About the Role
A newly discovered infostealer malware is targeting enterprise devices by exploiting a known vulnerability in FortiClient Enterprise Management Server (EMS). Cybersecurity researchers at Arctic Wolf have identified that attackers are delivering malicious payloads disguised as legitimate Fortinet endpoint updates, leveraging CVE-2026-35616—an improper access control flaw in FortiClient EMS. This role involves analyzing and mitigating such threats, focusing on vulnerability research and enterprise security hardening.
Key Responsibilities
- Investigate and analyze the CVE-2026-35616 vulnerability in FortiClient EMS
- Develop detection mechanisms for infostealer malware exploiting this flaw
- Collaborate with IT teams to patch and secure vulnerable enterprise systems
- Monitor threat intelligence feeds for similar exploitation attempts
- Document findings and provide remediation recommendations
- Assist in forensic analysis of compromised systems
- Stay updated on emerging cybersecurity threats and attack vectors
Requirements
- Proven experience in vulnerability research and malware analysis
- Deep understanding of enterprise security systems, particularly Fortinet products
- Familiarity with exploit chains and privilege escalation techniques
- Knowledge of VPN security and scripting workflows
- Relevant cybersecurity certifications (e.g., CISSP, CEH, OSCP) preferred
- Strong analytical and problem-solving skills
Compensation & Benefits
- Competitive salary based on experience
- Comprehensive health and wellness benefits
- Professional development opportunities
- Flexible work arrangements
- Cutting-edge security tools and resources
How to Apply
Interested cybersecurity professionals can explore this opportunity further by using the Apply Now button above. The original listing contains additional details about the position and application process. For those interested in similar roles, NetworkUstad features several relevant cybersecurity positions, including Vulnerability Research Opportunities and Open Source Security Engineer Roles at major tech firms. “`json