Vulnerability Researcher
Job description
About the role
You will conduct in-depth vulnerability research across a wide range of software and firmware targets to uncover zero-day conditions and novel exploitation paths. This position requires you to apply advanced reverse engineering techniques to complex binaries without the aid of traditional documentation or support materials. You will design and validate reliable vulnerability exploits that demonstrate concrete impact on mission-critical systems and operational environments. You will work closely with government customers to translate ambiguous operational requirements into precise technical objectives and testing methodologies. The role demands ownership of the full vulnerability lifecycle from initial discovery through weaponization, validation, and responsible disclosure. You will author high-quality technical reports and deliver clear findings to both technical and executive audiences during engagement reviews. In addition, you will contribute to the internal knowledge base by developing reusable tooling, proof-of-concept frameworks, and detection recommendations. As a senior team member, you will mentor junior researchers, conduct code reviews, and elevate the overall technical maturity of the cybersecurity practice.
Key facts
What you'll do
Perform static and dynamic analysis of proprietary and commercial software to identify memory corruption, logic flaws, and authentication bypass conditions.
Reverse engineer unknown binaries, firmware images, and device drivers using disassemblers, debuggers, and custom analysis scripts to infer functionality and pinpoint weaknesses.
Develop reliable client-side and server-side exploits for identified vulnerabilities, adapting techniques to constrained environments and legacy platforms.
Design and implement custom fuzzing campaigns, symbolic execution workflows, and concolic testing approaches to achieve high-coverage vulnerability discovery.
Collaborate with network and systems engineers to construct test scenarios that replicate sophisticated adversary behaviors and advanced persistent threat techniques.
Create indicators of compromise, behavioral analytics, and mitigation guidance to help detection engineers and incident responders defend against active threats.
Integrate exploit modules into operational toolsets, ensuring compatibility with controlled testbeds and adherence to strict data handling policies.
Maintain up-to-date knowledge of emerging exploit frameworks, public disclosures, and mitigation strategies to ensure continuous improvement of research methodologies.
Document every phase of the engagement with reproducible steps, evidence artifacts, and remediation guidance aligned with customer reporting standards.
Represent Redhorse in internal and external technical discussions, providing expert judgment on vulnerability severity, risk impact, and remediation prioritization.
Mentor junior researchers by conducting hands-on training sessions, walkthroughs of complex vulnerabilities, and peer review of technical deliverables.
Support the evaluation of third-party software and hardware components, assessing their security posture in the context of integrated mission solutions.
Coordinate closely with product vendors, government test teams, and red cell operators to ensure timely validation and remediation tracking.
Contribute to the strategic development of the vulnerability research practice, including tool selection, process refinement, and long-term capability planning.
Requirements
U.S. citizen eligible for public trust clearance.
Must be able to obtain and maintain a U.S. government Public Trust Clearance.
Eligible to work in the United States without sponsorship now or at any time during the employment period.
Must be physically located in or be willing to relocate to Herndon, VA for the duration of the assignment.
Demonstrated experience conducting vulnerability research, reverse engineering, and exploitation across multiple software domains.
Strong proficiency in C, C++, Python, and assembly languages for x86, x64, and at least one embedded architecture.
Experience with debugging frameworks, disassemblers, and interactive development environments such as IDA Pro, Ghidra, or equivalent tools.
Proven track record of discovering and responsibly disclosing vulnerabilities in commercial or open-source software.
Ability to read and interpret technical specifications, protocol documentation, and vendor advisories without significant external assistance.
Commitment to strict operational security, data protection, and compliance with government-defined handling and dissemination rules.
Excellent written and verbal communication skills with the ability to explain complex technical concepts to diverse audiences.
Willingness to work in a dynamic environment with frequent priority shifts, evolving requirements, and urgent operational needs.
Demonstrated mentorship experience guiding junior engineers through technical challenges and code reviews.
Reliable transportation and eligibility to drive within the United States if required for domestic travel related to testing.
Nice to have
Experience with exploit development for embedded systems, industrial control systems, or specialized hardware interfaces.
Familiarity with government reporting templates, risk assessment frameworks, and mitigation recommendation patterns.
Knowledge of common defensive technologies such as EDR, network detection, and secure development lifecycle practices.
Background in contributing to or contributing to open-source security tools, frameworks, or disclosure processes.
Experience working in regulated environments with strict documentation, audit, and quality assurance requirements.
Practical notes
U.S. citizenship is required for this position due to the sensitive nature of national security work and public trust eligibility.
You must be able to obtain and maintain a U.S. government Public Trust Clearance, which includes a favorable background investigation.
Employment is contingent upon successful completion of all clearance and onboarding requirements.
You must be physically located in or be willing to relocate to Herndon, VA to perform the essential functions of this role.
This is a full-time opportunity that may require occasional travel within the United States for testing and customer engagement activities.
The selected candidate must be eligible to work in the United States without sponsorship at any point during employment.
This role operates in a high-sensitivity environment and requires adherence to strict operational security protocols at all times.