Job Summary
This role is focused on end-to-end exploit development for real-world targets. The specialist will design, develop, and validate novel vulnerability discovery and exploitation capabilities against complex software and systems at the operating system, binary, and micro‑architectural levels. Success requires the ability to translate an under‑defined mission objective into a concrete, technically novel capability and to operate with minimal supervision, incomplete problem definitions, and delayed feedback.
Responsibilities
* Design, develop, and validate novel vulnerability discovery and exploitation capabilities.
* Conduct expert reverse engineering of binaries (x86‑64, ARM64, etc.) using industry‑standard tools.
* Identify and exploit real‑world vulnerabilities such as use‑after‑free, type confusion, integer truncation, and buffer overflow.
* Discover new, novel vulnerabilities in complex systems and rapidly understand current vulnerability research to apply findings.
* Employ both manual analysis and automated techniques (e.g., fuzzing) for vulnerability discovery.
* Code and debug complex functions in C, Python, and Assembly (x86‑64, ARM, etc.).
* Independently manage and execute research objectives, including scoping, experimentation, validation, and iteration.
* Travel to customer sites as required and perform on‑site work for extended periods.
Qualifications
* Expertise in reverse engineering of binaries using tools such as Binary Ninja, Ghidra, or IDA Pro.
* Precise understanding of stack and heap objects and exploit‑relevant vulnerabilities.
* Demonstrated ability to discover new vulnerabilities and use manual or automated techniques.
* Proficiency in coding and debugging C, Python, and Assembly.
* Ability to independently translate an under‑defined mission objective into a concrete, technically novel capability.
* Comfort operating with minimal supervision.
* TS/SCI clearance required (inactive SCI acceptable if SCI‑clearable).
Clearance & Logistics
* TS/SCI clearance required (inactive SCI acceptable if SCI‑clearable).
* Ability to travel to customer sites, including remote work‑from‑home and travel to specific locations as needed.
Pay Range Disclosure
The national estimate for the current base range for this position is $154,800 - $193,500. This position may also be eligible for a discretionary bonus program or commission plan, subject to the rules governing the program.
Equal Employment Opportunity
Bugcrowd is EOE, Disability/Age Employer. Individuals seeking employment are considered without regard to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation. The company is committed to the full inclusion of all qualified individuals and to providing reasonable accommodations for people with disabilities. #J-18808-Ljbffr
This role is focused on end-to-end exploit development for real-world targets. The specialist will design, develop, and validate novel vulnerability discovery and exploitation capabilities against complex software and systems at the operating system, binary, and micro‑architectural levels. Success requires the ability to translate an under‑defined mission objective into a concrete, technically novel capability and to operate with minimal supervision, incomplete problem definitions, and delayed feedback.
Responsibilities
* Design, develop, and validate novel vulnerability discovery and exploitation capabilities.
* Conduct expert reverse engineering of binaries (x86‑64, ARM64, etc.) using industry‑standard tools.
* Identify and exploit real‑world vulnerabilities such as use‑after‑free, type confusion, integer truncation, and buffer overflow.
* Discover new, novel vulnerabilities in complex systems and rapidly understand current vulnerability research to apply findings.
* Employ both manual analysis and automated techniques (e.g., fuzzing) for vulnerability discovery.
* Code and debug complex functions in C, Python, and Assembly (x86‑64, ARM, etc.).
* Independently manage and execute research objectives, including scoping, experimentation, validation, and iteration.
* Travel to customer sites as required and perform on‑site work for extended periods.
Qualifications
* Expertise in reverse engineering of binaries using tools such as Binary Ninja, Ghidra, or IDA Pro.
* Precise understanding of stack and heap objects and exploit‑relevant vulnerabilities.
* Demonstrated ability to discover new vulnerabilities and use manual or automated techniques.
* Proficiency in coding and debugging C, Python, and Assembly.
* Ability to independently translate an under‑defined mission objective into a concrete, technically novel capability.
* Comfort operating with minimal supervision.
* TS/SCI clearance required (inactive SCI acceptable if SCI‑clearable).
Clearance & Logistics
* TS/SCI clearance required (inactive SCI acceptable if SCI‑clearable).
* Ability to travel to customer sites, including remote work‑from‑home and travel to specific locations as needed.
Pay Range Disclosure
The national estimate for the current base range for this position is $154,800 - $193,500. This position may also be eligible for a discretionary bonus program or commission plan, subject to the rules governing the program.
Equal Employment Opportunity
Bugcrowd is EOE, Disability/Age Employer. Individuals seeking employment are considered without regard to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation. The company is committed to the full inclusion of all qualified individuals and to providing reasonable accommodations for people with disabilities. #J-18808-Ljbffr
Cleared Vulnerability Research Engineer in huntsville at Unknown Company
This position is listed as full time and able to be worked remotely.