylees under 8 U.S.C. § 1158, or eligible to obtain the required authorizations from the U.S. Department of State.