Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Principal Vulnerability Analyst

$170k
Full-time

Dragos

At Dragos, the mission is personal. The systems we protect deliver the water you drink, power your home, and keep the hospitals your community depends on running. Those critical infrastructure systems that power our civilization around the world are under attack every day by adversaries. When those systems fail, people are immediately at risk. We are the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. The people here chose this work because they understand what is at stake. Here, you will find a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust. If safeguarding the systems that protect your family, friends, and community is the kind of work that matters to you, you are in the right place.

About the Role :

Dragos' Vulnerability Analysis team identifies novel security gaps in the industrial control systems that power plants, water utilities, and manufacturing facilities depend on—and translates those findings into detections and actionable intelligence that defend critical infrastructure. As a Principal Vulnerability Analyst, you'll operate with high autonomy to identify research targets, perform in-depth vulnerability analysis, coordinate with affected vendors, and author vulnerability reports that shape how the industry understands emerging threats. You'll partner across threat intelligence, product engineering, and incident response teams to amplify the real-world impact of your work. Working alongside another vulnerability analyst, you'll serve as a recognized subject matter expert and trusted internal resource—mentoring researchers and penetration testers, driving methodology development, and helping identify gaps in the Dragos Platform's ability to detect new exploits.

Responsibilities :

  • Identify novel vulnerabilities in industrial products and control systems through strategic acquisition and rigorous analysis, assessing operational impact on both IT and ICS environments.
  • Coordinate responsible disclosure with affected vendors and author clear, technically rigorous vulnerability reports for internal customers and public publication.
  • Develop detection signatures (Suricata, YARA, internal analytics) and partner with product engineering to identify and close gaps in the Dragos Platform's vulnerability detection capabilities.
  • Serve as a trusted internal resource to threat intelligence and incident response teams, assessing in-the-wild exploits, analyzing vulnerability trends, and integrating findings into broader threat intelligence.
  • Contribute to the strategic vulnerability management roadmap and collaborate with customers and strategic partners on vulnerability research projects that advance collective defense.
  • Mentor other researchers and penetration testers while communicating Dragos expertise through public reporting, industry presentations, and engagement with the security community.
  • Champion the adoption of automated vulnerability analysis tools and processes to scale research capabilities and optimize team workflows.

Qualifications :

  • 5+ years developing, deploying, or evaluating proof-of-concept code related to vulnerabilities.
  • Demonstrable expertise in embedded systems reverse engineering or binary reverse engineering of Windows and/or embedded applications.
  • Strong familiarity with binary network protocols and low-level networking concepts.
  • 3+ years writing customer-facing technical material and demonstrated ability to translate complex details to inform decision-makers and operators.
  • In-depth understanding of vulnerability scoring mechanisms, their benefits and limitations in OT context, and measured ability to assess real-world operational impact.
  • Proven ability to function independently to identify devices and software to assess, determine acquisition strategies, and develop analysis roadmaps.
  • Demonstrated proficiency developing software tooling or analytical automation using Python, C#, or similar languages to enhance team workflows and scale research.

Nice to Haves :

  • Experience reverse engineering malware using static and dynamic analysis tools and techniques, with familiarity of malware code constructs.
  • Experience developing YARA, Snort, Suricata or Zeek detections rules.
  • Experience working with an operations center and incident response team during live engagements.
  • Track record of discovering and responsibly disclosing novel vulnerabilities.
  • Familiarity with ICS protocols (Modbus, DNP3, Profibus, etc.) and their security properties.
  • External presence or track record of knowledge sharing through publications, conference presentations, or industry engagement.

Compensation :

  • Salary: $200,000
  • Competitive Equity Package
  • Comprehensive Benefits Plan

#LI-JF1 #LI-REMOTE

Dragos is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, state, or local laws. All new hires must pass a background check as a condition of employment.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Principal Vulnerability Analyst in Remote vacancy
  • $75k

     ...Job Posting Title: Cybersecurity Threat and Vulnerability Analyst ---- Hiring Department: Information Security Office ---- Position Open To: All Applicants ---- Weekly Scheduled Hours: 40---- FLSA Status: Exempt from FLSA ---- Earliest Start Date:... 
    Suggested
    Full time
    For contractors
    Work at office
    Immediate start
    Remote work
    Flexible hours

    University of Texas at Austin

    Oregon State
    1 day ago
  • $86.8k - $198k

    Enterprise Cybersecurity Vulnerability Analyst, SeniorThe Opportunity:Support Booz Allen Hamilton's internal Enterprise Cybersecurity team by utilizing enterprise-level vulnerability scanning and assessment tools to identify internally and externally facing vulnerabilities... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    1 day ago
  •  ...required; US Citizenship preferred*Remote Position TBD*Applicants residing in the DMV area preferred as the client is located in Silver Spring, MD*Three references requiredPOSITION DESCRIPTION:The Principal Systems Analyst will provide senior-level analytical and s...... 
    Principal
    Remote work

    Think Tank Inc

    Silver Spring, MD
    5 days ago
  • $221.2k - $387.1k

     ...connected assets with the least possible impact on operations, and shifts the perception of security from blocker to enabler.Role As Principal Engineer for AI Security Governance, you will own the technical strategy, architecture, and hands-on delivery of the program end... 
    Principal
    Permanent employment
    Work at office
    Immediate start
    Remote work
    Flexible hours
    Shift work

    ServiceNow

    Kirkland, WA
    1 day ago
  •  ...Position Title Vulnerability Assessment Analyst and Penetration Tester Position Classification Exempt Position Type This position is full-time and generally follows standard business hours. The employee’s work schedule and hours may vary based on customer... 
    Suggested
    Full time
    Contract work
    For contractors
    For subcontractor
    Work at office
    Local area
    Remote work

    Lumbee Tribe Holdings, Inc.

    Sacramento, CA
    1 day ago
  •  ...Information Risk Strategy Management Vulnerability Management Role This position supports the Information Risk Strategy Management (IRSM) Vulnerability Management (VM) program reporting to the Vulnerability Management Team Lead. Responsibilities include managing the... 
    Remote work

    Software Technology Inc

    Houston, TX
    2 days ago
  • Block Pay Information Block takes a market-based approach to pay, and pay may vary depending on your location. U.S. locations are categorized into one of four zones based on a cost of labor index for that geographic area. The successful candidate's starting pay will...
    Principal
    Remote work

    Block | Square

    United States
    4 days ago
  • $401k

     ...a robust security culture.About the RoleOpenAI is seeking a Principal Security Engineer to join our Infrastructure Security (InfraSec...  ...of security principles, best practices, and common vulnerabilities, including strong security judgment under ambiguityA proactive... 
    Principal
    Work at office
    Local area
    Remote work
    Flexible hours

    OpenAI

    San Francisco, CA
    4 days ago
  • The University of Texas at Austin is seeking a Cybersecurity Threat and Vulnerability Analyst to join the Information Security Office. You will collaborate with risk management engineers to evaluate daily threats, develop response protocols, and publish vulnerability assessments... 
    Remote job
    Work at office

    The University of Texas at Austin

    Austin, TX
    2 days ago
  • The University of Texas at Austin seeks a Cybersecurity Threat and Vulnerability Analyst to join the Information Security Office. The role is on UT's main campus with remote work options and requires 40 hours per week, exempt status, and immediate start. Work involves assessing... 
    Remote job
    Work at office
    Immediate start

    Phase2 Technology

    Austin, TX
    2 days ago
  •  ...defined problem space. We bring Public and Private, Civilian and Military expertise to every case. We are hiring a System Vulnerability Analyst to work in the Fort Meade, MD vicinity. Position location is subject to change based on central MD client's needs.... 
    Full time
    Local area
    Work from home
    Flexible hours

    Themis Insight

    Maryland, MD
    a month ago
  •  ...of requirements and acceptance criteria.Mentors junior product analysts and developers on systems analysis techniques and business...  ...foreign education equivalent) and five (5) years of experience as a Principal Systems Analyst (or closely related occupation) performing... 
    Principal
    Full time

    Fidelity Investments

    Texas
    1 day ago
  •  ...Title: Cyber Risk Analyst W-2 Only (no 1099) Must be a U.S. Citizen Company's Location: Lemont, IL Job Description Background...  ...education and awareness, cybersecurity incident management, vulnerability management, compliance, and cybersecurity risk management.... 
    Full time
    Contract work
    For contractors
    Work at office
    Remote work
    Flexible hours

    Delan Associates Inc

    Lemont, IL
    1 day ago
  •  ...Services, LLC. (BGS) has created this Evergreen Talent Pool post for gathering qualified candidates for a position relating to Vulnerability Analyst which would support our clients. BGS is an engineering, technology, and security firm helping to advance missions of... 
    Full time
    Temporary work
    Remote work
    Monday to Friday

    Boston Government Services

    Oak Ridge, TN
    3 days ago
  • $153k - $207k

     ...environments. JOB DESCRIPTION Iron EagleX is seeking a Senior Principal Cyber Network Analyst to join our fast-paced technical team. In this role,...  ...pathways to identify relationships, dependencies, vulnerabilities, and potential operational access paths. Perform packet... 
    Principal
    Contract work
    Temporary work
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    General Dynamics Information Technology

    Arlington, VA
    4 days ago
  •  ...Seeking a Principal Security Architect to join the Cybersecurity organization in a full-time remote or Austin-based role, responsible for establishing a mature cybersecurity architecture practice, producing holistic architectures, and bridging the gap between design and... 
    Principal
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    4 days ago
  •  ...Principal Systems Analyst Are you interested in serving the needs of millions of customers in tax efficient savings, protection and guaranteed income in retirement? Fidelity Investments Life Insurance (FILI) Technology team in Personal Investing is seeking a hardworking... 
    Principal
    Work at office
    Work from home

    Samprasoft

    Durham, NC
    2 days ago
  •  ...remote and can be hired anywhere in the continental U.S.The Principal AI Advisor, Center of Excellence plays a critical role in serving...  ...understanding of the current threat landscape, vulnerabilities, and defensive controls as it pertains to AIStrong business and... 
    Principal
    Full time
    Local area
    Remote work
    Work from home

    Optiv

    Oklahoma City, OK
    4 days ago
  •  ...Principal Security Architect We are seeking a Principal Security Architect to lead the design, review, and evolution of secure technology...  ...leader, driving architecture strategy, advancing IAM, EDR, Vulnerability Management, and Zero Trust initiatives, and partnering with... 
    Principal
    Work at office
    Local area
    Remote work

    Advance Auto Parts

    Raleigh, NC
    3 days ago
  • $220k

     ...Type: Direct Hire • Posted: 1 week agoPrincipal Security Architect - Enterprise SecurityOur client is seeking a highly experienced Principal Security Architect to define and advance enterprise security architecture, standards, and long-term strategy. This is a senior... 
    Principal
    Local area
    Remote work
    Visa sponsorship

    Irvine Technology

    Dallas, TX
    4 days ago
  •  ...supporting a U.S. Government customer to provide cybersecurity vulnerability analysis support to reduce the prevalence and impact of...  ...Infrastructure Key Resources (CIKR). The Cybersecurity Vulnerability Analyst utilizes cybersecurity best practices, risk management... 

    Node.Digital LLC

    Arlington, VA
    4 days ago
  • $147.39k - $245.66k

     ...Overview:Information Security is essential to what we do at LPL, from protecting our employees, our advisors and their clients. As a Principal Business Information Security Officer (BISO) you will join a growing organization responsible for securing our advisors and their... 
    Principal
    Full time
    Work from home

    LPL Financial

    Fort Mill, York County, SC
    3 days ago
  • $131.3k - $237.35k

     ...strategy across cloud environmentsLead Authority to Operate (ATO) planning and execution activitiesConduct threat modeling and vulnerability assessments across platform componentsDesign and implement zero trust architecture principles across the enterpriseEstablish and... 
    Principal
    Full time
    Remote work

    Leidos

    Eagan, MN
    2 days ago
  •  ...To support a growing cloud-native networking platform, the full-time remote Principal Security Engineer will shape and drive security strategy across various domains, influence secure system design, and lead complex security initiatives. Key responsibilities Define and... 
    Principal
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    19 hours ago
  • $118.69k - $189.91k

     ...alternative technology to help address business requirements, problems or issues. Review documents and models produced by Business Analysts, Architects, and Developers to ensure end to end quality of the product. Support program and portfolio management goals through... 
    Principal
    Full time
    Work at office
    Local area
    Remote work
    Flexible hours
    2 days per week

    Blue Cross and Blue Shield of North Carolina

    Durham, NC
    2 days ago
  • $111.84k - $139.8k

     ...innovation that matters and a chance to learn, effect change, and make meaningful contributions at work and in communities. ​The Principal OT Security Engineer defines enterprise OT cybersecurity strategy, architecture, and a technical roadmap, leading complex initiatives... 
    Principal
    Full time
    Work experience placement
    Work at office
    Remote work

    Donaldson company

    Bloomington, MN
    1 day ago
  • This position will be fully remote and can be hired anywhere in the continental U.S.The Principal Cybersecurity Advisor serves as a senior technical leader within Optiv's Cisco Center of Excellence. This individual brings broad, current experience across Cisco enterprise... 
    Principal
    Full time
    Local area
    Remote work
    Work from home

    Optiv

    Milwaukee, WI
    1 day ago
  • $182.71k - $274.07k

    Citrix is seeking a Principal Security Technology Strategist to enhance cybersecurity solutions across North America. This role involves working closely with customers, evaluating their security needs, and driving adoption of Citrix products. The ideal candidate has over... 
    Principal
    Remote work

    Citrix

    Florida, NY
    2 days ago
  • $182.71k - $274.07k

    Citrix is looking for a Principal Security Technology Strategist to enhance customer engagements in North America. This role requires strong cybersecurity expertise and communication skills to assist customers in improving their security posture using Citrix’s solutions... 
    Principal
    Remote work

    Citrix

    New York, NY
    4 days ago
  •  ...Seeking a full-time Principal Cyber Security Engineer focused on agentic identity and security, this hands-on role will architect and build security features for AI agents across diverse environments while collaborating with various teams to bring innovative solutions... 
    Principal
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Principal Vulnerability Analyst. Be the first to apply!