SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 100,000 - 258,000 / annual
xAI is seeking a Vulnerability Analyst to join its Vulnerability Management team, responsible for assessing and mitigating security risks across the organization's portfolio. This role focuses on vulnerability analysis, risk assessment, and automation to protect against emerging threats.
You will evaluate vulnerabilities and determine their impact using industry standards, working closely with cross-functional teams to improve security posture. Key responsibilities include:
• Conducting vulnerability assessments using the CVSS standard (First.org)
• Understanding and implementing vector strings and vector chaining for risk evaluation
• Performing data analysis to assess security risks across the organization
• Identifying vulnerability reachability and impact to prioritize security responses
• Writing Python scripts to manage and manipulate data from CSV, Excel, JSON, and RESTful APIs
• Applying MITRE ATT&CK framework for attack path analysis
• Creating data reporting solutions, including dashboards
• Engaging with stakeholders to ensure security buy-in
• Demonstrating strong critical analysis, problem-solving, and security expertise
xAI operates with a flat organizational structure where all employees are hands-on contributors. The team is small, highly motivated, and focused on engineering excellence. Leadership is given to those who show initiative and deliver excellence. Strong work ethic, prioritization skills, and communication abilities are essential.
REQUIREMENTS:
• Mastery of CVSS and its environmental processing
• Expertise in Python for security data manipulation
• Strong understanding of vulnerability impact, risk assessment, and mitigation strategies
• Proficiency with MITRE ATT&CK framework for security analysis
• Experience creating dashboard-based reports to communicate security findings
• Excellent communication and stakeholder management skills
PREFERRED SKILLS:
• Experience with Elastic/OpenSearch
• Familiarity with Kibana/Grafana dashboarding
• Development of security automation playbooks
• Experience with AWS and/or GCP
• Experience building agentic workflows for vulnerability management
ITAR REQUIREMENT: Applicant must be a U.S. citizen or national, U.S. lawful permanent resident, Refugee, or Asylee, or be eligible to obtain required authorizations from the U.S. Department of State.