368,657open jobs
9,442companies
50,883added this week
Browse all
Salary
$200k per year
Location
Remote (United States)
Seniority
Principal · 5+ years exp
Overview
Company
Impact
Profile match
Secure your critical infrastructure with Dragos, our industrial cybersecurity solutions provide unmatched visibility and threat detection for OT environments.

At Dragos, the mission is personal. The systems we protect deliver the water you drink, power your home, and keep the hospitals your community depends on running. Those critical infrastructure systems that power our civilization around the world are under attack every day by adversaries. When those systems fail, people are immediately at risk. We are the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. The people here chose this work because they understand what is at stake. Here, you will find a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust. If safeguarding the systems that protect your family, friends, and community is the kind of work that matters to you, you are in the right place. 

About the Role

Dragos' Vulnerability Analysis team identifies novel security gaps in the industrial control systems that power plants, water utilities, and manufacturing facilities depend on-and translates those findings into detections and actionable intelligence that defend critical infrastructure. As a Principal Vulnerability Analyst, you'll operate with high autonomy to identify research targets, perform in-depth vulnerability analysis, coordinate with affected vendors, and author vulnerability reports that shape how the industry understands emerging threats. You'll partner across threat intelligence, product engineering, and incident response teams to amplify the real-world impact of your work. Working alongside another vulnerability analyst, you'll serve as a recognized subject matter expert and trusted internal resource-mentoring researchers and penetration testers, driving methodology development, and helping identify gaps in the Dragos Platform's ability to detect new exploits.

Responsibilities

  • Identify novel vulnerabilities in industrial products and control systems through strategic acquisition and rigorous analysis, assessing operational impact on both IT and ICS environments.
  • Coordinate responsible disclosure with affected vendors and author clear, technically rigorous vulnerability reports for internal customers and public publication.
  • Develop detection signatures (Suricata, YARA, internal analytics) and partner with product engineering to identify and close gaps in the Dragos Platform's vulnerability detection capabilities.
  • Serve as a trusted internal resource to threat intelligence and incident response teams, assessing in-the-wild exploits, analyzing vulnerability trends, and integrating findings into broader threat intelligence.
  • Contribute to the strategic vulnerability management roadmap and collaborate with customers and strategic partners on vulnerability research projects that advance collective defense.
  • Mentor other researchers and penetration testers while communicating Dragos expertise through public reporting, industry presentations, and engagement with the security community.
  • Champion the adoption of automated vulnerability analysis tools and processes to scale research capabilities and optimize team workflows.

Qualifications

  • 5+ years developing, deploying, or evaluating proof-of-concept code related to vulnerabilities.
  • Demonstrable expertise in embedded systems reverse engineering or binary reverse engineering of Windows and/or embedded applications.
  • Strong familiarity with binary network protocols and low-level networking concepts.
  • 3+ years writing customer-facing technical material and demonstrated ability to translate complex details to inform decision-makers and operators.
  • In-depth understanding of vulnerability scoring mechanisms, their benefits and limitations in OT context, and measured ability to assess real-world operational impact.
  • Proven ability to function independently to identify devices and software to assess, determine acquisition strategies, and develop analysis roadmaps.
  • Demonstrated proficiency developing software tooling or analytical automation using Python, C#, or similar languages to enhance team workflows and scale research.

Nice to Haves:

  • Experience reverse engineering malware using static and dynamic analysis tools and techniques, with familiarity of malware code constructs.
  • Experience developing YARA, Snort, Suricata or Zeek detections rules.
  • Experience working with an operations center and incident response team during live engagements.
  • Track record of discovering and responsibly disclosing novel vulnerabilities.
  • Familiarity with ICS protocols (Modbus, DNP3, Profibus, etc.) and their security properties.
  • External presence or track record of knowledge sharing through publications, conference presentations, or industry engagement. 

Compensation

  • Salary: $200,000
  • Competitive Equity Package  
  • Comprehensive Benefits Plan 

#LI-JF1 #LI-REMOTE  

Dragos is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, state, or local laws. All new hires must pass a background check as a condition of employment.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,657 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$111k – $200k per year (Estimated) • In office • Full-Time • 1+ year exp • Plano
JavaScript
Python
C#
C#
.NET
DevOps
Azure
CI/CD
Apply
$71k – $112k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Austria
C#
C++
Python
Visual Basic
Apply
$122k – $200k per year • In office • Full-Time • 10+ years exp • Jersey City • Charlotte
Java
Node JS
Python
SQL
JavaScript
Java
Hibernate
Spring Framework
Spring MVC
Databases
Apache Kafka
DynamoDB
Oracle
RabbitMQ
AI/ML
Ray
DevOps
Amazon CloudWatch
Amazon EC2
Amazon ECS
Amazon EKS
Amazon S3
Ansible
API Gateway
AWS
AWS Lambda
Azure
CI/CD
CloudFormation
GCP
Git
Grafana
IAM
Jenkins
Prometheus
Splunk
Terraform
Kubernetes
Apply
$106k – $149k per year • Remote/Hybrid • Full-Time • 7+ years exp • Bachelor's Degree • Overland Park
Python
SQL
Databases
Amazon Redshift
Analytics
Power BI
Tableau
Marketing
Salesforce
Apply
$96k – $218k per year (Estimated) • Equity • In office • Full-Time • 8+ years exp • Toronto
Python
Databases
Databricks
Snowflake
AI/ML
AI Agents
AWS Bedrock
AWS Bedrock AgentCore
LLM
LLM Evaluation
DevOps
AWS
CI/CD
GCP
Apply
$165k per year • Equity • Remote/Hybrid • 5+ years exp • Norfolk
Cybersecurity
Threat Modeling
Apply
$165k per year • Equity • Remote • 5+ years exp
Python
Rust
DevOps
Ansible
AWS
Azure
CI/CD
Docker
GCP
GitHub Actions
GitLab CI
Grafana
Jenkins
Kubernetes
Prometheus
Terraform
GitHub
GitLab
Apply
$166k per year • Equity • Remote • 5+ years exp
Apply
$166k per year • Equity • Remote • 5+ years exp
Apply
$166k per year • Equity • Remote • 5+ years exp
DevOps
AWS
Azure
GCP
Apply
See all jobs
This is one of many
368,657 more open roles from verified company boards, updated every day.