Jobgether
Sr. Vulnerability Researcher
datafull-timeUS
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more
About the role
Accountabilities
- Conduct original vulnerability research to identify previously unknown security weaknesses across operating systems, platforms, networking equipment, embedded systems, and devices.
- Analyze exposed attack surfaces and investigate vulnerabilities from initial discovery through validation and exploit development.
- Reverse engineer firmware, software, compiled binaries, and appliances using static and dynamic analysis techniques.
- Develop original exploit code to demonstrate and weaponize newly discovered vulnerabilities for defensive intelligence purposes.
- Create supporting security artifacts such as network detection rules, version scanners, Docker containers, ASM queries, and other technical outputs associated with vulnerability research.
- Acquire, extract, unpack, and analyze firmware while investigating embedded architectures, network protocols, and unauthenticated attack surfaces.
- Perform dynamic analysis and debugging against embedded or emulated environments to validate vulnerability hypotheses and exploitation techniques.
- Apply agentic AI and automated approaches to increase the scale, speed, and effectiveness of vulnerability discovery and exploit development.
- Collaborate with experienced vulnerability researchers and threat intelligence specialists on complex technical investigations and research initiatives.
- Contribute to the advancement of vulnerability research methodologies, tooling, and automated approaches.
- Communicate research findings clearly and contribute technical expertise to high-impact security research projects.
- Work independently on complex research problems while contributing effectively within a small, highly technical remote team.
- 5+ years of full-time professional vulnerability research experience, particularly involving networking device firmware, embedded Linux or RTOS environments, and/or network protocols.
- Demonstrable experience applying agentic or automated approaches to vulnerability discovery and exploit development.
- Proven experience developing original exploit code and demonstrating practical exploitation techniques.
- Strong experience acquiring, unpacking, analyzing, and debugging firmware and network appliances.
- Familiarity with embedded architectures such as MIPS and ARM, along with firmware extraction and unpacking tools such as Binwalk.
- Experience with dynamic analysis and debugging of embedded or emulated targets, including tools such as QEMU.
- Solid understanding of networking technologies and protocols, including TCP/IP, routing protocols, VPN technologies such as IPsec and SSL-VPN, and SNMP.
- Advanced reverse engineering capabilities, including static and dynamic analysis of compiled binaries and firmware; experience with Ghidra is particularly valuable.
- Strong knowledge of memory corruption and other vulnerability classes, including stack and heap overflows, use-after-free, type confusion, integer errors, command and path injection, authentication weaknesses, and logic flaws.
- Strong programming skills in C/C++ and proficiency in at least one scripting language such as Python.
- Ability to work effectively on complex technical projects in a remote environment, both independently and within small collaborative teams.
- Strong analytical thinking, intellectual curiosity, problem-solving ability, and willingness to investigate technically challenging problems.
- Prior cybersecurity experience within a security vendor, government organization, or comparable environment is preferred.
- A demonstrated record of discovering and documenting new vulnerabilities, such as CVEs, security advisories, exploits, or published research, is highly desirable.
- Ability to provide examples of previous vulnerability research or exploit development work is a plus.
- Candidates must be able to satisfy applicable U.S. export control, sanctions, and other legal or contractual requirements associated with access to certain technologies.
- Fully remote position within the United States.
- Generous and flexible paid time off.
- Retirement contributions, including a 401(k) plan with employer match in the United States.
- Comprehensive healthcare coverage.
- Generous paid parental leave.
- Remote-friendly working environment with flexibility.
- Support for home-office expenses such as phone and internet costs.
- Opportunity to work alongside experienced vulnerability researchers, hackers, and threat intelligence specialists.
- Exposure to cutting-edge vulnerability research, exploit intelligence, reverse engineering, and agentic security technologies.
- Opportunity to conduct original research and contribute to the broader cybersecurity community.
- Benefits may vary according to country or employment location and are confirmed during the offer process.
Requirements
Benefits
✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply