VulnCheck Logo

VulnCheck

Principal Threat Hunter

Posted 10 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
Expert/Leader
Remote
Hiring Remotely in United States
Expert/Leader
Conduct threat hunting across exploitation and attacker infrastructure data, investigate payloads and malware, develop detections and automation, and produce actionable threat intelligence. The role involves analyzing PCAPs, network traffic, vulnerabilities, and large datasets; writing Suricata/Snort rules and Nuclei templates; publishing research; presenting findings; and establishing VulnCheck’s threat hunting methodology and capabilities.
The summary above was generated by AI
Principal Threat Hunter (Remote, US)

Location: Remote, United States
Team: Product & Engineering
Employment Type: Full-Time, Remote

About VulnCheck

Exploitation prevention is only as strong as the intelligence driving those efforts, and most of the industry is still running on intelligence that lacks exploit context. VulnCheck, The Exploit Intelligence Company, delivers structured exploit intelligence on what is actively weaponized in the wild, purpose-built for the data lakes, ETL pipelines, automation, and AI and LLM workflows your infrastructure already runs on, raising the capability of everything it powers.

About the Role

VulnCheck is hiring a Principal Threat Hunter to discover, investigate, and document real-world exploitation and attacker infrastructure, and turn those discoveries into durable improvements to VulnCheck's detection capabilities.

VulnCheck operates infrastructure across the internet that gives us a direct view into attacker activity. Canary Intelligence deploys intentionally vulnerable systems and captures real exploitation attempts, giving researchers a steady stream of attacker binaries, source infrastructure, payloads, and exploitation techniques. Target Intelligence maintains a continuously updated view of internet-facing systems, including their exposure to known vulnerabilities and their relationships to scanners, proxies, C2 infrastructure, and other attack infrastructure.

Together, these datasets provide a foundation for research that is difficult to replicate elsewhere. You can observe exploitation as it happens rather than infer it from secondary telemetry, analyze what attackers deploy after gaining access, and pivot from an attacking host into the broader infrastructure behind it.

The role spans the full research process. You will hunt for interesting activity, investigate what you find, develop methods and detections to identify similar activity at scale, and turn those investigations into original threat intelligence. You will help build the tooling and detections needed to support your research and improve VulnCheck's ability to identify meaningful attacker activity.

You will be the first full-time threat hunter at VulnCheck, so there is no existing threat hunting pipeline or playbook to inherit. You will have substantial latitude to define areas of research and help establish how VulnCheck approaches threat hunting as the function grows.

This role is fully remote and open to candidates based anywhere in the United States.

What You'll Do
  • Hunt for emerging exploitation activity, attacker infrastructure, and novel attacker behavior across VulnCheck's data
  • Turn discoveries from threat hunting into durable improvements to VulnCheck's detection capabilities, including new rules, queries, tooling, and automation
  • Investigate exploitation attempts, attacker payloads, binaries, infrastructure, and post-exploitation activity
  • Build tooling and automation to support threat hunting and large-scale analysis
  • Pivot across vulnerabilities, hosts, IPs, domains, payloads, and other infrastructure to uncover relationships and broader activity
  • Turn research findings into actionable threat intelligence for VulnCheck customers
  • Write customer-facing threat intelligence reports and technical blog posts that clearly explain what you found and why it matters
  • Present research at conferences and other industry events
  • Work with vulnerability researchers and other members of the VulnCheck research team to connect observed exploitation with vulnerability intelligence
  • Help shape the direction, methodology, and capabilities of VulnCheck's threat hunting function as it grows
  • Use VulnCheck's data and products as an expert customer, identify gaps in our ability to detect or investigate attacker activity, and help drive improvements to close those gaps
What You'll Bring
  • A demonstrated track record of communicating technical security research through public writing, threat intelligence reports, blogs, presentations, or other published work
  • Experience hunting for threats, analyzing attacker activity, conducting threat intelligence research, or performing closely related security research
  • The ability to read and analyze PCAPs and reason about network traffic and protocols
  • Demonstrated experience developing and tuning detections, including Suricata and/or Snort rules, and translating research findings into repeatable detection capabilities
  • Experience writing Nuclei templates or other scanners to identify vulnerabilities, exposed services, or attacker infrastructure
  • Strong programming or scripting ability, with comfort reading and writing code in multiple languages and picking up unfamiliar languages when the research requires it
  • Experience working with Linux systems, networking, and internet-facing infrastructure
  • The ability to analyze malware, payloads, scripts, and other artifacts encountered during an investigation
  • Experience working with large datasets and developing queries or tooling to find meaningful activity within them
  • The ability to pivot across technical data sources and follow an investigation from an initial indicator to a broader set of infrastructure or activity
  • The curiosity and independence to identify interesting research questions and pursue them without a predefined playbook
Preferred Qualifications
  • A substantial body of published security research, particularly work that has had an impact on the security community
  • Experience researching exploitation campaigns, malware families, attacker infrastructure, or vulnerability exploitation in the wild
  • Experience working across multiple areas of security research, such as vulnerability research, reverse engineering, malware analysis, threat intelligence, or detection engineering
  • Experience leading threat intelligence or security research initiatives, including establishing research direction, methodologies, or operational processes
What We Offer

We believe people do their best work when they feel supported, trusted, and valued. VulnCheck offers benefits designed to meet a wide range of needs and lifestyles:

Benefits and Perks

  • Unlimited PTO
  • 401k plan
  • Comprehensive healthcare coverage
  • Generous paid parental leave
  • Remote friendly environment with flexibility
  • Expense reimbursement for Cell Phone & Internet
  • Ongoing professional development, coaching, and learning resources
  • Opportunities for career advancement within a fast-growing team
Why Join Us

Built on over two decades of cybersecurity experience, our team of experts understands the intricacies of vulnerabilities, their exploitation in the wild, and how to leverage this data to build more effective cybersecurity products that produce better outcomes for organizations.

VulnCheck gives organizations a tactical advantage by providing best-in-class exploit & vulnerability intelligence information. We have a sense of duty to protect the critical infrastructure we rely on including medical devices, power grids and telecommunication networks. We were founded in 2021 in Lexington, Massachusetts.

VulnCheck has a transparent, collaborative, and supportive culture — we are looking for people who have a growth mindset, are curious and innovative. Our team is smart, but humble, hardworking, and supportive.

VulnCheck is proud to be an Equal Employer Opportunity employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. VulnCheck is committed to working with and providing reasonable accommodations to applicants with physical and mental disabilities. Even if your experience doesn't perfectly align with the job description, we encourage you to apply — we value potential just as much as a perfect resume.

Similar Jobs

An Hour Ago
Remote
USA
190K-215K Annually
Expert/Leader
190K-215K Annually
Expert/Leader
Big Data • Fitness • Healthtech • Information Technology • Software • Analytics
Lead Medicaid policy analysis for a state program by translating eligibility, benefits, claims, and provider rules into analytic logic. Build production-grade data marts, registries, dashboards, reports, and cohort definitions using SQL and Python. Serve as the senior analytical partner to Medicaid leadership, contractors, vendors, and data teams; resolve data-quality issues, establish methodologies, prioritize work, and mentor analysts.
Top Skills: Amazon AthenaAmazon QuicksightAmazon RedshiftAWSClaude CodeConfluenceCpt/HcpcsCursorDbtFoundryGitIcd-10JIRAExcelNppesPower BIPythonSQLTableau
An Hour Ago
Remote or Hybrid
150K-150K Annually
Senior level
150K-150K Annually
Senior level
eCommerce • Legal Tech • Professional Services • Software • Data Privacy
Develop and maintain complex iOS applications from the ground up, integrate APIs, architect full-lifecycle solutions, and improve development workflows. The role requires Swift and SwiftUI expertise, testing across unit, integration, and UI levels, CI/CD pipeline development, and strong knowledge of Apple’s Human Interface Guidelines. The senior developer will mentor iOS engineers, conduct code reviews, collaborate with stakeholders, and contribute to agile product development.
Top Skills: APIsCi/CdCore DataGitiOSStructured ConcurrencySwiftSwift 6Swift TestingSwiftuiXctest
2 Hours Ago
Remote or Hybrid
Ponte Vedra, FL, USA
Senior level
Senior level
Fintech • Financial Services
Leads a Wells Fargo branch team to acquire, deepen, and retain customer relationships across deposits, lending, credit cards, investments, and banking services. Coaches employees, manages performance, drives sales and service excellence, partners with internal banking teams, promotes digital banking, analyzes performance, and maintains operational risk and compliance standards. Requires completion of a Branch Manager Readiness Program unless already serving as a Wells Fargo branch manager.

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account