
About VulnCheck
Exploitation prevention is only as strong as the intelligence driving those efforts, and most of the industry is still running on intelligence that lacks exploit context. VulnCheck, The Exploit Intelligence Company, delivers structured exploit intelligence on what is actively weaponized in the wild, purpose-built for the data lakes, ETL pipelines, automation, and AI and LLM workflows your infrastructure already runs on, raising the capability of everything it powers.
About the Role
VulnCheck is looking for a Senior Exploit Developer with a background in reverse engineering and exploit development. This role is on our Initial Access Intelligence team, which delivers exploits and related artifacts designed to give VulnCheck customers visibility into exploitation from exposure through execution and detection. You’ll work with a seasoned team of hackers and threat researchers to help global enterprises, governments, and intelligence firms defend against emerging threats and get ahead of the attacker curve.
While initial access vulnerabilities are our main focus area, you’ll also have the opportunity to work on a variety of local and other exploits, as well as our open-source go-exploit framework. This is a 100% remote role, primarily looking for candidates in Cheltenham, United Kingdom.
Why Join VulnCheck?
- Leverage your expertise: Work on cutting-edge threat intelligence initiatives that matter, alongside the top domain experts in the field.
- Shape the industry: Influence how vulnerabilities are classified, scored, mapped, and remediated at scale for enterprise customers and for the entire cybersecurity industry.
- Grow your impact: Collaborate with global partners, lead high-visibility projects, and drive standards across the security community.
- Innovate and explore: Conduct research and develop tools for automating and improving vulnerability enrichment and mapping.
What You'll Do
- Reverse engineering software to discover the root cause analysis (RCA) of vulnerabilities.
- Authoring original software exploits for initial access vulnerabilities, when little or no publicly-available proof of concept code for exploiting such vulnerabilities exists.
- Implementing detections (such as Suricata & Snort signatures, YARA rules, etc.) for identifying such initial access vulnerabilities being exploited on the wire.
- Writing Attack Surface Management (ASM) queries (e.g., Shodan, Census, FOFA, & ZoomEye) for finding vulnerable systems likely to be targeted.
What You'll Bring
- Prior experience with writing exploit code for RCE / initial access vulnerabilities (that do not require authentication to exploit).
- Experience working on technical projects remotely, alone, and on small teams.
Preferred Qualifications
- Prior Cybersecurity work experience (at a vendor or in Government).
- Able to share example exploit code written.
Note: This position may involve access to technology subject to U.S. export control regulations. Employment is contingent upon the company's ability to authorize access under applicable export control and sanctions requirements.
Benefits and Perks
- Competitive salary with employee equity program
- Health, dental, and vision coverage
- Unlimited PTO
- Pension Contribution
- Remote friendly environment with flexibility
- Expense reimbursement for home internet and phone
- Ongoing professional development, coaching, and learning resources
- Opportunities for career advancement within a fast-growing team
Timezone overlap
UTC+0–+3
Open to
UK · Cheltenham · United Kingdom
Sign in to track applications and earn points.