Staff Research Engineer - Exposure Intelligence

Tenable, Inc.•Columbia, MD
•$137,500 - $183,500•Hybrid

About The Position

Tenable's Research Special Operations (RSO) team produces the exposure intelligence and analysis that helps organizations understand and prioritize cyber risk. We translate what's happening in the global threat landscape into structured, actionable intelligence for SOC analysts, vulnerability management engineers, field teams, and CISO-level stakeholders. We're looking for a Staff Research Engineer who will be primarily responsible for executing the daily intelligence production cycle for our Exposure Intelligence function. You'll run the morning production cycle; sourcing, triaging, classifying, analyzing, and publishing finished intelligence in collaboration with other team members. On a typical day you might assess a newly disclosed zero-day, determine whether it warrants a full analytical workup, write the daily brief that informs operational priorities, and publish an external digest consumed by hundreds of stakeholders, then shift to deeper analytical work, framework development, or external content in the afternoon. This isn't a traditional security research role. The work blends intelligence analysis, production discipline, and analytical writing on a daily cadence. The right candidate can context-switch between operational triage and deep analysis, writes clearly and concisely to deliver time-sensitive deliverables, and treats repeatable process as a feature rather than a constraint.

Requirements

  • 7+ years in cybersecurity: with meaningful depth in at least two of: vulnerability research, threat intelligence analysis, security operations, or exposure/risk management.
  • Experience producing structured analytical intelligence: Beyond just advisories or blog posts, including multi-source assessments with confidence ratings and documented methodology.
  • Deep familiarity with the vulnerability lifecycle: Understanding the state of a vulnerability from disclosure through exploitation. Understanding CVSS scoring, exploit maturity, CISA KEV, and the difference between a vulnerability existing and an exposure being actively exploited in the wild.
  • Strong understanding of threat actors and campaigns: attribution frameworks, TTP mapping (MITRE ATT&CK), and the ability to classify threats at the right level without inflation.
  • Excellent analytical writing and verbal communication skills: This role produces significant written output daily including threat briefs, assessments, digests and blog posts.
  • Comfort with structured, repeatable processes: This role involves executing within a structured and governed production cycle with quality gates and standards, not just ad hoc research.
  • Sound judgment under uncertainty: Rapid analytical decisions with incomplete information, with honest confidence calibration. This role requires the ability to work independently and make informed decisions with accuracy and precision.
  • Ability to manage multiple concurrent workstreams and shifting priorities.
  • Applicants must be authorized to work for any employer in the U.S. without sponsorship.

Nice To Haves

  • Intelligence community or military intelligence background including structured analytic techniques, source reliability assessment, analytic confidence frameworks.
  • Experience in vulnerability management programs at scale, and understanding of what SOC teams actually need from threat intelligence to prioritize.
  • Familiarity with exposure management concepts with an understanding of the shift from vulnerability-centric to exposure-centric risk management, including cloud, identity, and OT/IoT.
  • Experience with AI-assisted analytical workflows. The team uses AI extensively as an analytical co-pilot.
  • Scripting and automation skills (Python, Bash, or similar) for data processing and tooling. This is not a software engineering role, but the ability to work with APIs and automate tasks is valuable.
  • Demonstrated experience writing for external audiences including blog posts, conference talks, media interviews and technical papers.
  • Experience with Tenable products (Tenable One, Nessus, Security Center) or competitive vulnerability management platforms.
  • Familiarity with exposure surface analysis tools (Shodan, Censys, GreyNoise) and OSINT techniques.
  • Experience with production tracking systems (Jira, Confluence) in a daily-cadence operational context.
  • Background in non-CVE exposure domains (e.g., cloud security, identity and credential exposure, shadow AI, OT/IoT).

Responsibilities

  • Executing the operational aspects of the Security Response process, including monitoring a broad source ecosystem, triaging, and producing the daily operations brief and an external intelligence digest.
  • Making fast, well-calibrated decisions, often with incomplete or imperfect information, and communicating those decisions clearly to the rest of the Research team and to leadership.
  • Applying structured analytical judgment to response decisions, assessing exploit maturity, likely attacker interest, and blast radius with clear confidence calibration.
  • Producing deeper analytical products including threat assessments with confidence ratings and documented methodology, actor and campaign profiles, and focused analytical notes on individual CVEs or exposure conditions.
  • Writing blog posts for the Tenable blog, coordinating with public relations and product marketing on media responses, and contributing to webinars and conference presentations.
  • Providing input into the classification standards, analytical methodologies, and source management practices that underpin the team's work.
  • Identifying opportunities for improvement based on experience executing the daily production cycle and collaborating with other team members on evolving these capabilities, including AI-assisted workflows.
  • Contributing to development and execution of the team's strategic priorities.
  • Responding to internal intelligence requests from product teams and leadership.
  • Collaborating with stakeholders to understand their intelligence needs and bringing those perspectives back to the team to help inform analytical priorities and areas of focus beyond daily response work.

Benefits

  • medical, dental, vision, disability and life insurance
  • 401(k) retirement savings with company match
  • an employee stock purchase plan
  • an employee referral program
  • flexible spending accounts
  • an Employee Assistance Program (EAP)
  • education assistance
  • parental leave
  • paid time off (PTO)
  • company-paid holidays
  • health and wellness events
  • community programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service