Cleared Vulnerability Research Engineer
Job description
About the role
This role is focused on end-to-end exploit development for real-world targets. The specialist will design, develop, and validate novel vulnerability discovery and exploitation capabilities against complex software and systems. Work is conducted at the operating system, binary, and micro-architectural levels, with a strong emphasis on creating new technical capabilities. Success in this position requires the ability to independently translate an under-defined mission objective into a concrete, technically novel capability. The hire will own the full lifecycle of advanced exploit development, from initial research through validation against live targets. They will operate with minimal supervision and comfort incomplete problem definitions and delayed feedback. This position drives the creation of new technical capabilities for real-world engagements.
Key facts
What you'll do
Conduct expert reverse engineering of binaries (x86-64, ARM64, etc.) using industry-standard tools such as Binary Ninja, Ghidra, or IDA Pro.
Identify and exploit real-world vulnerabilities such as Use-after-free, Type confusion, Integer truncation, and Buffer overflow within complex software environments.
Design, develop, and validate novel vulnerability discovery and exploitation capabilities to address evolving threat landscapes.
Perform vulnerability discovery through a combination of manual analysis and automated techniques, including fuzzing, to uncover hidden flaws.
Demonstrate the ability to discover new, novel vulnerabilities in complex systems rather than relying solely on known issue patterns.
Code, debug, and analyze intricate functions and logic using C, Python, and Assembly for x86-64, ARM, and other relevant architectures.
Independently manage and execute research objectives, including scoping, research, experimentation, validation, and iterative refinement of methodologies.
Travel to customer sites as required and perform on-site for extended periods to address specific engagement needs.
Apply findings from current vulnerability research to rapidly identify new instances of vulnerability classes across different platforms.
Maintain a high level of technical rigor by documenting processes, findings, and methodologies throughout the research and development lifecycle.
Collaborate with internal teams to integrate discovered vulnerabilities into broader security assessments and customer deliverables.
Adapt quickly to new technologies, reverse engineering challenges, and unfamiliar problem spaces without extensive direction.
Ensure all work products meet the quality standards and expectations of professional security engagements under tight deadlines.
Leverage creativity and deep technical insight to propose unconventional approaches for identifying and exploiting difficult-to-find issues.
Contribute to the collective knowledge base within the team to improve methodologies and tooling for future vulnerability research efforts.
Requirements
Expertise in exploit development with hands-on experience in designing, developing, and validating novel vulnerability discovery and exploitation capabilities.
Strong proficiency in reverse engineering binaries for operating systems and software, targeting architectures such as x86-64 and ARM64 using professional tools.
Comprehensive understanding of exploit-relevant vulnerabilities including Use-after-free, Type confusion, Integer truncation, and Buffer overflow.
Proven ability to discover new vulnerabilities independently, demonstrating success in finding issues that are not publicly documented.
Capability to rapidly assimilate current vulnerability research findings and apply them to identify similar vulnerabilities in other systems or codebases.
Experience employing both manual code analysis and automated discovery techniques, ensuring broad coverage during vulnerability assessments.
Strong coding skills in C, Python, and Assembly, with the ability to write, debug, and maintain complex functions for security research.
Self-driven research skills, including the capacity to define scope, plan experiments, iterate on findings, and validate hypotheses with minimal oversight.
Ability to travel to customer locations as needed and sustain on-site presence for extended durations during active engagements.
Possession of TS/SCI clearance, with inactive SCI eligibility being acceptable for candidates who can obtain full clearance.
Willingness to work under challenging conditions where problem definitions may evolve and feedback loops can be delayed.
Physical capability to meet the job's working conditions, including prolonged sitting or standing and moving equipment like laptops throughout the workday.
Ability to complete all physical requirements of the role, with or without reasonable accommodation, as outlined in the working conditions.
Practical notes
This role requires a commitment to independent execution and advanced technical problem solving in demanding security research scenarios. The Cleared Vulnerability Research Engineer will play a critical part in advancing the offensive capabilities of security assessments conducted through the Bugcrowd platform. The position demands resilience, intellectual curiosity, and a methodical approach to complex software challenges. Individuals in this role will interact directly with difficult real-world targets, requiring patience and precision. They must be comfortable navigating environments where initial objectives are under-defined and outcomes depend on deep technical exploration. The successful candidate will uphold the highest standards of quality and reliability when developing and validating exploit code. Effective communication skills are essential for coordinating with stakeholders and translating technical findings into actionable insights. This position is part of a broader effort to harness the power of hacker ingenuity and AI-driven technology to outpace emerging threats. The work conducted will contribute directly to the organization's mission of empowering customers to maintain control over their security posture. The role operates within the framework of remote-first flexibility, with specific location options provided to align with operational needs. Clearances and the ability to meet travel requirements are non-negotiable aspects of this position. The environment is fast-paced, requiring adaptability and continuous learning. Candidates should be prepared to engage with cutting-edge research and contribute to impactful security outcomes.