Senior Vulnerability Researcher

Posted 13hrs ago

Employment Information

Industry
Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior vulnerability researcher discovering and weaponizing vulnerabilities across firmware, software, and network devices. Advancing VulnCheck’s exploit intelligence and agentic vulnerability research.

Responsibilities:

  • Conduct vulnerability research to identify net-new vulnerabilities across a range of operating systems, platforms, and devices
  • Reverse engineer a variety of firmware and software
  • Author original exploits, network rules (Suricata / Snort), and other artifacts such as Docker containers, version scanners, and ASM queries to accompany new vulnerability finds
  • Apply and expand agentic approaches to scale vulnerability discovery and exploit development
  • Work with a seasoned team of hackers and threat researchers to find and weaponize new vulnerabilities before adversaries do
  • Drive original research from exposure analysis and reverse engineering through vulnerability discovery and weaponized exploit development

Requirements:

  • 5+ years of full-time vulnerability research experience, including experience targeting networking device firmware, embedded Linux/RTOS-based systems, and/or network protocols
  • Demonstrable experience with agentic approaches to vulnerability discovery and exploit development
  • Experience developing original (weaponized) exploit code
  • Comfort acquiring, unpacking, and analyzing target firmware and appliances, including reasoning about network protocols and unauthenticated attack surface
  • Familiarity with embedded architectures (MIPS, ARM) and firmware extraction/unpacking (e.g., binwalk)
  • Experience with dynamic analysis and debugging on embedded/emulated targets (e.g., QEMU)
  • Working knowledge of common networking protocols (TCP/IP, routing protocols, VPN protocols such as IPsec/SSL-VPN, SNMP, etc.)
  • Strong reverse engineering skills, including static and dynamic analysis of compiled binaries and firmware (VulnCheck uses Ghidra for reversing)
  • Strong command of memory corruption and other vulnerability classes (e.g., stack and heap overflows, use-after-free, type confusion, integer errors, command and path injection, authentication and logic flaws)
  • Solid working knowledge of C/C++ and at least one scripting language (e.g., Python)
  • Experience working on technical projects remotely, alone, and on small teams
  • Employment may require authorization to access technology subject to U.S. export control regulations, sanctions, and other applicable legal or contractual requirements

Benefits:

  • Generous, flexible time off
  • Retirement/pension plan contributions (e.g., 401k with match in the US; local pension schemes elsewhere)
  • Comprehensive healthcare coverage
  • Generous paid parental leave
  • Remote-friendly environment with flexibility
  • Support for home office costs (phone & internet)