Vulnerability Researcher jobs in United States
cer-icon
Apply on Employer Site
company-logo

Delta Dental Ins. · 11 hours ago

Vulnerability Researcher

Delta Dental Ins. is dedicated to safeguarding the health and financial stability of its employees and their families. They are seeking a Vulnerability Researcher who will analyze systems and software to discover vulnerabilities, conduct vulnerability assessments, and develop testing methodologies while maintaining communication with management and stakeholders.

HealthcareProperty & Casualty InsuranceHealth InsuranceHealth CareInsurance
badNo H1Bnote

Responsibilities

Conducts research to identify highly impactful, unknown vulnerabilities in a wide variety of applications and technologies, including AI-enabled applications and services
Performs vulnerability assessments using industry best practices on various environments, including web applications, APIs, and cloud infrastructure
Develops and manages testing methodologies that adhere to common security guidelines and NIST standards
Conducts an evaluation of cloud security configurations, identifies prevalent vulnerabilities in cloud security controls, and improves and maintains cloud testing standards
Provides detailed reports with proof of vulnerabilities, guidance, and advice to support customer teams through vulnerability remediation
Develops and communicates comprehensive and accurate reports and presentations for client stakeholders including technical staff and executive leadership
Maintains communication with management regarding development within assigned responsibilities and performs special projects as required
Researches and develops innovative techniques, tools, and methodologies for vulnerability research and red team activities
Develops leadership-level communications, including management-specific metrics, white papers, procedures, thought position papers, etc
This list is not all-inclusive, and you are expected to perform other cybersecurity-congruent duties as requested or assigned

Qualification

Cyber SecurityVulnerability AssessmentPenetration TestingBinary AnalysisCustom Tool DevelopmentAdversary EmulationSecurity MethodologiesProgramming LanguagesAnalytical SkillsTechnical WritingTeam CollaborationProblem-Solving

Required

7+ years of work experience in the Cyber Security industry
Bachelor's Degree in Computer Science or Management Information related field, or equivalent work experience
Understanding of all phases of adversary emulation operations including reconnaissance, social engineering, exploitation, post-exploitation, covert techniques, lateral movement, and data exfiltration
Extensive experience in offensive cybersecurity roles, such as red teaming, penetration testing (e.g., web, infrastructure, cloud), and purple team exercises in cloud and on-prem environments
A robust understanding of contemporary security theory and application exploitation techniques and attack vectors (including the vulnerability lifecycle and scanning methodologies (SAST, DAST, IAST, RASP))
Experience developing and managing testing methodologies that adhere to common security guidelines such as OWASP and frameworks such NIST 800 or MITRE ATT&CK
A solid understanding of computer architecture and organization with respect to binary analysis and exploitation
Ability to analyze, create, and debug shellcode and other low-level exploits
Experience developing custom security (either offensive or defensive) software in one or more compiled languages
Demonstrated abilities to reverse engineer binaries, enumerate vulnerabilities in compiled software, and provide working exploits (e.g., CVEs, public acknowledgements, or ability to demonstrate on demand)
Familiarity with automated security analysis and fuzzing tools (e.g., AFL and Peach)
Demonstrated ability to discover vulnerabilities via static analysis and source code review
A working understanding of key programming languages and frameworks (e.g., Java, Node.js, Python, JSP, etc.), including the ability to pick up new languages quickly, understand the security implications of those languages, and enumerate vulnerabilities in custom-developed software packages that leverage those languages
Familiarity with scripting/programming of Python, PowerShell, or C# with the ability to create and customize tools
Excellent written and verbal communication skills (technical writing, documentation development, process mapping, and visualization)
Must be able to communicate technical concepts to technical and non-technical audiences effectively and communicate well with people in various positions, roles, and levels
Strong analytical and problem-solving skills; ability to examine issues strategically and analytically
Ability to interact well with co-workers and outside contacts; ability to work collaboratively in a team environment
Ability to work on multiple, simultaneous initiatives and prioritize workload to meet commitments
Self-motivated with a strong sense of urgency, an adaptive mindset, and a demonstrated propensity to learn quickly

Benefits

Competitive base and incentive pay
401(k) with robust matching and non-matching contributions
Rich medical & pharmacy benefits
100% employer-paid dental and vision benefits
Holistic wellbeing program with deep financial incentives
Generous paid time off plus 12 paid holidays and your birthday off
Culture of growth and learning: career development; tuition reimbursement; recognition program
Family support: adoption assistance, fertility treatment, child, elder & pet care assistance
Social responsibility and volunteer opportunities
Employee discount program

Company

Delta Dental Ins.

twittertwittertwitter
company-logo
At Delta Dental, we’re behind millions of smiles and counting.

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
Ed Goldman
VP, Infrastructure & Operations
linkedin
Company data provided by crunchbase