Jobgether

Sr. Vulnerability Researcher

Jobgether

vulnerability researchexploit developmentreverse engineeringnetwork protocolsfirmware analysisC#Pythondynamic analysisGhidraTCP/IP

About the Role

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Vulnerability Researcher based in United States. This senior security research role focuses on discovering and understanding previously unknown vulnerabilities before adversaries can exploit them. You will work within an experienced vulnerability research and threat intelligence team focused on active cyber defense. The position spans exposure analysis, reverse engineering, vulnerability discovery, and original exploit development across diverse platforms and devices. You will investigate firmware, embedded systems, operating systems, and network protocols while developing practical defensive intelligence and security artifacts. A key part of the role involves advancing agentic and automated techniques to scale vulnerability discovery and exploit development. Your research will contribute to exploit intelligence, detection capabilities, and tools used to help organizations identify and mitigate emerging threats. This is a fully remote opportunity for a technically curious researcher who enjoys solving difficult problems independently and collaborating with highly skilled security experts. This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Vulnerability Researcher based in United States. This senior security research role focuses on discovering and understanding previously unknown vulnerabilities before adversaries can exploit them. You will work within an experienced vulnerability research and threat intelligence team focused on active cyber defense. The position spans exposure analysis, reverse engineering, vulnerability discovery, and original exploit development across diverse platforms and devices. You will investigate firmware, embedded systems, operating systems, and network protocols while developing practical defensive intelligence and security artifacts. A key part of the role involves advancing agentic and automated techniques to scale vulnerability discovery and exploit development. Your research will contribute to exploit intelligence, detection capabilities, and tools used to help organizations identify and mitigate emerging threats. This is a fully remote opportunity for a technically curious researcher who enjoys solving difficult problems independently and collaborating with highly skilled security experts. Accountabilities Conduct original vulnerability research to identify previously unknown security weaknesses across operating systems, platforms, networking equipment, embedded systems, and devices. Analyze exposed attack surfaces and investigate vulnerabilities from initial discovery through validation and exploit development. Reverse engineer firmware, software, compiled binaries, and appliances using static and dynamic analysis techniques. Develop original exploit code to demonstrate and weaponize newly discovered vulnerabilities for defensive intelligence purposes. Create supporting security artifacts such as network detection rules, version scanners, Docker containers, ASM queries, and other technical outputs associated with vulnerability research. Acquire, extract, unpack, and analyze firmware while investigating embedded architectures, network protocols, and unauthenticated attack surfaces. Perform dynamic analysis and debugging against embedded or emulated environments to validate vulnerability hypotheses and exploitation techniques. Apply agentic AI and automated approaches to increase the scale, speed, and effectiveness of vulnerability discovery and exploit development. Collaborate with experienced vulnerability researchers and threat intelligence specialists on complex technical investigations and research initiatives. Contribute to the advancement of vulnerability research methodologies, tooling, and automated approaches. Communicate research findings clearly and contribute technical expertise to high-impact security research projects. Work independently on complex research problems while contributing effectively within a small, highly technical remote team. Requirements 5+ years of full-time professional vulnerability research experience, particularly involving networking device firmware, embedded Linux or RTOS environments, and/or network protocols. Demonstrable experience applying agentic or automated approaches to vulnerability discovery and exploit development. Proven experience developing original exploit code and demonstrating practical exploitation techniques. Strong experience acquiring, unpacking, analyzing, and debugging firmware and network appliances. Familiarity with embedded architectures such as MIPS and ARM, along with firmware extraction and unpacking tools such as Binwalk. Experience with dynamic analysis and debugging of embedded or emulated targets, including tools such as QEMU. Solid understanding of networking technologies and protocols, including TCP/IP, routing protocols, VPN technologies such as IPsec and SSL-VPN, and SNMP. Advanced reverse engineering capabilities, including static and dynamic analysis of compiled binaries and firmware; experience with Ghidra is particularly valuable. Strong knowledge of memory corruption and other vulnerability classes, including stack and heap overflows, use-after-free, type confusion, integer errors, command and path injection, authentication weaknesses, and logic flaws. Strong programming skills in C/C++ and proficiency in at least one scripting language such as Python. Ability to work effectively on complex technical projects in a remote environment, both independently and within small collaborative teams. Strong analytical thinking, intellectual curiosity, problem-solving ability, and willingness to investigate technically challenging problems. Prior cybersecurity experience within a security vendor, government organization, or comparable environment is preferred. A demonstrated record of discovering and documenting new vulnerabilities, such as CVEs, security advisories, exploits, or published research, is highly desirable. Ability to provide examples of previous vulnerability research or exploit development work is a plus. Candidates must be able to satisfy applicable U.S. export control, sanctions, and other legal or contractual requirements associated with access to certain technologies. Benefits Fully remote position within the United States. Generous and flexible paid time off. Retirement contributions, including a 401(k) plan with employer match in the United States. Comprehensive healthcare coverage. Generous paid parental leave. Remote-friendly working environment with flexibility. Support for home-office expenses such as phone and internet costs. Opportunity to work alongside experienced vulnerability researchers, hackers, and threat intelligence specialists. Exposure to cutting-edge vulnerability research, exploit intelligence, reverse engineering, and agentic security technologies. Opportunity to conduct original research and contribute to the broader cybersecurity community. Benefits may vary according to country or employment location and are confirmed during the offer process. How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1

You'll be redirected to Jobgether's application page

Job Details

Salary

Not disclosed

Location

United States

Job type

Full-time

Category

Security Engineering

Experience

5+ years

Posted

Today

Job Highlights

  • 5+ years level role
  • 100% Remote — open to candidates in United States
  • Full-time position

About Jobgether

This job is hosted by Jobgether. Clicking Apply opens their site.

More jobs from Jobgether on RC9

Remote Work Style

Mixed

Mix of flexible and scheduled meetings

Your Match

See how well your skills line up with this role, and what you're missing.

AI Cover Letter

Generate a cover letter tailored to this job from your profile.