Dragos Logo

Dragos

Associate Principal Vulnerability Analyst

Posted 4 Days Ago
Be an Early Applicant
Easy Apply
Remote
Hiring Remotely in United States
145K-145K Annually
Senior level
Easy Apply
Remote
Hiring Remotely in United States
145K-145K Annually
Senior level
The Associate Principal Vulnerability Analyst will evaluate and curate vulnerability data, translate it into actionable intelligence, mentor team members, and lead process improvements to enhance cybersecurity for OT environments.
The summary above was generated by AI

Dragos is on a relentless mission to defend industrial organizations that provide us with the necessities of modern civilization; running water, functioning electricity, and safe industrial working environments. As the market leader in ICS/OT Cybersecurity, we are dedicated to arming our customers with best-in-class technology, threat intelligence, and services to protect their systems as effectively and efficiently as possible. We’re a remote-first culture with operations in North America, Europe, the Middle East, and APAC. We’re looking for mission-oriented teammates who embody our core values of authenticity, transparency, and trust. Are you ready to make a difference? Come join a mission that can save the world! 

About the Role:

Dragos is seeking an experienced Vulnerability Analyst to join our Vulnerability Analysis Content Team. In this position you will play a critical role in transforming vulnerability data from public sources into actionable intelligence tailored for operational technology (OT) environments. Working alongside a team of analysts and engineers, you will be responsible for evaluating, curating, enriching, and contextualizing vulnerability information from CVEs, NVD, vendor advisories, and various other sources to deliver high-quality findings to our customers. This role directly supports Dragos's mission to safeguard industrial infrastructure by producing timely, accurate, and OT-relevant vulnerability intelligence.

Responsibilities:  

  • Evaluate vulnerability disclosures from CVEs, NVD, KEV, CISA, vendor advisories, and other public sources to assess relevance and impact to OT environments.
  • Curate and prioritize vulnerability information based on asset criticality, exploitability, and operational impact to industrial systems.
  • Own the technical strategy for vulnerability content standards, including analysis methodologies, quality benchmarks, and content review.
  • Enrich vulnerability data by mapping affected products, firmware versions, and asset classifications to ensure comprehensive coverage.
  • Translate technical vulnerability details into actionable, OT-contextualized content for the Dragos platform, including advisories, asset mappings, and mitigation guidance.
  • Leverage platform telemetry and maintain product catalogs to identify detection gaps, prioritize coverage, and improve content accuracy.
  • Mentor junior and mid-level analysts, providing technical guidance and quality review of content outputs.
  • Lead cross-functional initiatives with engineering teams to improve content creation workflows, validation processes, and delivery pipelines.
  • Monitor emerging vulnerability sources and feeds to ensure timely coverage and identify gaps in existing content.
  • Drive continuous improvement of team processes, content standards, and analysis methodologies.

Qualifications:  

  • 6+ years of experience in vulnerability analysis, vulnerability management, or a related technical security discipline. 
  • 2+ years of hands-on experience with ICS/OT technologies, including PLCs, RTUs, HMIs, SCADA systems, or industrial networking protocols (Modbus, DNP3, EtherNet/IP, OPC, etc.).
  • Strong understanding of CVE lifecycle, CVSS scoring, CPE (Common Platform Enumeration), and vulnerability advisory interpretation.
  • Strong working knowledge of vulnerability databases, threat intelligence feeds, and security content platforms.
  • Demonstrated ability to map vulnerabilities to affected products, firmware versions, and asset inventories.
  • Proven ability to produce clear, accurate, and actionable technical content for diverse audiences.
  • Proficiency with git workflows, branching strategies, and code review processes.
  • Familiarity with command-line tooling and scripting languages (Python or similar) for workflow automation.
  • Strong communication and collaboration skills with the ability to mentor others and influence content quality standards.
  • Background in asset management, configuration management, or IT/OT inventory systems is beneficial.
  • Prior experience in critical infrastructure sectors (energy, manufacturing, water, transportation) is nice to have.

Compensation: 

  • Salary: $145,000
  • Competitive Equity Package
  • Comprehensive Benefits Plan 

 

#LI-JF1 #LI-REMOTE   



Dragos is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, state, or local laws. All new hires must pass a background check as a condition of employment.

Top Skills

Cve
Dnp3
Ethernet/Ip
Git
Hmis
Ics
Modbus
Nvd
Opc
Ot
Plcs
Python
Rtus
Scada

Similar Jobs

An Hour Ago
Remote or Hybrid
USA
145K-220K Annually
Expert/Leader
145K-220K Annually
Expert/Leader
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
The Technology Resilience Principal will lead resilience functions, driving strategies for technical resilience across systems, ensuring service reliability, and disaster recovery.
Top Skills: Application ResilienceChaos EngineeringCloud-Native EnvironmentsEnterprise Disaster RecoveryInfrastructure RedundancyMonitoring Platforms
An Hour Ago
Remote or Hybrid
USA
70K-110K Annually
Mid level
70K-110K Annually
Mid level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
The Insider Risk Analyst will develop vetting protocols, conduct background checks on elevated-risk candidates, analyze security risks, and enhance screening processes. Responsibilities include evaluating background check outcomes, preparing reports, and collaborating with security teams.
Top Skills: Open-Source Intelligence (Osint)
An Hour Ago
Remote or Hybrid
USA
140K-215K Annually
Senior level
140K-215K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
As a Security Engineer, assess and implement security measures for software supply chains, guide engineers on security risks, and manage security initiatives.
Top Skills: Argo CdArtifactoryBitbucketDatadogGitGoJavaScriptJenkinsLinuxLogscalePrometheusPythonS3ShellSplunkUnix

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account