Experienced Vulnerability Researcher

CoreTech Security Services

Salisbury

Hybrid

GBP 70,000 - 110,000

Full time

7 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

25 days holiday
Private medical
8% company pension
Relocation support
Training and development
Cycle-to-work

Job summary

CoreTech Security Services in the United Kingdom is seeking an experienced Vulnerability Researcher to join a world-class team of developers and researchers. You will work on bespoke security research projects for high-profile clients, applying reverse engineering, fuzzing, and exploit development where appropriate.

The role supports hybrid and remote work near Salisbury; candidates should be proficient in Ghidra/IDA Pro, C/C++, Linux internals, and mobile architectures.

Qualifications

  • Experience in reverse engineering with Ghidra or IDA Pro.
  • Strong knowledge of ARM, AARCH64, x86/x64 and MIPS.
  • Background in bug hunting and vulnerability research.
  • Ethical hacking with web/network technologies.

Responsibilities

  • Reverse engineer in IDA Pro or Ghidra to identify security flaws.
  • Audit C/C++ source code and identify weaknesses.
  • Develop novel tools and techniques for vulnerability research.
  • Collaborate with researchers and engineers on projects.
  • Design niche solutions with real-world impact.
  • Lead technical projects and mentor teammates.

Skills

Reverse engineering
Ghidra
IDA Pro
C/C++
Linux internals
ARM
x86/x64
MIPS
Ethical hacking
Bug hunting
Exploit techniques
Python

Tools

Ghidra
IDA Pro
Python

Job description

Working for CoreTech as a vulnerability researcher will see you join a world-class team of developers and vulnerability researchers whose mission is to deliver bespoke products and research into the most interesting cyber security clients in the UK.

CoreTech is looking for candidates with a bug hunting, ethical hacking or reverse engineering background to join our vulnerability research team. We deliver bespoke and innovative solutions which enable the operational needs of our clients. Our team is highly experienced, deeply technical and has a rich history of blending rapid prototyping, security research and software engineering skills.

Our Research team use Ghidra as our tool of choice for reverse engineering and produce proof of concepts in the most suitable language for the project which could be C, C++, Python or assembly code. The role requires an inquisitive mindset and enthusiasm for solving difficult research tasks.


Typical tasks might include
  • Developing a deep understanding of how Android mobile devices work, from applications to kernel.
  • Reverse engineering proprietary binaries using your knowledge of ARM, ARM64, and MIPS.
  • Auditing C and C++ source code, spotting security flaws that others haven’t.
  • Growing the team’s capabilities by developing novel tools and techniques to enable cutting-edge vulnerability research.
  • Working in tandem with other hugely talented vulnerability researchers and software engineers.
  • Designing and producing niche solutions with immediate real-world impact.
An ideal candidate will
  • Have a passion for cyber security.
  • Thriveon solving difficult and complex problems.
  • Havea genuine interest in bug hunting and be familiar with recent vulnerabilities.
  • Enjoy sharing their knowledge and working with team members.
Your Experience
  • Reverse engineering in IDA Pro or Ghidra.
  • Familiarity with one or more of ARM, AARCH64, x86, x64 and MIPS.
  • Knowledge of bug hunting / vulnerability research.
  • Ethical hacking, including familiarity with web/network technologies.
  • Knowledge of exploitation techniques and mitigations.
  • Experience and knowledge of Linux and its internals.
  • Experience and knowledge of Android or iOS and its internals.
  • A good understanding of the C or C++ language.

This vacancy is for experienced researchers and will require skills and experience in several of the areas listed as well as the ability to lead technical projects. If you do not meet these requirements please check our other vacancies which have different skills requirements.

Work Benefits
  • Promotions are based on technical excellence and reviewed regularly.
  • 25 days holiday per year (with bank holidays on top), option to buy up to 5 days per year.
  • Level up with an extra day of holiday per year, up to an extra 5 days, starting from 2 years' service.
  • We offer financial support to cover HMRC allowable costs of relocating if you’re moving to the area.
  • Training and development opportunities to support your career aspirations
  • O'Reilly books subscription which provides access to huge range of technical books
  • Regular events including internal technical conferences, company socials and pizza-fuelled lunchtime seminars.
  • Free seasonal fruit, tea, coffee, milk, squash and hot chocolate.
Health Benefits - Private medical including access to:
  • Private online GP, and a helpline to speak with various healthcare professionals.
  • Physiotherapists, osteopaths or chiropractors for muscle, bone, and joint pain.
  • Mental health - counselling, and specialist consultations and treatment with psychologists and cognitive behavioural therapists.
  • Annual Health assessment.
Financial Benefits
  • A company bonus scheme so that everybody is rewarded for company success. This is an annual award that is based on the company hitting its targeted forecast. We have achieved this every year to date.
  • 8% company contribution to pension with no minimum requirement for employee contribution.
  • Death in Service cover of 4x base salary.
Lifestyle Benefits
  • Enhanced maternity/paternity/adoption leave: 12 weeks maternity leave at full pay as soon as you join, further enhanced to 20 weeks full pay from 2 years’ service. 2 weeks paternity leave at full pay as soon as you join, further enhanced to 4 weeks full pay from 2 years’ service.
  • Enhanced cycle-to-work scheme including the ability to purchase a bike over £1,000 (e-bikes, specialist cycles and trikes allowed).

Salary

This vacancy is for an experienced Vulnerability Researcher; we are able to support market-leading salaries for every grade within our sector/location. We reward staff based on technical excellence and not years of experience, so it's important to us to speak with you to see which grade you would fit into - it's not always obvious from a CV! Your interviewer will spend time during your first interview speaking with you about how your skills and experience map against our grades, and discuss a salary band so that you know early what you can expect if you receive an offer from us. The technical interview will provide a deeper assessment of your skills against your mapped grade which ultimately determines whether you receive an offer and the exact salary.

Location

We are based near Salisbury, this role will have the opportunity for remote and hybrid working.

Additional Details

Our interview process is quick and to the point: if you look like a good fit for the role, we'll schedule a brief call to discuss it in more detail and answer any questions you may have. If that goes well, we'll arrange a technical interview to understand your level of experience. We aim to get back to you with an answer within a couple of days of the technical interview.

Please note, due to sensitivity of the role, successful applicants must be British Citizens and willing to undergo extensive background checks to obtain a security clearance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Experienced Vulnerability Researcher
Experienced Vulnerability Researcher

CoreTech Security • Salisbury

Hybrid
GBP 70,000 - 110,000
Promotions for technical excellence
25 days holiday plus bank holidays
Relocation support to area
+4
Junior Vulnerability Researcher - September 2027
Junior Vulnerability Researcher - September 2027

CoreTech Security • Cheltenham

On-site
GBP 32,000 - 42,000
Promotions based on technical merit
25 days holiday + bank holidays
Relocation cost support
+8
Junior Cyber Security Researcher - September 2027
Junior Cyber Security Researcher - September 2027

CoreTech Security Services • Cheltenham

On-site
GBP 34,000 - 42,000
25 days holiday + 5"buy" days
Relocation support
Training & development
+9
Junior Cyber Security Researcher - September 2027
Junior Cyber Security Researcher - September 2027

CoreTech Security • Cheltenham

On-site
GBP 34,000 - 42,000
Promotions based on technical merit
25 days holiday + bank holidays
Relocation support
+10
Exploit Developer
Exploit Developer

慨正橡扯 • Cheltenham

On-site
GBP 50,000 - 75,000
25 days holiday plus bank holidays
O'Reilly books subscription
Financial support for relocation
+4
Cyber Security Researcher
Cyber Security Researcher

慨正橡扯 • Salisbury

On-site
GBP 60,000 - 80,000
25 days holiday per year
Financial support for relocation
Training and development opportunities
+2
Cyber Security Researcher
Cyber Security Researcher

慨正橡扯 • Cheltenham

On-site
GBP 40,000 - 80,000
25 days holiday
Financial support for relocation
Training and development opportunities
+1
Cyber Security Researcher — Cutting-Edge R&D & Impact
Cyber Security Researcher — Cutting-Edge R&D & Impact

慨正橡扯 • Cheltenham

On-site
Operational Cyber Vulnerability Researcher
Operational Cyber Vulnerability Researcher

Cyber UK • Gloucester

On-site
GBP 50,000 - 70,000
Dedicated training budget
Flexible working hours
Private medical and dental insurance
+2
Senior Vulnerability Researcher – Remote/Hybrid
Senior Vulnerability Researcher – Remote/Hybrid

CoreTech Security • Salisbury

Hybrid
GBP 70,000 - 110,000
Promotions for technical excellence
25 days holiday plus bank holidays
Relocation support to area
+4