--- title: 'Staff Research Engineer - Exposure Intelligence at Tenable, Inc.' canonical: 'https://feeny.ai/job/staff-research-engineer-exposure-intelligence-tenable-inc-boston-ytjqz4z7w3n1' type: 'job' last_seen: '2026-09-23' --- # Staff Research Engineer - Exposure Intelligence at Tenable, Inc. - **Company:** Tenable, Inc. - **Location:** Boston, MA / Columbia, MD - **Compensation:** $138k–$184k - **Work type:** hybrid - **Posted:** 2026-09-22 - **Last confirmed live:** 2026-09-23 - **Apply:** https://job-boards.greenhouse.io/tenableinc/jobs/5431539008 ## Job description Who is Tenable? Tenable® is the Exposure Management company. Over 40,000 organizations around the globe rely on Tenable to understand and reduce cyber risk. Our global employees support 65 percent of the Fortune 500, 50 percent of the Global 2000, and large government agencies. Come be part of our journey! What makes Tenable such a great place to work? Ask a member of our team and they’ll answer, “Our people!” We work together to build and innovate best-in-class cybersecurity solutions for our customers; all while creating a culture of belonging, respect, and excellence where we can be our best selves. When you’re part of our #OneTenable team, you can expect to partner with some of the most talented and passionate people in the industry, and have the support and resources you need to do work that truly matters. We deliver results that exceed expectations and we win together! Applicants must be authorized to work for any employer in the U.S. without sponsorship. We are unable to provide sponsorship for work visas of any kind at the time of hire, or at any point during employment. This includes, but is not limited to: F1-OPT, F1-CPT, H-1B, TN, J-1, etc Your Role: Tenable's Research Special Operations (RSO) team produces the exposure intelligence and analysis that helps organizations understand and prioritize cyber risk. We translate what's happening in the global threat landscape into structured, actionable intelligence for SOC analysts, vulnerability management engineers, field teams, and CISO-level stakeholders. We're looking for a Staff Research Engineer who will be primarily responsible for executing the daily intelligence production cycle for our Exposure Intelligence function. You'll run the morning production cycle; sourcing, triaging, classifying, analyzing, and publishing finished intelligence in collaboration with other team members. On a typical day you might assess a newly disclosed zero-day, determine whether it warrants a full analytical workup, write the daily brief that informs operational priorities, and publish an external digest consumed by hundreds of stakeholders, then shift to deeper analytical work, framework development, or external content in the afternoon. This isn't a traditional security research role. The work blends intelligence analysis, production discipline, and analytical writing on a daily cadence. The right candidate can context-switch between operational triage and deep analysis, writes clearly and concisely to deliver time-sensitive deliverables, and treats repeatable process as a feature rather than a constraint. Your Opportunity: Daily Intelligence Production - You have primary responsibility for executing the operational aspects of the Security Response process. That means monitoring a broad source ecosystem, triaging what matters, and producing the daily operations brief that informs the team's priorities, and an external intelligence digest distributed to a broad cross-section of stakeholders. You will make fast, well-calibrated decisions, often with incomplete or imperfect information, and communicate those decisions clearly to the rest of the Research team and to leadership, sometimes at short notice. You will apply structured analytical judgment to response decisions, assessing exploit maturity, likely attacker interest, and blast radius with clear confidence calibration. Analytical Products and External Content - Beyond the daily cycle, you'll produce deeper analytical products including threat assessments with confidence ratings and documented methodology, actor and campaign profiles, and focused analytical notes on individual CVEs or exposure conditions. You'll also write blog posts for the Tenable blog, coordinate with public relations and product marketing on media responses, and contribute to webinars and conference presentations. Standards and Tooling - As a senior contributor, you will provide input into the classification standards, analytical methodologies, and source management practices that underpin the team's work. You will identify opportunities for improvement based on your experience executing the daily production cycle and collaborate with other team members on evolving these capabilities, including AI-assisted workflows that extend the team's analytical capacity. Stakeholder Engagement - Contribute to development and execution of the team's strategic priorities, respond to internal intelligence requests from product teams and leadership, collaborate with stakeholders to understand their intelligence needs, and bring those perspectives back to the team to help inform analytical priorities and areas of focus beyond daily response work. What You'll Need: - 7+ years in cybersecurity: with meaningful depth in at least two of: vulnerability research, threat intelligence analysis, security operations, or exposure/risk management. - Experience producing structured analytical intelligence: Beyond just advisories or blog posts, including multi-source assessments with confidence ratings and documented methodology. Experience with intelligence community analytic standards is preferred. - Deep familiarity with the vulnerability lifecycle: Understanding the state of a vulnerability from disclosure through exploitation. You understand CVSS scoring, exploit maturity, CISA KEV, and the difference between a vulnerability existing and an exposure being actively exploited in the wild. - Strong understanding of threat actors and campaigns: attribution frameworks, TTP mapping (MITRE ATT&CK), and the ability to classify threats at the right level without inflation. - Excellent analytical writing and verbal communication skills: This role produces significant written output daily including threat briefs, assessments, digests and blog posts. - Comfort with structured, repeatable processes: This role involves executing within a structured and governed production cycle with quality gates and standards, not just ad hoc research. - Sound judgment under uncertainty: Rapid analytical decisions with incomplete information, with honest confidence calibration. This role requires the ability to work independently and make informed decisions with accuracy and precision. - Ability to manage multiple concurrent workstreams and shifting priorities. And Ideally: - Intelligence community or military intelligence background including structured analytic techniques, source reliability assessment, analytic confidence frameworks. - Experience in vulnerability management programs at scale, and understanding of what SOC teams actually need from threat intelligence to prioritize. - Familiarity with exposure management concepts with an understanding of the shift from vulnerability-centric to exposure-centric risk management, including cloud, identity, and OT/IoT. - Experience with AI-assisted analytical workflows. The team uses AI extensively as an analytical co-pilot. - Scripting and automation skills (Python, Bash, or similar) for data processing and tooling. This is not a software engineering role, but the ability to work with APIs and automate tasks is valuable. - Demonstrated experience writing for external audiences including blog posts, conference talks, media interviews and technical papers. - Experience with Tenable products (Tenable One, Nessus, Security Center) or competitive vulnerability management platforms. - Familiarity with exposure surface analysis tools (Shodan, Censys, GreyNoise) and OSINT techniques. - Experience with production tracking systems (Jira, Confluence) in a daily-cadence operational context. - Background in non-CVE exposure domains (e.g., cloud security, identity and credential exposure, shadow AI, OT/IoT). ## #LI-MS1 #LI-Hybrid This is the base pay range for this position. Compensation for the role will depend on a number of factors, including the candidate's qualifications, skills, competencies, location and experience, and may fall outside of the range shown. Employees are also eligible for variable compensation in addition to base pay (commission for sales roles, bonus for non-sales roles), depending on company and individual performance. Tenable also offers a variety of comprehensive and competitive benefits which include: medical, dental, vision, disability and life insurance; 401(k) retirement savings with company match; an employee stock purchase plan; an employee referral program; flexible spending accounts; an Employee Assistance Program (EAP); education assistance; parental leave; paid time off (PTO); company-paid holidays; health and wellness events; and community programs. US Pay Range $137,500—$183,500 USD We’re committed to promoting Equal Employment Opportunity (EEO) at Tenable - through all equal employment opportunity laws and regulations at the international, federal, state and local levels.  If you need a reasonable accommodation due to a disability during the application or recruiting process, please contact Recruiting@Tenable.com for further assistance. Tenable Data Consent Statement Tenable is committed to protecting the privacy and security of your personal data. Depending on your location, one or more of the following notices may apply to you: [General Applicant Privacy Notice](https://static.tenable.com/marketing/hr/Tenable_General_Applicant_Privacy_Notice_FINAL_4-29-2026_branded.pdf) [California Applicant Privacy Notice](https://static.tenable.com/marketing/hr/Tenable_CCPA_Notice_Applicants_FINAL_4-29-2026_branded.pdf) [EU/EEA/UK Applicant Privacy Notice](https://static.tenable.com/marketing/hr/Tenable_EEA_UK_Applicant_Privacy_Notice_FINAL_6-4-2026_branded.pdf) ## About Tenable, Inc. ## Company Overview - **One-liner**: Tenable is the Exposure Management company, providing an AI-powered platform that unifies security visibility, insight, and action across the entire attack surface to help organizations understand and reduce cyber risk. - **Entity Type**: Public (Ticker: TENB) - **Headquarters**: Columbia, Maryland, USA - **Founded**: 2002 - **Founders**: Ron Gula, Jack Huffard, Renaud Deraison ## Core Business - Primary industry/industries: Cybersecurity (Exposure Management, Vulnerability Management, Cloud Security, OT Security, Identity Security) - Target customers: Enterprise, SMB, and government organizations (B2B) — serving over 44,000 customers worldwide, including 65% of the Fortune 500 and 50% of the Global 2000 [tenable.com](https://www.tenable.com/about-tenable/about-us) - Mission or purpose statement: "We believe every business has the right to pursue its ambitions free from security worry. This is why we dedicate ourselves to isolating and eradicating the cyber exposures that hold organizations back." [tenable.com](https://www.tenable.com/about-tenable/about-us) ## Products & Services - **[Tenable One](https://www.tenable.com/)**: The company's flagship Exposure Management platform. It unifies visibility, insight, and action across the entire attack surface (IT, cloud, OT, identity, third-party applications, and AI) using native signals, exposure intelligence, and third-party data. It is powered by **Tenable Hexa AI**, which provides agentic orchestration to accelerate remediation. - **Vulnerability Management**: Core solution for discovering assets and prioritizing vulnerabilities based on risk. - **AI Exposure**: Provides visibility into the AI supply chain, including LLM integrations and data pipelines, to identify misconfigurations and shadow AI. - **Cloud Security (CNAPP)**: Reduces cloud risk by closing misconfigurations, risky entitlements, and vulnerabilities across multi-cloud and hybrid environments. - **Identity Exposure**: Continuously discovers assets and uses risk-based prioritization to focus on the most exploitable vulnerabilities. - **OT Exposure**: Manages security across cyber-physical ecosystems, bridging the gap between IT and OT. ## Market Standing - **Valuation/Market Cap**: Not publicly available in search results. (Public company; market cap fluctuates with stock price.) - **Key Metric**: Annual Revenue — Not publicly available in search results. (As a public company, revenue is disclosed in SEC filings like 10-K/10-Q; the latest figure was not cited in the provided search results.) - **Notable Investors/Partners**: The company went public in 2018 in one of the largest raises for a U.S.-listed security company at the time. Key leadership includes co-CEOs Steve Vintz and Mark Thurmond [tenable.com](https://www.tenable.com/about-tenable/about-us). - **Growth Signals**: - Named a Leader in the 2025 Gartner Magic Quadrant for Exposure Assessment Platforms. - Named a Leader in the IDC MarketScape Worldwide Exposure Management 2025 Vendor Assessment. - Named a Leader in The Forrester Wave: Unified Vulnerability Management Solutions, Q3 2025. - Serves 44,000+ customers worldwide, including 65% of the Fortune 500. - Processes 1.7 trillion unique exposure data points per year and covers 336,000+ CVEs [tenable.com](https://www.tenable.com/about-tenable/about-us). ## Competitive Advantages - **Market Leadership**: Consistently recognized as a Leader by major analyst firms (Gartner, Forrester, IDC) in the exposure management and vulnerability management categories. - **Vast Data Fabric**: The Tenable Exposure Data Fabric and Hexa AI provide a unique ability to understand how risk moves through an environment, enabling precise prioritization and coordinated remediation across teams and AI agents. - **Broad Coverage**: Unifies visibility across IT, cloud, OT, identity, and AI — a breadth that few competitors match. - **Scale & Trust**: Trusted by a massive portion of the Fortune 500 and Global 2000, creating a strong network effect and brand moat. ## Strategic Focus - **AI-Powered Exposure Management**: Deep investment in Tenable Hexa AI for agentic orchestration, aiming to shorten the time from detection to resolution. - **Expanding the Attack Surface View**: Continuously adding new domains (AI, identity, OT) to the platform to provide a truly unified view. - **Closing the Gap**: The core mission is to "close the gap between exposure and attack" by making exposure clear and actionable for customers. ## Why Work Here - **Culture & Recognition**: Great Place to Work Certified, 2025 Best Workplace in Technology, 2025 Best Workplaces in Tech in the UK, and Best Workplace for Disability Inclusion [tenable.com](https://www.tenable.com/careers). - **Work Model**: Hybrid and remote opportunities available. "Hub" roles require some weekly in-office presence, while Field/Remote roles are more flexible with occasional office attendance [tenable.com](https://www.tenable.com/careers). - **Benefits**: Comprehensive health benefits (physical, mental, and family-forming plans), retirement plans, Employee Stock Purchase Plan (ESPP), equity incentives, life and disability insurance, and generous paid time off. - **Professional Development**: Customizable opportunities including learning courses, mentorship, leadership programs, and tuition reimbursement. - **Engineering & Research Focus**: Strong emphasis on world-class research (covering 336K+ CVEs) and engineering innovation. The company is building "innovative platforms, products and features to help our customers stay one step ahead" [tenable.com](https://www.tenable.com/careers). - **Global Impact**: Work with a team across 40 countries, serving 44,000+ customers including some of the largest organizations in the world. ## Sources 1. [tenable.com](https://www.tenable.com/) 2. [tenable.com](https://www.tenable.com/about-tenable/about-us) 3. [tenable.com](https://www.tenable.com/careers) 4. [greenhouse.io](https://boards.greenhouse.io/tenableinc) 5. [linkedin.com](https://www.linkedin.com/company/tenableinc) ## Other roles at Tenable, Inc. - [Data Analyst - SQL / Databricks](https://feeny.ai/job/data-analyst-sql-databricks-tenable-inc-massachusetts-columbia-md-423beqmgasph) — Massachusetts / Columbia, MD - [Regional Sales Director - Southern Europe](https://feeny.ai/job/regional-sales-director-southern-europe-tenable-inc-spain-0k041st5sv35) — Spain - [Regional Sales Director - Southern Europe](https://feeny.ai/job/regional-sales-director-southern-europe-tenable-inc-italy-d7ax1rzzmvb3) — Italy - [Staff Software Engineer](https://feeny.ai/job/staff-software-engineer-tenable-inc-tel-aviv-8m4ecqnwva29) — Tel Aviv, Israel - [VP, Product Management](https://feeny.ai/job/vp-product-management-tenable-inc-tel-aviv-2h7hv2r6kzjh) — Tel Aviv, Israel - [Country Manager, Canada](https://feeny.ai/job/country-manager-canada-tenable-inc-canada-qsshds3bxkt6) — Canada - [Customer Success Manager](https://feeny.ai/job/customer-success-manager-tenable-inc-massachusetts-columbia-md-76826jpr3c36) — Massachusetts / Columbia, MD - [IT Support Engineer](https://feeny.ai/job/it-support-engineer-tenable-inc-tel-aviv-4e0vxt8dn6hh) — Tel Aviv, Israel - [Creative eLearning Developer](https://feeny.ai/job/creative-elearning-developer-tenable-inc-boston-t5f32wav9kep) — Boston, MA / Columbia, MD - [Associate Services Architect](https://feeny.ai/job/associate-services-architect-tenable-inc-boston-wypcj1183zxr) — Boston, MA / Columbia, MD