Security Analyst
Role summary
Decryption Digest is seeking a research-first Security Analyst to analyze active threats, CVEs, and breaches. This role involves understanding exploit mechanics, reproducing vulnerabilities, and translating complex technical findings into clear, actionable threat briefs. The analyst will also develop lightweight tools to support research and data collection. The ideal candidate has a strong technical understanding of vulnerabilities, excellent writing skills, and a passion for tracking real-world threats. Experience with web, API, or system-level security issues, code analysis, and hands-on validation is required. Preferred qualifications include reverse engineering, exploit development, and scripting.
About the Company
Decryption Digest is built for security teams that want signal, not noise. We track active threats across CVEs, ransomware, breaches, and threat actors. Then we break them down into clear, usable intelligence. Everything we publish answers one question: what does this mean, and what should you do next. We focus on speed, clarity, and real-world impact.
About the Role
This is a research-first security role with a strong writing component. As a Security Analyst, you will go beyond the headline of a vulnerability or breach. You will study how exploits work, how attackers use them, and why they matter in real environments. You will turn technical findings into clear, actionable threat briefs for Decryption Digest. You will also build simple tools and scripts to support your research and improve how we track threats.
Responsibilities
- Analyze new CVEs and explain root cause and exploit paths
- Review proof-of-concepts and validate how they work
- Reproduce vulnerabilities in lab environments when needed
- Track how vulnerabilities are used in the wild
- Turn research into clear, concise threat articles
- Break down complex technical issues into practical guidance
- Build lightweight tools to support research and data collection
- Identify patterns across vulnerabilities and attacker behavior
Qualifications
- Strong understanding of how vulnerabilities work at a technical level
Required Skills
- Experience with web, API, or system-level security issues
- Ability to read code and understand exploit logic
- Hands-on approach. You test and validate, not just read
- Clear writing skills with a focus on simplicity and accuracy
- Ability to explain complex topics in plain English
- Strong interest in tracking active threats
Preferred Skills
- Experience with reverse engineering or exploit development
- Familiarity with CVE analysis, KEV, and vulnerability scoring
- Experience building lab environments for exploit testing
- Scripting experience in Python, Bash, or similar
- Background in research, red team, or application security
Pay range and compensation package
We offer competitive pay that reflects your experience and the impact of your work, along with the chance to shape how real-world threats are understood and acted on.
Equal Opportunity Statement
We are committed to building a diverse and inclusive team.
Similar roles
- Security AnalystMjolnir Security · Toronto, Ontario, Canada · Hybrid
Security AnalystExperis Canada · Canada · Remote
Security AnalystCanada's Wonderland · Ontario, Canada · Onsite
Security AnalystCanada's Wonderland · Ontario, Canada · Onsite- Senior Security AnalystAMSYS Innovative Solutions · Canonsburg, Pennsylvania, United States · Onsite