
Senior Vulnerability Researcher
Posted Sep 8

Posted Sep 8
This is a fully remote position, open to applicants in United States.
• Perform vulnerability research to discover new vulnerabilities across various operating systems, platforms, and devices.
• Reverse engineer diverse firmware and software applications.
• Create original exploits, network rules (Suricata / Snort), and additional artifacts such as Docker containers, version scanners, and ASM queries to support new vulnerability discoveries.
• Implement and enhance agentic methodologies to scale the processes of vulnerability discovery and exploit development.
• Collaborate with an experienced team of hackers and threat researchers to identify and weaponize new vulnerabilities ahead of adversaries.
• Lead original research from exposure analysis and reverse engineering to vulnerability discovery and the development of weaponized exploits.
• Over 5 years of full-time experience in vulnerability research, including targeting firmware for networking devices, embedded Linux/RTOS systems, and/or network protocols.
• Proven experience employing agentic approaches to vulnerability discovery and exploit development.
• Background in developing original (weaponized) exploit code.
• Proficiency in acquiring, unpacking, and analyzing target firmware and appliances, with the ability to reason about network protocols and unauthenticated attack surfaces.
• Familiarity with embedded architectures (MIPS, ARM) and the extraction/unpacking of firmware (e.g., binwalk).
• Experience in dynamic analysis and debugging on embedded/emulated targets (e.g., QEMU).
• Solid understanding of common networking protocols (TCP/IP, routing protocols, VPN protocols such as IPsec/SSL-VPN, SNMP, etc.).
• Strong reverse engineering capabilities, including both static and dynamic analysis of compiled binaries and firmware (VulnCheck utilizes Ghidra for reversing).
• In-depth knowledge of memory corruption and various vulnerability types (e.g., stack and heap overflows, use-after-free, type confusion, integer errors, command and path injection, authentication and logic flaws).
• Competent in C/C++ and at least one scripting language (e.g., Python).
• Experience working on technical projects remotely, independently, and in small teams.
• Employment may necessitate authorization to access technology subject to U.S. export control regulations, sanctions, and other applicable legal or contractual obligations.
• Generous and flexible paid time off.
• Contributions to retirement/pension plans (e.g., 401k with matching in the U.S.; local pension schemes in other locations).
• Comprehensive healthcare coverage.
• Generous paid parental leave.
• A remote-friendly work environment with flexibility.
• Support for home office expenses (phone & internet).
Budderfly
St. Croix Hospice
Academy of Art University School of Game Development
Get handpicked remote jobs straight to your inbox weekly.