Engineering Roles

Vulnerability Researcher

In this role, you’ll hunt for the flaws that matter in software, firmware, and hardware—then prove them. You’ll take understood targets and probe them for weaknesses, develop proofs of concept and exploit chains, and reason about how a real adversary would chain small defects into mission impact. You’ll work at the intersection of offense and defense, in tightly cleared environments against real targets.

The Work
You’ll discover vulnerabilities that no scanner will find. Sometimes you start with a reverse engineer’s analysis of a binary or firmware image and hunt for the memory-corruption, logic, or protocol flaw that breaks the system’s assumptions. Sometimes you’re collaborating with an advanced AI model to find the edge that leads to a vulnerability. You may be fuzzing at scale, building harnesses and conducting coverage-guided campaigns against targets that fight back. Sometimes the vulnerability lives in a state machine, a trust boundary, or the seam between two components, and you’ll have to model the whole system to see it. Once you find a flaw, you prove it: a reliable trigger, a working proof of concept, and an accurate reassessment of exploitability and impact. Your toolkit spans LLMs, C, Python, Rust, assembly, fuzzers, and whatever instrumentation the target demands.
You’ll spend some of your time seeking novel bug classes and developing new techniques to reach targets others can’t. You’ll spend some of your time hardening your findings into dependable capability. And you’ll document what you find with enough clarity that operators can act on it.
Who You Work With
You’ll collaborate with reverse engineers who hand you the deep understanding of a target, software engineers who turn your findings into dependable capabilities, and program managers who translate your discoveries into mission impact. You’ll have access to lab equipment—hardware test benches, emulation platforms, fuzzing infrastructure, software-defined instrumentation—and you’ll interact with customers who bring you real-world targets and constraints.
What We Look For
Vulnerability research and exploit development experience across binaries, firmware, or protocols, fluency in C, Python, Rust, and assembly, and command of fuzzing and program-analysis techniques; reverse-engineering experience and familiarity with tools like Ghidra and IDA Pro are valued, as is familiarity with the application of AI to cyber issues.

Open Positions

Ready to find your place?

Browse every open position for this role across all capability areas and all U.S. locations.

No current job openings were found.