Vulnerability & Exploitation Specialist
Job description
About the role
You own the full lifecycle for customer missions, shaping intake briefs, building custom tooling, reviewing findings, shipping solutions, and partnering with cleared teams in Annapolis Junction. This role hands you dangerous systems to probe, document, and harden, with room to coach peers on a visible national security program. You translate ambiguous customer needs into precise test plans and execution roadmaps that drive measurable security improvements. You operate at the edge of offensive and defensive disciplines, turning complex technical findings into actionable strategies for high-impact customers. The position requires a hands-on mindset where deep technical craftsmanship directly supports national security objectives in a sensitive environment. You will mentor peers, elevate the collective capability of the team, and ensure every engagement leaves the customer more resilient than before. Your work will be visible at the highest levels, influencing how cleared partners design, build, and defend critical systems.
Key facts
What you'll do
Design intake workflows that translate mission needs into test plans and target environments.
Architect custom analysis tools and fuzzing harnesses for C, C++, Python, Java, and mobile OS stacks.
Conduct code reviews using CodeQL, Joern, and Semgrep to surface hidden attack paths.
Run reverse engineering sessions in Ghidra, IDA Pro, and Binary Ninja on varied binaries and firmware.
Exploit discovered 0-day and n-day vulnerabilities in controlled environments to prove impact.
Productize findings into repeatable techniques and artifacts for government customers and cleared partners.
Coordinate with SCIF-based teams during engagements, handling tool builds, debug sessions, and data handling.
Maintain fluency in ARM and MIPS environments, Linux variants, and Windows internals for diverse engagements.
Conduct threat modeling and attack surface analysis to guide secure design decisions early in the lifecycle.
Perform static, dynamic, and behavioral analysis across desktop, server, and embedded platforms.
Validate vendor patches and regression test fixes to ensure vulnerabilities remain closed in production.
Develop exploit primitives and payloads that reflect real adversary techniques while adhering to rules of engagement.
Capture and document methodologies in detailed technical reports suitable for cleared audiences and audit reviews.
Collaborate with red and blue teams to integrate offensive findings into defensive detection and response playbooks.
Requirements
You hold active TS/SCI with polygraph clearance applicable to this role and location.
You have discovered 0-day vulnerabilities or contributed to CVEs with public attribution.
You can demonstrate history performing vulnerability research across software and firmware.
You have hands-on experience with AFL, LibFuzzer, ClusterFuzz, or oss-fuzz for fuzzing campaigns.
You are skilled using CodeQL, Joern, and Semgrep for static and semantic code analysis.
You have previously exploited or productized 0-day vulnerabilities in real engagements.
You have exploited n-day or publicly disclosed vulnerabilities to validate customer risk.
You routinely reverse engineer malware or foreign code for computer network exploitation.
You are adept with Ghidra, IDA Pro, Binary Ninja, and debuggers such as GDB or WinDbg.
You write, navigate, and build C and C++ code for diverse target platforms.
You use VsCode, Visual Studio, and VIM or Emacs efficiently in daily workflows.
You understand ARM and MIPS architectures and various Linux distributions.
You are comfortable writing Python to automate tooling and analysis tasks.
You can operate independently and within structured team environments under strict operational security.
You communicate technical concepts clearly to both technical and leadership audiences in sensitive contexts.
You are committed to continuous learning, staying current with emerging offensive techniques and mitigations.
Nice to have
Proven work in cleared environments on national security related programs.
Skills & tools
C/C++, Python, Assembly (x86/x64), Java, mobile OSs, Windows, Linux, RE, debugging tools, CodeQL, Joern, Semgrep, AFL, LibFuzzer, ClusterFuzz, oss-fuzz, Ghidra, IDA Pro, Binary Ninja, GDB, WinDbg, VsCode, Visual Studio, VIM, Emacs.
About the company
Grvty is a company linked to Kiat Lim. He is a businessman from Singapore, born on 5 July 1993. His father is Peter Lim, who is also a businessman from Singapore. Peter Lim is the owner of a Spanish football club named Valencia. Kiat Lim has held the role of president of Valencia since 3 March 2025. This shows a direct family connection to the leadership of the club. The company background is tied to this family and their activities. The focus is on the relationship between father and son in business. The son's role in the club is recent and clearly defined. The information centers on family, business, and the specific club. Grvty's description is based on these personal and professional links. The background reflects a family with strong business interests in sport. This context defines the public profile of Grvty.