Vulnerability Researcher

Woburn, Massachusetts, United States

Applications have closed

STR is hiring hardware, software and firmware Vulnerability Researchers who enjoy working on hard problems and unique targets to perform analysis, discovery, development, and remediation of cyber physical system vulnerabilities.

Duties will include:

  • Working in small research teams to reverse engineer and identify vulnerabilities in complex software, firmware, and/or hardware targets
  • Performing vulnerability research (VR), proof of concept generation, and vulnerability mitigation on a variety of challenging targets ranging from Windows/Linux binaries to embedded firmware on non-traditional information systems
  • Staying up to date on current and emerging vulnerabilities and exploitation techniques
  • Documenting, demonstrating, and presenting research

Required Skills and Experience:

  • Ability to obtain a Security Clearance
  • BS, MS or PhD in Computer Science, Computer Engineering, Cybersecurity or related field (or equivalent)
  • 2+ years of relevant experience
  • Knowledge of performing VR using disassemblers such as Binary Ninja, Ghidra, or IDA
  • Knowledge of performing static / dynamic / symbolic program analysis
  • Knowledge of with common vulnerability primitives and their expressions in code
  • Proficiency in one or more scripting languages for development of proof-of-concept exploits demonstrating the vulnerability

Desired Skills and Experience:

  • Active Security Clearance at the Secret or Top Secret (TS) level
  • Knowledge of reverse engineering and anti-reverse engineering techniques
  • Operating system internals including memory/process/thread management
  • Knowledge of binary file structures and formats
  • Implant or software patch development
  • Understanding of common networks and protocols
  • Understanding of standard exploit techniques for proof-of-concept vulnerability weaponization
  • Track record of vulnerability discovery, exploitation examples
  • Embedded systems or firmware analysis
  • JTAG debugging, firmware flashing or extraction
  • Assembly Languages (x86, ARM, PowerPC, etc.)

All STR employees may be subject to COVID-19 vaccination requirement in response to Executive Order 14042 and accompanying Task Force Guidance, unless a medical or religious accommodation is formally approved by STR.

STR is a growing technology company with locations near Boston, MA, Arlington, VA, near Dayton, OH, Melbourne, FL, and Carlsbad, CA. We specialize in advanced research and development for defense, intelligence, and national security in: cyber; next generation sensors, radar, sonar, communications, and electronic warfare; and artificial intelligence algorithms and analytics to make sense of the complexity that is exploding around us.

STR is committed to creating a collaborative learning environment that supports deep technical understanding and recognizes the contributions and achievements of all team members. Our work is challenging, and we go home at night knowing that we pushed the envelope of technology and made the world safer.

STR is not just any company. Our people, culture, and attitude along with their unique set of skills, experiences, and perspectives put us on a trajectory to change the world. We can't do it alone, though - we need fellow trailblazers. If you are one, join our team and help to keep our society safe! Visit us at www.str.us for more info.

STR is an equal opportunity employer. We are fully dedicated to hiring the most qualified candidate regardless of race, color, religion, sex (including gender identity, sexual orientation and pregnancy), marital status, national origin, age, veteran status, disability, genetic information or any other characteristic protected by federal, state or local laws.

If you need a reasonable accommodation for any portion of the employment process, email us at appassist@str.us and provide your contact info.

Pursuant to applicable federal law and regulations, positions at STR require employees to obtain national security clearances and satisfy the requirements for compliance with export control and other applicable laws.

Tags: Analytics Artificial Intelligence Clearance Compliance Computer Science Exploit Exploits Ghidra Linux PhD Reverse engineering Scripting Security Clearance Top Secret Vulnerabilities Windows

Perks/benefits: Career development

Region: North America
Country: United States
Job stats:  9  1  0
Category: Research Jobs

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.