Sr. Exploit Developer (US)

1 month, 2 weeks ago
Full-time
Senior
Software Development
VulnCheck

VulnCheck

VulnCheck offers cutting-edge vulnerability intelligence to outpace adversaries, empowering defenders with crucial insights to focus on critical vulnerabilities worldwide.

Internet Software & Services
11-50
Founded 2021

Description

  • Reverse engineer software to identify the root cause of vulnerabilities.
  • Author original exploits for initial access vulnerabilities when little or no public proof-of-concept code exists.
  • Implement detections such as Suricata and Snort signatures and YARA rules to identify exploitation on the wire.
  • Write attack surface management queries using tools such as Shodan, Census, FOFA, and ZoomEye to find vulnerable systems.
  • Contribute to local and other exploit development efforts beyond the initial access focus area.
  • Work on the open-source go-exploit framework.
  • Collaborate with a seasoned team of hackers and threat researchers on high-visibility security projects.
  • Conduct research and develop tools to improve vulnerability enrichment and mapping.

Requirements

  • Prior experience writing exploit code for RCE or initial access vulnerabilities that do not require authentication.
  • Background in reverse engineering and exploit development.
  • Experience working on technical projects remotely, independently, and on small teams.
  • Prior cybersecurity work experience at a vendor or in government is preferred.
  • Ability to share example exploit code written is preferred.
  • Must be able to meet U.S. export control, sanctions, and other applicable legal or contractual authorization requirements if needed.
  • 100% remote role, with priority given to candidates based in Massachusetts, Maryland, or Austin, TX.

Benefits

  • Unlimited PTO.
  • 401(k) plan with company match.
  • Comprehensive healthcare coverage.
  • Generous paid parental leave.
  • Remote-friendly work environment with flexibility.
  • Expense reimbursement for cell phone and internet.
  • Ongoing professional development, coaching, and learning resources.
  • Opportunities for career advancement within a fast-growing team.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Saviynt IAM Specialist

The Missing Link 51-250 Internet Software & Services

The Missing Link is seeking a Security Engineer - Saviynt to support large enterprise identity governance initiatives, design and deliver Saviynt-based solutions, and strengthen its growing cyber security practice.

Active Directory Azure Cybersecurity JavaScript PowerShell REST API SAP SQL
13 hours, 50 minutes ago

AI Security Architect (REMOTE - United States)

EnableComp 251-1K Insurance

EnableComp is seeking a remote AI Security Architect to secure and govern its AI and machine learning initiatives within its healthcare revenue cycle management environment.

Azure Cybersecurity HIPAA LLM Machine Learning
14 hours, 6 minutes ago

Senior Infrastructure Security Engineer

Dropbox 1K-5K Internet Software & Services

Dropbox is hiring a Security Engineer to secure its AI and agentic infrastructure while helping protect products and users across cloud and on-prem environments.

Bash CI/CD CrowdStrike Go Java Kubernetes Linux LLM Node.js OAuth OpenID Connect OWASP Python Ruby Rust SIEM
14 hours, 6 minutes ago

Staff, Security Engineer

Fullscript 251-1K Health Care Providers & Services

Fullscript is hiring a Staff Security Engineer to lead hands-on security engineering across its healthcare technology platform, shaping secure product development and protecting systems that support practitioners and patients.

AWS GitHub GitLab GraphQL JavaScript Node.js Penetration Testing Ruby on Rails
14 hours, 35 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers