Remote job
Sr. Vulnerability Researcher (US)
Job details
About this role
Role overview A senior vulnerability researcher position focused on discovering net-new vulnerabilities across operating systems, platforms, and devices. The role sits inside an Initial Access Intelligence group that produces exploits, detections, and supporting artifacts for active cyber defense, with a strong emphasis on applying agentic and automated approaches to scale research. It is a fully remote position based in the United States.
Responsibilities - Conduct original vulnerability research to surface previously unknown flaws across diverse operating systems, platforms, and devices. - Reverse engineer a variety of firmware and software targets to understand their internals. - Author weaponized exploits, network detection signatures (Suricata/Snort), and supporting artifacts such as Docker containers, version scanners, and ASM queries alongside new findings. - Apply and expand agentic methods to scale vulnerability discovery and exploit development workflows. - Collaborate with a small team of researchers and threat analysts, working independently on complex technical problems.
Requirements - At least five years of full-time vulnerability research experience, including work targeting networking device firmware, embedded Linux or RTOS-based systems, and/or network protocols. - Demonstrated experience developing original, weaponized exploit code. - Comfort acquiring, unpacking, and analyzing firmware and appliances, with strong reasoning about network protocols and unauthenticated attack surface. - Familiarity with embedded architectures such as MIPS and ARM, plus firmware extraction tooling like binwalk. - Strong static and dynamic reverse engineering skills using tools such as Ghidra. - Solid working knowledge of memory corruption and related vulnerability classes, plus C/C++ and at least one scripting language (e.g., Python).
Nice to have - Hands-on experience with agentic or automated approaches to vulnerability discovery. - Dynamic analysis and debugging on emulated or embedded targets (e.g., QEMU). - Working knowledge of common networking protocols such as TCP/IP, routing protocols, IPsec/SSL-VPN, and SNMP. - Prior cybersecurity work in a vendor or government environment, a track record of CVEs or published research, and the ability to share example research or exploit code.
Benefits and work setup - Fully remote within the United States. - Generous, flexible time off plus paid parental leave. - Retirement plan contributions and comprehensive healthcare coverage. - Home office support for phone and internet costs. - Note: employment is contingent on the ability to authorize access under applicable U.S. export control regulations.