Verified current Job

Sr. Vulnerability Researcher

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Vulnerability Researcher based in United State

Job Remote Full source details
Jobgether Source published Sep 14, 2026 Verified 3 hours ago
✓ 100% verification score · Source: jobgether (lever) · Always confirm final requirements on the original source.
Complete source information imported The available role or programme description, requirements, benefits and source facts were imported from the public official endpoint and formatted for reading.
EmploymentFull-time
Work modeRemote / location-flexible

Overview

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Vulnerability Researcher based in United State

Full job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Vulnerability Researcher based in United States. This senior security research role focuses on discovering and understanding previously unknown vulnerabilities before adversaries can exploit them. You will work within an experienced vulnerability research and threat intelligence team focused on active cyber defense. The position spans exposure analysis, reverse engineering, vulnerability discovery, and original exploit development across diverse platforms and devices. You will investigate firmware, embedded systems, operating systems, and network protocols while developing practical defensive intelligence and security artifacts. A key part of the role involves advancing agentic and automated techniques to scale vulnerability discovery and exploit development. Your research will contribute to exploit intelligence, detection capabilities, and tools used to help organizations identify and mitigate emerging threats. This is a fully remote opportunity for a technically curious researcher who enjoys solving difficult problems independently and collaborating with highly skilled security experts.

Conduct original vulnerability research to identify previously unknown security weaknesses across operating systems, platforms, networking equipment, embedded systems, and devices. Analyze exposed attack surfaces and investigate vulnerabilities from initial discovery through validation and exploit development. Reverse engineer firmware, software, compiled binaries, and appliances using static and dynamic analysis techniques. Develop original exploit code to demonstrate and weaponize newly discovered vulnerabilities for defensive intelligence purposes. Create supporting security artifacts such as network detection rules, version scanners, Docker containers, ASM queries, and other technical outputs associated with vulnerability research. Acquire, extract, unpack, and analyze firmware while investigating embedded architectures, network protocols, and unauthenticated attack surfaces. Perform dynamic analysis and debugging against embedded or emulated environments to validate vulnerability hypotheses and exploitation techniques. Apply agentic AI and automated approaches to increase the scale, speed, and effectiveness of vulnerability discovery and exploit development. Collaborate with experienced vulnerability researchers and threat intelligence specialists on complex technical investigations and research initiatives. Contribute to the advancement of vulnerability research methodologies, tooling, and automated approaches. Communicate research findings clearly and contribute technical expertise to high-impact security research projects. Work independently on complex research problems while contributing effectively within a small, highly technical remote team. Requirements 5+ years of full-time professional vulnerability research experience, particularly involving networking device firmware, embedded Linux or RTOS environments, and/or network protocols. Demonstrable experience applying agentic or automated approaches to vulnerability discovery and exploit development. Proven experience developing original exploit code and demonstrating practical exploitation techniques. Strong experience acquiring, unpacking, analyzing, and debugging firmware and network appliances. Familiarity with embedded architectures such as MIPS and ARM, along with firmware extraction and unpacking tools such as Binwalk. Experience with dynamic analysis and debugging of embedded or emulated targets, including tools such as QEMU. Solid understanding of networking technologies and protocols, including TCP/IP, routing protocols, VPN technologies such as IPsec and SSL-VPN, and SNMP. Advanced reverse engineering capabilities, including static and dynamic analysis of compiled binaries and firmware; experience with Ghidra is particularly valuable. Strong knowledge of memory corruption and other vulnerability classes, including stack and heap overflows, use-after-free, type confusion, integer errors, command and path injection, authentication weaknesses, and logic flaws. Strong programming skills in C/C++ and proficiency in at least one scripting language such as Python. Ability to work effectively on complex technical projects in a remote environment, both independently and within small collaborative teams. Strong analytical thinking, intellectual curiosity, problem-solving ability, and willingness to investigate technically challenging problems. Prior cybersecurity experience within a security vendor, government organization, or comparable environment is preferred. A demonstrated record of discovering and documenting new vulnerabilities, such as CVEs, security advisories, exploits, or published research, is highly desirable. Ability to provide examples of previous vulnerability research or exploit development work is a plus. Candidates must be able to satisfy applicable U.S. export control, sanctions, and other legal or contractual requirements associated with access to certain technologies. Benefits Fully remote position within the United States. Generous and flexible paid time off. Retirement contributions, including a 401(k) plan with employer match in the United States. Comprehensive healthcare coverage. Generous paid parental leave. Remote-friendly working environment with flexibility. Support for home-office expenses such as phone and internet costs. Opportunity to work alongside experienced vulnerability researchers, hackers, and threat intelligence specialists. Exposure to cutting-edge vulnerability research, exploit intelligence, reverse engineering, and agentic security technologies. Opportunity to conduct original research and contribute to the broader cybersecurity community. Benefits may vary according to country or employment location and are confirmed during the offer process.

Tips for this job

Practical Job and Scholarship guidance. These tips do not replace official rules or create new eligibility requirements.

  1. Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
  2. Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
  3. Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
  4. Apply through the original employer or official recruitment destination shown on this page.

Verification notes

laptop-ats-crawler v3

Original authoritative source

Job and Scholarship is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.

jobgether (lever) ↗

Browse current Job and Scholarship listings from jobgether (lever) →

More ways to save

Discover deals, coupons and free courses on our sister site.

Explore DealVorio
Save more with DealVorio: deals, coupons, free courses, apps and books