Senior Security Researcher
Job description
About the role
The owns the complete research lifecycle for every engagement they manage from initial scoping through final delivery. They are responsible for designing intricate test scenarios that challenge the boundaries of software and firmware resilience. This position requires the independent judgment to analyze deeply complex systems and dissect undocumented behaviors under significant time constraints. The researcher must exhibit resilience when confronting highly resistant targets that demand unconventional approaches. They translate highly technical discoveries into clear defensive recommendations that engineering teams can implement without friction. Collaboration with partner teams is constant, ensuring that offensive findings immediately inform defensive strategy and architecture improvements. This role demands a commitment to delivering high quality results that clients can trust with their most sensitive infrastructure. The position operates at the intersection of offensive research and defensive enablement within a national security context.
Key facts
What you'll do
- Conduct comprehensive vulnerability research across a diverse range of software and firmware targets using advanced methodologies.
- Perform deep system analysis by running dynamic analysis sessions with debuggers and custom instrumentation against live production and test systems.
- Develop reliable exploits for memory corruption vulnerabilities and logic flaws, turning theoretical weaknesses into working proofs of concept.
- Mentor less experienced researchers on methodology, best practices, and rigorous documentation standards to elevate the entire team's capability.
- Coordinate closely with partner teams to align testing scope and share tactical findings promptly to ensure continuous security validation.
- Build and maintain repeatable analysis workflows and tooling using disassemblers, debuggers, and custom scripts to increase research efficiency.
- Adapt assessment techniques specifically for embedded environments and specialized platforms that operate outside standard computing norms.
- Present technical research outcomes with clarity and precision to both deep technical audiences and leadership stakeholders for executive decision making.
- Leverage disassemblers and custom tooling to build robust analysis pipelines that can be reused across multiple engagements.
- Drive the discovery process for 0-day vulnerabilities by combining deep protocol knowledge with creative exploitation strategies.
- Utilize emulation platforms such as QEMU to run and interact with binaries in non-native environments for safe and isolated testing.
- Maintain strict operational security and professionalism when handling sensitive materials and classified information throughout the research lifecycle.
Requirements
- Hold an active TS/SCI clearance which is mandatory for this position, and the candidate must be a United States citizen without exception.
- Possess a bachelor's degree in Computer Engineering, Computer Science, Software Engineering, or a closely related discipline as a baseline qualification.
- Candidates may substitute four years of relevant full-time software engineering experience for the degree requirement if they can demonstrate equivalent knowledge.
- Demonstrate hands on experience with industry standard reverse engineering tools such as Ghidra, Binary Ninja, or IDA as a non negotiable skill.
- Maintain a strong comfort level with Linux internals including networking stacks, memory management mechanisms, and process primitives.
- Show proficiency in writing and adapting code for multiple processor architectures including ARM, MIPS, and x86 to operate independently on diverse targets.
- Possess strong fundamentals in networking protocols, data structures, and system design concepts essential for analyzing complex interactions.
- Have a documented skill set for creating exploits against common vulnerability patterns observed in the wild and in controlled testing scenarios.
- Be able to work full-time in the USA based on the engagement requirements and project timelines.
- Understand the importance of clear, precise, and structured documentation for research artifacts and findings.
- Commit to continuous learning to keep pace with rapidly evolving exploitation techniques and defensive technologies.
- Adhere to the strict ethical guidelines and professional standards required when working on national security related research.
Nice to have
- Possession of a current Top Secret security clearance is preferred as it reduces onboarding time for sensitive projects.
- Prior experience with operating system and kernel reverse engineering provides an immediate advantage in complex engagements.
- Familiarity with mitigation bypass techniques, modern fuzzers, and dynamic analysis tools such as gdb and gdbserver is a significant plus.
- Understanding of processor tool chains and direct experience with 0-day discovery processes are highly advantageous for senior level work.
- Experience with emulation using QEMU for running binaries in non-native environments allows for faster setup of testing labs.
Practical notes
This is a full-time position based in the United States. Details regarding the application process and requirements must be confirmed Please review that page carefully for the most current instructions and documentation procedures.