
Principal Reverse Engineering, Vulnerability Research Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Conduct vulnerability research and reverse engineering for client projects.
• Execute both static and dynamic analysis utilizing research tools such as disassemblers, debuggers, and fuzzers.
• Engage in exploit development based on identified vulnerabilities.
• Share security research insights internally and, when appropriate, with external parties.
• Guide and mentor fellow security researchers.
• Analyze and thoroughly comprehend the functionality of various systems.
• Navigate through the initial stages of vulnerability research projects, advancing them through multiple phases and iterations.
• Must possess the ability to obtain and maintain a TS/SCI security clearance (note: only U.S. citizens are eligible for security clearances).
• Bachelor's degree in Computer Engineering, Computer Science, Software Engineering, or a related technical field, coupled with six years of professional experience.
• Experience in participating in Capture The Flag (CTF) events, hackathons, or other cybersecurity competitions.
• Proficiency with Ghidra, Binary Ninja, IDA, or other reverse engineering/disassembler tools.
• Familiarity with Linux fundamentals (including sockets, file descriptors, networking, iptables, file systems, kernel, etc.).
• Capability to read and write C and assembly languages as required (ARM, MIPS, x86_64).
• Understanding of programming fundamentals, especially in networking, data structures, and data models.
• Knowledge of exploitation techniques such as utilizing arbitrary read-write primitives, shellcoding, and return-oriented programming / jump-oriented programming.
• Proven experience in exploit development targeting Android operating systems and Chrome web browsers.
• Preferred: Currently holds a Top Secret security clearance.
• Preferred: Experience with OS and kernel reverse engineering.
• Preferred: Familiarity with fuzzers like AFL++ or libfuzzer.
• Preferred: Understanding of common exploit mitigation strategies such as SELinux, Seccomp, ASLR, and CFI.
• Preferred: Strong grasp of dynamic analysis using gdb/gdbserver and similar tools.
• Preferred: Basic knowledge of processor tool chains and the Android NDK.
• Preferred: Insight into emulation using Qemu or Unicorn for executing code in a non-native environment.
• Preferred: Experience in identifying zero-day vulnerabilities and other security flaws.
• Competitive salary and performance-based bonuses.
• Comprehensive health, dental, and vision insurance plans.
• Generous paid time off and holiday leave.
• Opportunities for professional development and continuous learning.
• Flexible work arrangements to promote work-life balance.
Clarity Innovations, Inc.
Clarity Innovations, Inc.
Synthesia
Get handpicked remote jobs straight to your inbox weekly.