Bitsight is a cyber risk management leader transforming how companies manage exposure, performance, and risk for themselves and their third parties. Companies rely on Bitsight to prioritize their cybersecurity investments, build greater trust within their ecosystem, and reduce their chances of financial loss.
Built on over a decade of technological innovation, its integrated solutions deliver value across enterprise security performance, digital supply chains, cyber insurance, and data analysis.
The Vulnerability Research team within Bitsight’s Security Research department develops and deploys techniques to remotely detect the presence of recently disclosed vulnerabilities. These techniques are integrated into the company’s Internet scanning infrastructure which enables Bitsight to measure the rate at which organizations patch and remediate vulnerabilities. This function is a critical input into Bitsight’s capability to assess the effectiveness of organizational security programs as well as the ability to identify third party vulnerability exposures in organizations’ digital supply chains. The team also enables a unique form of “vulnerability epidemiology” research in tracking the scale, impact, and organizational response for high-profile vulnerabilities. This role will work alongside an international team of vulnerability researchers in the research and development of new vulnerability detection and inference tools and techniques as well as the integration and operationalization of those techniques within Bitsight’s telemetry collection infrastructure.
Objectives & Responsibilities
Maintain situational awareness of newly published, high-profile vulnerabilities and contribute to the development of vulnerability intelligence tooling
Triage open source technical reporting to assess viability of remote, network-based detection methods for new vulnerabilities in alignment with Bitsight’s vulnerability prioritization framework
Reverse engineer software and software patches to identify new detection methods
Develop new python modules within Bitsight’s Internet scanning framework to implement newly researched vulnerability detection and product fingerprinting capabilities
Conduct peer review of teammate detection capabilities to provide feedback on potential improvements and to evaluate the intrusiveness of the capability in alignment with Bitsight’s vulnerability scanning risk management framework
Analyze Internet scan results to evaluate technique efficacy and ensure data quality of new detection capabilities
Contribute to tooling and infrastructure that enables the team to increase the scale and efficiency capability delivery
Collaborate with the Product Management team in the design of new vulnerability-related Bitsight product features
Qualifications:
Broad knowledge of information security principles and network protocols
Experience in network-based vulnerability detection capability development
Experience in source code analysis
Familiarity software reverse engineering and patch diffing
Strong communication and analytical skills, including the ability to identify and solve ambiguous problems
Ownership mindset
Proficient in python programming
Diversity. Bitsight is proud to be an equal opportunity employer. This means we do not tolerate discrimination of any kind and are committed to providing equal employment opportunities regardless of your gender identity, race, nationality, religion, sexual orientation, status as a protected veteran, or status as an individual with a disability.
Culture. We put our people first. Bitsight offers best in class benefits. We devote the same energy to nurturing our company's inclusive culture as we apply to serving our customers' needs. Working at Bitsight will give you the opportunity to fulfill your professional goals and expand your skills.
Open-minded. If you got to this point, we hope you’re feeling excited about the job description you just read. Even if you don’t feel that you meet every single requirement, we still encourage you to apply. We’re eager to meet people that believe in Bitsight’s mission and can contribute to our team in a variety of ways.
Additional Information for United States of America Applicants:
Bitsight also provides reasonable accommodations to qualified individuals with disabilities or based on a sincerely held religious belief in accordance with applicable laws. If you need to inquire about a reasonable accommodation, or need assistance with completing the application process, please email recruiting@bitsight.com. This contact information is for accommodation requests only, and cannot be used to inquire about the status of applications.
Qualified applicants with criminal histories will be considered for employment consistent with applicable law.
This position may be considered a promotional opportunity pursuant to the Colorado Equal Pay for Equal Work Act.
Innatera
Westat
Apollo.io
Eventbrite
Hyphen Connect