Cyber Vulnerability Researcher

SG2 Recruiting

California (MO)

On-site

USD 110,000 - 120,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Lumbee Holdings seeks a Cyber Vulnerability Researcher to advance vulnerability discovery, binary analysis, and exploitation across embedded and RTOS platforms in support of Marine Corps testing at Camp Pendleton, CA.

Role requires active DoD Secret security clearance (Top Secret preferred) and hands-on experience with Ghidra, IDA Pro, and related tools. Responsibilities include research, reporting, and remediation guidance, with on-site work at Camp Pendleton.

Qualifications

  • Active DoD Secret Security Clearance (ability to obtain and maintain Top Secret preferred).
  • At least five years using Ghidra for vulnerability research, binary analysis, and reverse engineering.

Responsibilities

  • Conduct Original Vulnerability Research using static/dynamic analysis with tools like Ghidra, IDA Pro, WinDbg, OllyDbg, and gdb.
  • Execute fuzzing campaigns and develop PoC exploits in isolated environments to validate impact.
  • Analyze low-level assembly across x86/x64/ARM/MIPS/PowerPC to identify memory corruption and bypass strategies (DEP, ASLR, stack canaries).
  • Assess embedded & RTOS platforms (VxWorks, RTOSs, Android, Linux, Windows) beyond commercial scanners.
  • Analyze code and write reports outlining CWEs and security posture assessments for program offices.
  • Automate research workflows with Python, Perl, Ruby, or C/C++ to speed up discovery cycles.
  • Publish findings in Vulnerability Survey Reports and technical briefings with remediation guidance.

Skills

Ghidra
C/C++
Python
Reverse engineering

Tools

IDA Pro
WinDbg
OllyDbg
gdb

Job description

THIS POSITION REQUIRES AN ACTIVE US GOVERNMENT SECURITY CLEARANCE. IF YOU DO NOT HAVE A CLEARANCE, PLEASE DO NOT APPLY.

Cyber Vulnerability Researcher

SG2 Recruiting has partnered with Lumbee Holdings to spearhead the search for a visionary Cyber Vulnerability Researcher. This is a pivotal opportunity to join a dynamic team and directly influence the company’s next phase of growth. If you are a strategic thinker ready to make a tangible impact, we want to hear from you.

About the Company

At Lumbee Holdings, we deliver mission-critical logistical, technical, and analytical support to empower strategic government and defense operations. Our culture is built on continuous improvement, operational integrity, and dedicated service to key defense stakeholders. When you join our team, you become part of a collaborative environment where your expertise directly supports military readiness and system efficiency.

About the Role

As a Cyber Vulnerability Researcher, you will deliver advanced vulnerability research and low-level exploit development capability in support of the MCTSSA Cyber Branch’s adversarial testing mission at Camp Pendleton, CA. Your core purpose is to extend the team’s offensive depth beyond tool-based penetration testing into original vulnerability discovery, binary analysis, and exploitation of embedded systems, real-time operating systems (RTOS), and custom platform architectures. Working in close coordination with vulnerability assessment analysts and penetration testers, you will translate research-derived findings into actionable assessment products and technically defensible remediation recommendations for Marine Corps Program Offices.

Responsibilities
  • Conduct Original Vulnerability Research: Perform static and dynamic analysis using tools like Ghidra, IDA Pro, WinDbg, OllyDbg, and gdb to identify exploitable weaknesses in Marine Corps software, firmware, and embedded platforms.
  • Execute Fuzzing & Exploitation: Develop and execute fuzz testing campaigns to discover zero-day vulnerabilities, and create proof-of-concept (PoC) exploits in isolated research environments to validate mission impact.
  • Analyze Low-Level Assembly Code: Examine assembly architectures (x86, x64, ARM, MIPS, PowerPC) to identify memory corruption, logic flaws, and bypass strategies for DEP, ASLR, and stack canaries.
  • Assess Embedded & RTOS Platforms: Research weapons systems, C5ISR platforms, embedded systems, and real-time operating systems (VxWorks, RTOSs, Android, Linux, Windows) that commercial COTS scanners cannot evaluate.
  • Analyze Code & Write Reports: Conduct static/dynamic source code analysis to identify CWEs, produce Code Review Reports, and deliver summary Security Posture Assessments to guide program office decision-making.
  • Automate Research Workflows: Utilize Python, Perl, Ruby, or C/C++ to build custom scripts and tools that accelerate research discovery cycles and improve methodology repeatability.
  • Publish Research Findings: Synthesize research into Vulnerability Survey Reports, technical briefings, attack path analyses, and mitigation strategies compliant with Security Classification Guides.
Qualifications
  • Security Clearance: Active DoD Secret Security Clearance (ability to obtain and maintain Top Secret preferred).
  • Tooling Expertise: At least five (5) years of hands-on experience using Ghidra for vulnerability research, binary analysis, and reverse engineering.
  • Programming & Debugging: Proficiency in C or C++, scripting languages (Python, Perl, or Ruby), assembly languages (x86, x64, ARM, MIPS, PowerPC), and debuggers (gdb, WinDbg, OllyDbg).
  • System & Protocol Knowledge: Experience with PC/embedded system architectures, OS internals, network protocols, fuzzing techniques, and common mitigation techniques (DEP, ASLR, stack canaries).
  • Location/On-Site: Willingness and ability to work 100% on-site at Camp Pendleton, CA.
Required Skills
  • Security Clearance: Active DoD Secret Security Clearance (ability to obtain and maintain Top Secret preferred).
  • Tooling Expertise: At least five (5) years of hands-on experience using Ghidra for vulnerability research, binary analysis, and reverse engineering.
  • Programming & Debugging: Proficiency in C or C++, scripting languages (Python, Perl, or Ruby), assembly languages (x86, x64, ARM, MIPS, PowerPC), and debuggers (gdb, WinDbg, OllyDbg).
  • System & Protocol Knowledge: Experience with PC/embedded system architectures, OS internals, network protocols, fuzzing techniques, and common mitigation techniques (DEP, ASLR, stack canaries).
  • Location/On-Site: Willingness and ability to work 100% on-site at Camp Pendleton, CA.
Preferred Skills
  • Certifications: Advanced software assurance credentials such as OSED, OSEE, GREM, or equivalent.
  • Advanced Research Skills: Experience developing IDA Pro plugins/scripts, hardware/FPGA debugging, or 10+ years of low-level reverse engineering and systems programming experience.
  • Competitions & Tradecraft: Active participation in Capture The Flag (CTF) or software hacking competitions.
  • Military & Veteran Equivalents: We strongly encourage transitioning service members and veterans to apply! Candidates with backgrounds in the following military occupational specialties (MOS), Air Force Specialty Codes (AFSC), and Navy Enlisted Classifications (NEC) are exceptionally well-suited for this role:
  • U.S. Army MOS/WO: 17C (Cyber Operations Specialist), 170D (Cyber Warfare Technician Warrant Officer).
  • U.S. Air Force AFSC: 1B4X1 (Cyber Warfare Operations).
  • U.S. Navy Rating/Designator: CWT (Cyber Warfare Technician) or CWE (Cyber Warfare Engineer).
Pay range and compensation package
  • Salary Range: $110,000.00 To $120,000.00 Annually.
  • Benefits: Comprehensive benefits package (detailed terms and eligibility provided during onboarding).
Equal Opportunity Statement

Lumbee Holdings is an Equal Opportunity Employer. We do not discriminate in employment opportunities or practices on the basis of race, color, religion, sex (including pregnancy, sexual orientation, or gender identity), national origin, age, disability, protected veteran status, genetic information, or any other characteristic protected by applicable federal, state, or local law. We are committed to providing reasonable accommodations to qualified individuals with disabilities in all phases of the employment process, including the application and interview phase. If you require a reasonable accommodation to participate in the application or recruitment process, please inform your recruiter or contact our HR team.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Vulnerability Researcher
Cyber Vulnerability Researcher

SG2 Recruiting • San Onofre (CA)

On-site
USD 110,000 - 120,000
Comprehensive benefits
On-site at Camp Pendleton
Cybersecurity Engineer
Cybersecurity Engineer

SG2 Recruiting • Oceanside (CA)

On-site
USD 110,000 - 120,000
Comprehensive benefits
Cybersecurity Engineer
Cybersecurity Engineer

SG2 Recruiting • California (MO)

On-site
USD 110,000 - 120,000
Vulnerability Researcher
Vulnerability Researcher

Lumbee Tribe Enterprises, Llc • California (MO)

On-site
USD 110,000 - 120,000
Cyber Vulnerability Researcher (On-Site Camp Pendleton)
Cyber Vulnerability Researcher (On-Site Camp Pendleton)

SG2 Recruiting • California (MO)

On-site
USD 110,000 - 120,000
Cyber Vulnerability Researcher & Exploit Specialist
Cyber Vulnerability Researcher & Exploit Specialist

Lumbee Tribe Enterprises, Llc • California (MO)

On-site
USD 110,000 - 120,000
Vulnerability Assessment Analyst and Penetration Tester
Vulnerability Assessment Analyst and Penetration Tester

SteelToad • Annapolis (MD)

On-site
USD 120,000 - 150,000
Medical Insurance
401(k) Plan with matching contributions
Paid Time Off
+2
Cyber Vulnerability Researcher - On-Site Camp Pendleton
Cyber Vulnerability Researcher - On-Site Camp Pendleton

SG2 Recruiting • San Onofre (CA)

On-site
USD 110,000 - 120,000
Comprehensive benefits
On-site at Camp Pendleton
Senior Vulnerability Researcher
Senior Vulnerability Researcher

Medium • Herndon (VA)

On-site
USD 130,000 - 150,000
Senior Vulnerability Researcher
Senior Vulnerability Researcher

Redhorse Corporation • Herndon (VA)

On-site
USD 120,000 - 160,000