
Cybersecurity Research Specialist
Posted 5 days ago

Posted 5 days ago
This is a fully remote position, open to applicants in New York.
• Analyze technical evaluations of intricate software vulnerabilities and security scenarios.
• Confirm root causes of vulnerabilities across software, operating systems, networks, cloud settings, and web applications.
• Evaluate exploitability, technical feasibility, prerequisites, and security assumptions.
• Review analyses of AI-generated exploits and reasoning for multi-stage attacks.
• Assess reverse engineering, binary analysis, memory corruption, application security, and offensive-security logic.
• Critique exploit chains to identify weaknesses or inconsistencies.
• Evaluate defensive recommendations, mitigation strategies, and secure software engineering guidance.
• Review security reasoning across various contexts including operating systems, networks, web, cloud, browsers, mobile, and embedded-security.
• Provide structured written feedback that clarifies technical evaluation decisions.
• Contribute to the formulation of structured benchmarks for advanced AI cybersecurity capabilities.
• Develop or enhance evaluation criteria and technical assessment rubrics.
• Identify security scenarios that challenge advanced reasoning capabilities.
• Assist in establishing consistent standards for evaluating intricate cybersecurity outputs.
• Solid professional or research experience in offensive security, vulnerability research, exploit development, application security, product security, or security engineering.
• Proven expertise in multiple domains, including reverse engineering, binary analysis, vulnerability research, operating systems, networks, web security, or cryptography.
• Several recognized technical accomplishments, such as competitive CTF performance, published CVEs, major bug-bounty discoveries, security research publications, or significant public technical contributions.
• Experience in identifying or analyzing vulnerabilities in widely used open-source or commercial software.
• Proficiency with reverse-engineering tools such as IDA Pro, Ghidra, Binary Ninja, Radare2, or similar platforms.
• Experience with fuzzing, symbolic execution, static analysis, dynamic analysis, or related techniques for vulnerability discovery.
• Strong programming skills in C/C++, Rust, Python, Go, or Java.
• Ability to articulate complex cybersecurity concepts clearly and accurately in writing.
• Experience in a recognized security research laboratory, academic research group, product-security team, or a comparable industry environment is highly regarded.
• Publications or presentations at conferences such as Black Hat, DEF CON, USENIX Security, IEEE S&P, ACM CCS, NDSS, or similar events are highly valued.
• Contributions to established open-source security tools or recognized bug-bounty programs are advantageous.
• Relevant advanced security certifications may also be taken into consideration.
• Work must be performed without using confidential or proprietary information belonging to any employer, client, institution, or other third party.
• H1-B and STEM OPT support is not available for this position.
• Fully remote independent contractor position.
• Flexible scheduling based on the needs of the project.
• Engagements may be extended, shortened, or concluded based on project requirements and performance.
• Strong contributors may be considered for additional cybersecurity evaluation projects.
CivicScience
ICF
The Health Management Academy
ICON plc
Get handpicked remote jobs straight to your inbox weekly.