Principal Vulnerability Analyst New

Dragos, Inc.

Northern (KY)

Hybrid

USD 130,000 - 180,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive Equity Package

Job summary

Dragos is seeking a Principal Vulnerability Analyst to autonomously identify research targets, conduct in-depth vulnerability analyses, and author reports that shape industry understanding of threats. You will work with threat intel, engineering, and incident response teams to amplify real-world impact.

You will mentor colleagues, drive methodology development, and help Dragos scale vulnerability research with automation and robust tooling.

Qualifications

  • 5+ years developing, deploying, or evaluating vulnerability-related concepts.
  • Expertise in embedded or binary reverse engineering for Windows or embedded apps.
  • Strong knowledge of binary protocols and low-level networking concepts.
  • 3+ years writing customer-facing technical material for decision-makers.
  • Deep understanding of vulnerability scoring and OT impact assessment.
  • Ability to independently identify targets, plan analyses, and acquire assets.
  • Proficiency in software tooling or automation using Python, C#, or similar.

Responsibilities

  • Identify novel vulnerabilities in industrial products and assess IT/ICS impact.
  • Coordinate disclosure with vendors and produce clear vulnerability reports.
  • Develop detection signatures and collaborate with engineering to close gaps.
  • Serve as internal SME for threat intel and incident response teams.
  • Contribute to vulnerability research roadmap and partner with customers.
  • Mentor researchers and testers, and share Dragos expertise publicly.
  • Champion automated vulnerability analysis tools to scale research.

Skills

Vulnerability analysis
Reverse engineering
Low-level networking
Customer-facing writing
Python/C# tooling
Autonomy / roadmap planning

Tools

Suricata
YARA
Snort
Zeek
Python
C#

Job description

At Dragos, the mission is personal. The systems we protect deliver the water you drink, power your home, and keep the hospitals your community depends on running. Those critical infrastructure systems that power our civilization around the world are under attack every day by adversaries. When those systems fail, people are immediately at risk. We are the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. The people here chose this work because they understand what is at stake . Here, you will find a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust. If safeguarding the systems that protect your family, friends, and community is the kind of work that matters to you, you are in the right place.

About the Role

Dragos' Vulnerability Analysis team identifies novel security gaps in the industrial control systems that power plants, water utilities, and manufacturing facilities depend on—and translates those findings into detections and actionable intelligence that defend critical infrastructure. As a Principal Vulnerability Analyst, you'll operate with high autonomy to identify research targets, perform in-depth vulnerability analysis, coordinate with affected vendors, and author vulnerability reports that shape how the industry understands emerging threats. You'll partner across threat intelligence, product engineering, and incident response teams to amplify the real‑world impact of your work. Working alongside another vulnerability analyst, you'll serve as a recognized subject matter expert and trusted internal resource—mentoring researchers and penetration testers, driving methodology development, and helping identify gaps in the Dragos Platform's ability to detect new exploits.

Responsibilities
  • Identify novel vulnerabilities in industrial products and control systems through strategic acquisition and rigorous analysis, assessing operational impact on both IT and ICS environments.
  • Coordinate responsible disclosure with affected vendors and author clear, technically rigorous vulnerability reports for internal customers and public publication.
  • Develop detection signatures (Suricata, YARA, internal analytics) and partner with product engineering to identify and close gaps in the Dragos Platform's vulnerability detection capabilities.
  • Serve as a trusted internal resource to threat intelligence and incident response teams, assessing in-the-wild exploits, analyzing vulnerability trends, and integrating findings into broader threat intelligence.
  • Contribute to the strategic vulnerability management roadmap and collaborate with customers and strategic partners on vulnerability research projects that advance collective defense.
  • Mentor other researchers and penetration testers while communicating Dragos expertise through public reporting, industry presentations, and engagement with the security community.
  • Champion the adoption of automated vulnerability analysis tools and processes to scale research capabilities and optimize team workflows.
Qualifications
  • 5+ years developing, deploying, or evaluating proof-of-concept code related to vulnerabilities.
  • Demonstrable expertise in embedded systems reverse engineering or binary reverse engineering of Windows and/or embedded applications.
  • Strong familiarity with binary network protocols and low‑level networking concepts.
  • 3+ years writing customer‑facing technical material and demonstrated ability to translate complex details to inform decision‑makers and operators.
  • In‑depth understanding of vulnerability scoring mechanisms, their benefits and limitations in OT context, and measured ability to assess real‑world operational impact.
  • Proven ability to function independently to identify devices and software to assess, determine acquisition strategies, and develop analysis roadmaps.
  • Demonstrated proficiency developing software tooling or analytical automation using Python, C#, or similar languages to enhance team workflows and scale research.
Nice to Haves
  • Experience reverse engineering malware using static and dynamic analysis tools and techniques, with familiarityofmalware code constructs.
  • Experience developing YARA, Snort, Suricata or Zeek detections rules.
  • Experience working with an operations center and incident response team during live engagements.
  • Track record of discovering and responsibly disclosing novel vulnerabilities.
  • Familiarity with ICS protocols (Modbus, DNP3, Profibus, etc.) and their security properties.
  • External presence or track record of knowledge sharing through publications, conference presentations, or industry engagement.
Compensation
  • Competitive Equity Package

#LI-JF1 #LI-REMOTE

Dragos is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, state, or local laws. All new hires must pass a background check as a condition of employment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Software Engineer
Senior Software Engineer

Clutch Canada • United States

Remote
USD 140,000 - 165,000
Competitive Equity Package
Comprehensive Benefits Plan
Senior Software Engineer
Senior Software Engineer

Dragos, Inc • United States

On-site
USD 100,000 - 130,000
Competitive Equity Package
Associate Principal Malware Analyst New
Associate Principal Malware Analyst New

Dragos, Inc. • Northern (KY)

Hybrid
USD 120,000 - 190,000
Principal Field Operations Engineer - Federal
Principal Field Operations Engineer - Federal

Linuxconfig • Northern (KY)

Hybrid
USD 120,000 - 180,000
Associate Principal Incident Responder
Associate Principal Incident Responder

Dragos, Inc. • United States

On-site
USD 131,000 - 179,000
Senior Capabilities Developer
Senior Capabilities Developer

Dragos, Inc. • Northern (KY)

Hybrid
USD 140,000 - 200,000
Competitive Equity Package
Senior Systems Engineer
Senior Systems Engineer

Dragos, Inc. • Northern (KY)

Hybrid
USD 120,000 - 180,000
Competitive Equity Package
Principal Resident Engineer (Federal)
Principal Resident Engineer (Federal)

AllegisCyber Capital • Washington

On-site
USD 180,000 - 220,000
Salary: $200,000
Competitive Equity Package
Comprehensive Benefits Plan
Senior Vulnerability Analyst, ICS/OT Threat Hunter
Senior Vulnerability Analyst, ICS/OT Threat Hunter

Dragos, Inc. • United States

On-site
USD 153,000 - 187,000
Equity package
Benefits plan
Associate Principal Resident Engineer (Federal)
Associate Principal Resident Engineer (Federal)

Dragos, Inc. • Washington

On-site
USD 155,000
Competitive Equity Package
Comprehensive Benefits Plan