Jobgether
Jobgether

Sr. Vulnerability Researcher

datafull-timeUS
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
Apply for this position
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more

About the role

Accountabilities

    • Conduct original vulnerability research to identify previously unknown security weaknesses across operating systems, platforms, networking equipment, embedded systems, and devices.
    • Analyze exposed attack surfaces and investigate vulnerabilities from initial discovery through validation and exploit development.
    • Reverse engineer firmware, software, compiled binaries, and appliances using static and dynamic analysis techniques.
    • Develop original exploit code to demonstrate and weaponize newly discovered vulnerabilities for defensive intelligence purposes.
    • Create supporting security artifacts such as network detection rules, version scanners, Docker containers, ASM queries, and other technical outputs associated with vulnerability research.
    • Acquire, extract, unpack, and analyze firmware while investigating embedded architectures, network protocols, and unauthenticated attack surfaces.
    • Perform dynamic analysis and debugging against embedded or emulated environments to validate vulnerability hypotheses and exploitation techniques.
    • Apply agentic AI and automated approaches to increase the scale, speed, and effectiveness of vulnerability discovery and exploit development.
    • Collaborate with experienced vulnerability researchers and threat intelligence specialists on complex technical investigations and research initiatives.
    • Contribute to the advancement of vulnerability research methodologies, tooling, and automated approaches.
    • Communicate research findings clearly and contribute technical expertise to high-impact security research projects.
    • Work independently on complex research problems while contributing effectively within a small, highly technical remote team.
    • Requirements

      • 5+ years of full-time professional vulnerability research experience, particularly involving networking device firmware, embedded Linux or RTOS environments, and/or network protocols.
      • Demonstrable experience applying agentic or automated approaches to vulnerability discovery and exploit development.
      • Proven experience developing original exploit code and demonstrating practical exploitation techniques.
      • Strong experience acquiring, unpacking, analyzing, and debugging firmware and network appliances.
      • Familiarity with embedded architectures such as MIPS and ARM, along with firmware extraction and unpacking tools such as Binwalk.
      • Experience with dynamic analysis and debugging of embedded or emulated targets, including tools such as QEMU.
      • Solid understanding of networking technologies and protocols, including TCP/IP, routing protocols, VPN technologies such as IPsec and SSL-VPN, and SNMP.
      • Advanced reverse engineering capabilities, including static and dynamic analysis of compiled binaries and firmware; experience with Ghidra is particularly valuable.
      • Strong knowledge of memory corruption and other vulnerability classes, including stack and heap overflows, use-after-free, type confusion, integer errors, command and path injection, authentication weaknesses, and logic flaws.
      • Strong programming skills in C/C++ and proficiency in at least one scripting language such as Python.
      • Ability to work effectively on complex technical projects in a remote environment, both independently and within small collaborative teams.
      • Strong analytical thinking, intellectual curiosity, problem-solving ability, and willingness to investigate technically challenging problems.
      • Prior cybersecurity experience within a security vendor, government organization, or comparable environment is preferred.
      • A demonstrated record of discovering and documenting new vulnerabilities, such as CVEs, security advisories, exploits, or published research, is highly desirable.
      • Ability to provide examples of previous vulnerability research or exploit development work is a plus.
      • Candidates must be able to satisfy applicable U.S. export control, sanctions, and other legal or contractual requirements associated with access to certain technologies.
      • Benefits

        • Fully remote position within the United States.
        • Generous and flexible paid time off.
        • Retirement contributions, including a 401(k) plan with employer match in the United States.
        • Comprehensive healthcare coverage.
        • Generous paid parental leave.
        • Remote-friendly working environment with flexibility.
        • Support for home-office expenses such as phone and internet costs.
        • Opportunity to work alongside experienced vulnerability researchers, hackers, and threat intelligence specialists.
        • Exposure to cutting-edge vulnerability research, exploit intelligence, reverse engineering, and agentic security technologies.
        • Opportunity to conduct original research and contribute to the broader cybersecurity community.
        • Benefits may vary according to country or employment location and are confirmed during the offer process.
✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply
Apply now
Sr. Vulnerability Researcher at Jobgether — Remote