Lead Vulnerability Intelligence Analyst (Europe or LATAM, Remote)
- Hiring from
- Europe, Latin America
- Work type
- Remote
- Posted
- Oct 2, 2026
Company Overview:
Intel 471 empowers enterprises, government agencies, and other organizations to win the cybersecurity war using near-real-time insights into the latest malicious actors, relationships, threat patterns, and imminent attacks relevant to their businesses. Founded in 2014, Intel 471 provides comprehensive intelligence and monitoring on threat actors. The company’s centralized TITAN platform enables intelligence and security professionals to access structured information, dashboards, timely alerts and intelligence reporting via web portal or API integration.
Our pedigree is unmatched and we count upon a team with experience operating in the intelligence services, military, law enforcement and private threat intelligence companies in nearly every continent on earth.
The Role:
You own the technical depth of our vulnerability intelligence practice. When a new CVE drops, you're the person who determines what's actually true and decides what our customers should do about it.
This is a team lead role where you'll set the technical standard for how we validate, assess, and communicate vulnerability risk. You'll also build and maintain the tooling that lets a small team cover the ever-growing world of vulnerability research.
What You'll Do:
Design, build, and deploy honeypot systems to monitor for exploitation activity. Acquire, test, and validate proof-of-concept exploits in virtual environments to confirm or refute claims about exploitability. Develop practical mitigations for cases where patching is delayed, impossible, or insufficient. These mitigations could include configuration hardening, network segmentation, ACLs, disabling features, or other controls. You'll devise techniques for detecting both attempted and successful exploitation by illuminating the artifacts defenders should hunt for. You'll write vulnerability reports that dive into the details about an exploit such as how it works, who is using it and who is being targeted. Automation is a key component of the role; you will build and maintain the systems we use to streamline vulnerability assessment and automate triage of vulnerability alerts.
Required Qualifications:
Every candidate must be able to:
- Validate and test PoCs to verify the validity of exploitation claims.
- Devise mitigation techniques beyond patching.
- Devise techniques for detecting exploit activity, attempted or successful.
- Write vulnerability reports such as Vulnerability Spotlights.
- Identify new sources of vulnerability intelligence.
- Train and mentor junior team members.
Technical foundation:
- Proficiency with at least one programming language (Python, Go, C/C++, or similar) sufficient to read exploit code, modify PoCs, and build tooling.
- Hands-on fluency with virtual machines, containers, and re-usable lab environments for safe detonation and analysis.
- Solid computer science fundamentals.
- Thorough understanding of computing and internet fundamentals: TCP/IP, HTTP, DNS, TLS, authentication and authorization models, and how real systems are actually deployed.
- Demonstrated subject-matter-expert-level depth.
- A working bias toward automation.
Strong candidates additionally bring:
- Experience building honeypot or sensor systems to monitor real-world exploitation activity.
- Experience building systems that streamline or automate PoC testing and validation.
- Demonstrated ability to integrate a new intelligence source end-to-end, from evaluation and ingestion to normalization, enrichment and delivery.
Also valuable: original vulnerability research or CVE credits; reverse engineering skills; detection engineering (Sigma, Snort/Suricata, YARA); SOC experience; familiarity with CVSS, CWE, EPSS, and the KEV catalog; public speaking or published writing.
Benefits:
- Competitive compensation
- Remote-friendly culture
- Wellness programs
- A variety of professional development opportunities
- Inclusive culture focused on people, customers and innovation
Our Culture:
The Intel 471 team is constantly growing and is always on the lookout for talented professionals who seek to operate on the forefront of the fight against threat actors impacting our customers and partners. Our culture of humility and quiet professionalism is a core attribute of Intel 471 and everyone within it. Our culture is collaborative, supportive and fast-paced. We're a mission-driven company. We're looking for talented, 'can-do' minded people with a passion for always doing the right thing.
We believe in supporting a progressive culture that allows all our people to be themselves, enjoy exciting opportunities and grow with us. That's why our culture is founded on our core values of openness, inclusion, integrity and client focus, which set the tone for how we work together and treat each other in order to empower us all – and foster a unique team spirit.