Cleared Vulnerability Research Engineer

1 hour, 21 minutes ago
Full-time
Lead
Software Development
Bugcrowd

Bugcrowd

Bugcrowd provides a crowdsourced cybersecurity platform that connects organizations with elite security researchers to enhance security measures through managed bug bounty programs, penetration testing, and vulnerability disclosure initiatives.

Internet Software & Services
1K-5K
Founded 2012
$79M raised

Description

  • Design, develop, and validate novel vulnerability discovery and exploitation capabilities against complex software and systems.
  • Perform expert reverse engineering of binaries at the x86-64, ARM64, and related architecture levels using industry-standard tools.
  • Identify and exploit real-world vulnerability classes such as use-after-free, type confusion, integer truncation, and buffer overflow.
  • Discover new vulnerabilities in complex systems rather than only exploiting known issues.
  • Apply current vulnerability research to uncover new instances of known vulnerability classes.
  • Use both manual analysis and automated techniques such as fuzzing for vulnerability discovery.
  • Code and debug complex functions in C, Python, and Assembly.
  • Independently scope, research, experiment, validate, and iterate on research objectives.
  • Travel to customer sites and perform work on-site for extended periods as required.

Requirements

  • Experience with reverse engineering binaries using tools such as Binary Ninja, Ghidra, or IDA Pro.
  • Strong understanding of stack and heap objects and exploit-relevant vulnerabilities.
  • Demonstrated ability to discover new vulnerabilities in complex systems.
  • Experience with both manual analysis and automated vulnerability discovery techniques such as fuzzing.
  • Ability to code and debug in C, Python, and Assembly for x86-64, ARM, and similar environments.
  • Ability to independently translate an under-defined mission objective into a concrete technical capability.
  • Comfort operating with minimal supervision and incomplete problem definitions.
  • TS/SCI clearance required; inactive SCI is acceptable if SCI-clearable.
  • Ability to travel to customer sites as required and work on-site in cleared spaces for extended periods.
  • Experience with exploit development and vulnerability research is strongly implied as a core qualification.

Benefits

  • Base salary range of $154,800 to $193,500.
  • Eligibility for a discretionary bonus program or commission plan based on individual and organizational performance.
  • Remote work-from-home arrangement with travel to a customer location in Alabama.
  • Reasonable accommodations available for qualified individuals with disabilities.
  • Comprehensive background check process for positions involving sensitive information.
  • Opportunity to work in a collaborative, inclusive environment that values diverse backgrounds and perspectives.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Staff Research Scientist, Voyage AI

MongoDB 1K-5K Internet Software & Services

MongoDB’s Voyage AI team is seeking a Staff Research Scientist to advance next-generation AI models for embedding, reranking, and information retrieval, with work spanning research and production deployment in the U.S. or Palo Alto.

AWS Azure Deep Learning GCP LLM Machine Learning MongoDB Neural Networks NLP Python
6 minutes ago

Senior Researcher

STR 251-1K Aerospace & Defense

STR's Sensors Division is seeking a Senior Researcher to develop and apply autonomy capabilities for national security simulations and related defense applications.

Linux Machine Learning MATLAB Python PyTorch
1 hour, 17 minutes ago

Senior Research Engineer

STR 251-1K Aerospace & Defense

STR’s APEX Group is seeking a Senior Research Engineer to develop advanced radar sensing concepts and demonstrations for defense research programs.

Machine Learning MATLAB Python
1 hour, 21 minutes ago

DevSecOps Engineer

Alpaca 51-250 Capital Markets

Alpaca is seeking a DevSecOps Engineer to strengthen the security, reliability, and resilience of its cloud platform and CI/CD systems as the company scales its brokerage infrastructure globally.

CI/CD DevSecOps Go Kubernetes Penetration Testing Python Secrets Management Terraform
1 hour, 21 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers