Lead Vulnerability Researcher

GrammaTech

Herndon (VA)

On-site

USD 175,000 - 220,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, Dental, Vision
401(k) with company contributions
Paid holidays
PTO / personal leave
Bonus opportunities

Job summary

GrammaTech is seeking a Lead Vulnerability Researcher in Herndon, VA to guide investigations across hardware, software, and operations. You will mentor engineers, develop PoC code, and reverse‑engineer embedded systems to uncover vulnerabilities with real‑world impact.

The role requires on‑site presence at the Linthicum, MD site or GrammaTech HQ in Herndon. A doctorate or master’s with extensive experience is preferred, along with strong C/C++, Python, and ISA skills.

Qualifications

  • Doctorate or Master’s with 6+ years or Bachelor’s with 8+ years in relevant fields.
  • Experience in computer security, vulnerability analysis, or reverse‑engineering.
  • Proficiency in C/C++, Python, and at least one ISA (x86/ARM/MIPS).
  • Proficiency with Linux command line and standard debugging tools.

Responsibilities

  • Lead vulnerability research across hardware, software, personnel, and physical security.
  • Develop PoC code for identified vulnerabilities.
  • Reverse‑engineer embedded systems to identify flaws.
  • Review code for risks and vulnerabilities and analyze impacts.
  • Propose countermeasures and produce technical reports and briefings.
  • Mentor junior engineers and review technical approaches.

Skills

C/C++
Python
ISA knowledge
Linux CLI
Decompiler tools
Vulnerability tools
Debugger tools

Education

Doctorate in Computer Science or Engineering
Master’s degree in related field
Bachelor’s degree in related field
Associate’s degree + 10 years experience

Tools

IDA Pro
Binary Ninja
Ghidra
Emulators
Fuzzers
GDB
WinDbg

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Lead Vulnerability Researcher

Herndon, VA, US

7 days ago Requisition ID: 1015

Join us at GrammaTech where you’ll lead vulnerability research across hardware, software, and operational systems. Working side by side with engineers and security researchers, you’ll guide investigations, identify critical vulnerabilities, and develop countermeasures with operational impact. Our fast-growing roster of government customers relies on us to deliver advanced security solutions, and we’re looking for a Lead Vulnerability Researcher to provide technical leadership and mentorship.

This role requires regular on-site support at the Linthicum, Maryland customer site or our headquarters in Herndon VA

What you will do:

  • Lead the identification of vulnerabilities and attacks across hardware, software, personnel, logistics, procedures, and physical security.
  • Develop proof of concept (PoC) code for identified vulnerabilities
  • Reverse-engineer targeted embedded systems to identify vulnerabilities
  • Review source code looking for risks and vulnerabilities
  • Analyze the effects of vulnerabilities on mission outcomes and operational effectiveness.
  • Compare system attack techniques and propose operationally effective countermeasures
  • Produce reports, briefings, and perspectives on actual and potential attacks
  • Provide technical leadership on research efforts, prioritizing investigations, reviewing methodologies, and overseeing proof-of-concepts.
  • Mentor and guide junior engineers and researchers, reviewing technical approaches and fostering skill development.

What you will need (Basic Qualifications):

  • Doctorate in Computer Science, Computer/Electrical Engineering, or a related field and 4 years of relevant experience, OR Master’s degree and 6 years of relevant experience, OR Bachelor’s degree and 8 years of relevant experience, OR Associate’s degree and 10 years of relevant experience.
    • Relevant experience: computer/information systems design/development, programming, information/cyber/network security, reverse-engineering, vulnerability analysis, penetration testing, computer forensics, information assurance, or systems engineering
  • Proficiency in C/C++, Python, and at least one ISA (e.g. x86/ARM/MIPS)
  • Proficiency in Linux command-line environments
  • Experience using a decompiler such as IDA Pro, Binary Ninja, or Ghidra
  • Experience using vulnerability research tools such as emulators or fuzzers
  • Experience using a software debugger such as GDB or WinDbg

Nice If You Have (Preferred):

  • Experience translating vulnerabilities into operationally relevant impact assessments and countermeasures.
  • Experience producing client-facing technical briefings for operational stakeholders
  • Experience using a hardware debugger
  • Experience with UART, SPI, I2C
  • Experience with common secure communications such as TLS or SSH
  • Familiarity with embedded firmware, RTOS, or networked systems
  • Familiarity with high-side environments

Security Clearance:

  • Active TS/SCI clearance ( Herndon) with Polygraph required at customer site in Maryland

The anticipated base salary range for this position is $175,000–$220,000 annually. This range reflects the Company's good-faith estimate at the time of posting. Final compensation will be determined based on a variety of factors, including the scope and level of the role, relevant experience, technical expertise, education, and other job-related qualifications.

GrammaTech offers a comprehensive total rewards package designed to support the health, well-being, and financial security of our employees. Benefits include medical, dental, and vision insurance; short- and long-term disability coverage; life insurance; and a 401(k) retirement plan with company contributions. Employees are also eligible for paid holidays, paid time off (PTO), sick and personal leave, annual merit increases, and performance-based bonus opportunities.

GrammaTech, Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status. GrammaTech is committed to providing reasonable accommodations to qualified individuals with disabilities throughout the application and hiring process. Applicants requiring accommodation should contact Human Resources.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Hardware Reverse Engineer
Senior Hardware Reverse Engineer

Grammatech • Herndon (VA), Northern (KY)

Hybrid
USD 150,000 - 215,000
Senior Embedded Security Software Engineer
Senior Embedded Security Software Engineer

Grammatech • Herndon (VA), Northern (KY)

Hybrid
USD 130,000 - 190,000
Medical, dental, and vision insurance
401(k) with company contributions
Paid holidays and PTO
+1
Senior Vulnerability Research Lead - Embedded & Hardware
Senior Vulnerability Research Lead - Embedded & Hardware

GrammaTech • Herndon (VA)

On-site
USD 175,000 - 220,000
Medical, Dental, Vision
401(k) with company contributions
Paid holidays
+2
Senior Embedded Security Software Engineer
Senior Embedded Security Software Engineer

GrammaTech • Maryland

On-site
USD 130,000 - 190,000
Medical, dental, and vision insurance
401(k) with company contributions
Paid holidays and PTO
Lead Vulnerability Researcher ($285k+/year + Sign-On Bonus)
Lead Vulnerability Researcher ($285k+/year + Sign-On Bonus)

Doist • Linthicum (MD)

On-site
USD 285,000 - 300,000
Medical insurance
Dental and vision
401(k) matching
+2
Vulnerability & Exploitation Specialist
Vulnerability & Exploitation Specialist

GRVTY • Maryland

On-site
USD 180,000 - 230,000
Robust health plan including medical, dental, and vision
Health Savings Account with company contribution
Annual Paid Time Off and Paid Holidays
+3
Lead Vulnerability Researcher ($285k+/year + Sign-On Bonus)
Lead Vulnerability Researcher ($285k+/year + Sign-On Bonus)

Two Six Technologies • Linthicum (MD)

On-site
USD 285,000 - 300,000
Senior Vulnerability Researcher ($250k+/year + Sign-On Bonus)
Senior Vulnerability Researcher ($250k+/year + Sign-On Bonus)

Doist • Linthicum (MD)

On-site
USD 250,000 - 285,000
Health, dental, and vision
401(k) matching
Professional development
+2
Lead Vulnerability Researcher
Lead Vulnerability Researcher

Two-Six-Technologies • Tysons (VA)

On-site
USD 140,000 - 210,000
Medical insurance
Dental insurance
Vision insurance
+1
Senior Vulnerability Researcher ($250k+/year + Sign-On Bonus)
Senior Vulnerability Researcher ($250k+/year + Sign-On Bonus)

Two Six Technologies • Linthicum (MD)

On-site
USD 250,000 - 285,000
Healthcare benefits
401(k) matching
Paid professional development
+2