Cyber Vulnerability Researcher

SG2 Recruiting

San Onofre (CA)

On-site

USD 110,000 - 120,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Comprehensive benefits
On-site at Camp Pendleton

Job summary

Lumbee Holdings seeks a Cyber Vulnerability Researcher to deliver advanced vulnerability research and exploit development for the MCTSSA Cyber Branch at Camp Pendleton, CA. You will expand offensive depth beyond tool-based testing through vulnerability discovery and analysis of embedded systems and RTOS.

You will translate findings into actionable remediation recommendations for Marine Corps program offices and publish vulnerability surveys and technical briefs.

Qualifications

  • Active DoD Secret Security Clearance (Top Secret preferred).
  • At least five years of hands-on vulnerability research using Ghidra.
  • Proficiency in C/C++, scripting (Python, Perl, or Ruby), and multiple debuggers (gdb, WinDbg, OllyDbg).
  • Experience with PC/embedded system architectures, OS internals, networks, fuzzing, and mitigations (DEP, ASLR, stack canaries).

Responsibilities

  • Conduct original vulnerability research with static and dynamic analysis tools.
  • Develop and execute fuzz testing campaigns and PoC exploits in isolated research environments.
  • Analyze low-level assembly (x86/x64/ARM/MIPS/PowerPC) for memory corruption and bypass techniques.
  • Assess embedded and RTOS platforms (VxWorks, RTOSs, Android, Linux, Windows) for security gaps.
  • Analyze code via static/dynamic review and write security posture reports.
  • Automate workflows with Python, Perl, Ruby, or C/C++ to speed up research cycles.

Skills

Ghidra
Binary analysis
Reverse engineering
C/C++
Python
Debugger skills

Tools

IDA Pro
WinDbg
OllyDbg
gdb

Job description

Cyber Vulnerability Researcher

THIS POSITION REQUIRES AN ACTIVE US GOVERNMENT SECURITY CLEARANCE. IF YOU DO NOT HAVE A CLEARANCE, PLEASE DO NOT APPLY.

SG2 Recruiting has partnered with Lumbee Holdings to spearhead the search for a visionary Cyber Vulnerability Researcher. This is a pivotal opportunity to join a dynamic team and directly influence the company’s next phase of growth. If you are a strategic thinker ready to make a tangible impact, we want to hear from you.

Company Overview:

At Lumbee Holdings, we deliver mission-critical logistical, technical, and analytical support to empower strategic government and defense operations. Our culture is built on continuous improvement, operational integrity, and dedicated service to key defense stakeholders. When you join our team, you become part of a collaborative environment where your expertise directly supports military readiness and system efficiency.

Your Role:

As a Cyber Vulnerability Researcher, you will deliver advanced vulnerability research and low-level exploit development capability in support of the MCTSSA Cyber Branch’s adversarial testing mission at Camp Pendleton, CA. Your core purpose is to extend the team’s offensive depth beyond tool-based penetration testing into original vulnerability discovery, binary analysis, and exploitation of embedded systems, real-time operating systems (RTOS), and custom platform architectures. Working in close coordination with vulnerability assessment analysts and penetration testers, you will translate research-derived findings into actionable assessment products and technically defensible remediation recommendations for Marine Corps Program Offices.

What You Will Be Doing
  • Conduct Original Vulnerability Research: Perform static and dynamic analysis using tools like Ghidra, IDA Pro, WinDbg, OllyDbg, and gdb to identify exploitable weaknesses in Marine Corps software, firmware, and embedded platforms.

  • Execute Fuzzing & Exploitation: Develop and execute fuzz testing campaigns to discover zero-day vulnerabilities, and create proof-of-concept (PoC) exploits in isolated research environments to validate mission impact.

  • Analyze Low-Level Assembly Code: Examine assembly architectures (x86, x64, ARM, MIPS, PowerPC) to identify memory corruption, logic flaws, and bypass strategies for DEP, ASLR, and stack canaries.

  • Assess Embedded & RTOS Platforms: Research weapons systems, C5ISR platforms, embedded systems, and real-time operating systems (VxWorks, RTOSs, Android, Linux, Windows) that commercial COTS scanners cannot evaluate.

  • Analyze Code & Write Reports: Conduct static/dynamic source code analysis to identify CWEs, produce Code Review Reports, and deliver summary Security Posture Assessments to guide program office decision-making.

  • Automate Research Workflows: Utilize Python, Perl, Ruby, or C/C++ to build custom scripts and tools that accelerate research discovery cycles and improve methodology repeatability.

  • Publish Research Findings: Synthesize research into Vulnerability Survey Reports, technical briefings, attack path analyses, and mitigation strategies compliant with Security Classification Guides.

What You Will Need
Must-Haves
  • Security Clearance: Active DoD Secret Security Clearance (ability to obtain and maintain Top Secret preferred).

  • Tooling Expertise: At least five (5) years of hands-on experience using Ghidra for vulnerability research, binary analysis, and reverse engineering.

  • Programming & Debugging: Proficiency in C or C++, scripting languages (Python, Perl, or Ruby), assembly languages (x86, x64, ARM, MIPS, PowerPC), and debuggers (gdb, WinDbg, OllyDbg).

  • System & Protocol Knowledge: Experience with PC/embedded system architectures, OS internals, network protocols, fuzzing techniques, and common mitigation techniques (DEP, ASLR, stack canaries).

  • Location/On-Site: Willingness and ability to work 100% on-site at Camp Pendleton, CA.

Nice-to-Haves
  • Certifications: Advanced software assurance credentials such as OSED, OSEE, GREM, or equivalent.

  • Advanced Research Skills: Experience developing IDA Pro plugins/scripts, hardware/FPGA debugging, or 10+ years of low-level reverse engineering and systems programming experience.

  • Competitions & Tradecraft: Active participation in Capture The Flag (CTF) or software hacking competitions.

Military & Veteran Equivalents:
  • U.S. Army MOS/WO: 17C (Cyber Operations Specialist), 170D (Cyber Warfare Technician Warrant Officer).

  • U.S. Air Force AFSC: 1B4X1 (Cyber Warfare Operations).

  • U.S. Navy Rating/Designator: CWT (Cyber Warfare Technician) or CWE (Cyber Warfare Engineer).

Logistics
  • Work Location: MCTSSA Cyber Branch – Camp Pendleton, California (Standard business hours: Mon–Fri, 8:00 a.m. – 5:00 p.m.)

  • Position Type: On-site, full-time, Exempt

  • Travel Required: Less than 10% CONUS travel

  • Salary Range: $110,000.00 To $120,000.00 Annually

  • Benefits: Comprehensive benefits package (detailed terms and eligibility provided during onboarding)

Mental and Physical Demands: This position is primarily sedentary and performed in an office or laboratory setting, requiring extended periods of computer use, close visual attention to technical detail, and the ability to sit or stand for extended periods. The role requires the cognitive ability to perform complex technical analysis, review software architectures, and interpret low-level system instructions. Occasional lifting of computer or lab equipment up to 25 lbs. may be required.

Related Duties as Assigned: To support evolving mission priorities and organizational goals, the Program Manager or MCTSSA Cyber Branch Lead may assign you additional operational, technical, or research tasks.

Equal Employment Opportunity & Disability Accommodations: Lumbee Holdings is an Equal Opportunity Employer. We do not discriminate in employment opportunities or practices on the basis of race, color, religion, sex (including pregnancy, sexual orientation, or gender identity), national origin, age, disability, protected veteran status, genetic information, or any other characteristic protected by applicable federal, state, or local law.

We are committed to providing reasonable accommodations to qualified individuals with disabilities in all phases of the employment process, including the application and interview phase. If you require a reasonable accommodation to participate in the application or recruitment process, please inform your recruiter or contact our HR team.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Vulnerability Researcher
Cyber Vulnerability Researcher

SG2 Recruiting • California (MO)

On-site
USD 110,000 - 120,000
Cybersecurity Engineer
Cybersecurity Engineer

SG2 Recruiting • Oceanside (CA)

On-site
USD 110,000 - 120,000
Comprehensive benefits
Cybersecurity Engineer
Cybersecurity Engineer

SG2 Recruiting • California (MO)

On-site
USD 110,000 - 120,000
Vulnerability Researcher
Vulnerability Researcher

Lumbee Tribe Enterprises, Llc • California (MO)

On-site
USD 110,000 - 120,000
Cyber Vulnerability Researcher (On-Site Camp Pendleton)
Cyber Vulnerability Researcher (On-Site Camp Pendleton)

SG2 Recruiting • California (MO)

On-site
USD 110,000 - 120,000
Cyber Vulnerability Researcher - On-Site Camp Pendleton
Cyber Vulnerability Researcher - On-Site Camp Pendleton

SG2 Recruiting • San Onofre (CA)

On-site
USD 110,000 - 120,000
Comprehensive benefits
On-site at Camp Pendleton
Cyber Vulnerability Researcher & Exploit Specialist
Cyber Vulnerability Researcher & Exploit Specialist

Lumbee Tribe Enterprises, Llc • California (MO)

On-site
USD 110,000 - 120,000
Cybersecurity Engineer
Cybersecurity Engineer

Lumbee Tribe Enterprises, Llc • California (MO), Northern (KY)

Hybrid
USD 110,000 - 120,000
Vulnerability Assessment Analyst and Penetration Tester
Vulnerability Assessment Analyst and Penetration Tester

SteelToad • Annapolis (MD)

On-site
USD 120,000 - 150,000
Medical Insurance
401(k) Plan with matching contributions
Paid Time Off
+2
Lead Cyber Mission Threat Analyst - Clearance Required
Lead Cyber Mission Threat Analyst - Clearance Required

Cydecor, Inc. • Port Hueneme (CA)

On-site
USD 180,000 - 218,000
Health and Dental Insurance
401(k) + company match
Paid Time Off (PTO)