Senior Vulnerability Engineer

Telemetry Today LLC

Boston (MA)

On-site

USD 191,000 - 253,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Anduril Cyber seeks a Vulnerability Engineer to uncover novel weaknesses in hardware and software across embedded systems, firmware, protocols, and device interfaces. You will design rigorous research plans, build custom tooling, and collaborate with hardware, software, and systems teams to drive pragmatic remediation.

Your work includes hardware-in-the-loop experiments, evidence-based reports, and publication-ready artifacts that advance secure-by-design goals.

Qualifications

  • Proven experience finding vulnerabilities in firmware, software, network services, embedded Linux, drivers, protocols, IoT devices or hardware-adjacent systems.
  • Strong programming skills in Python, C, C++, Rust or Go for vulnerability tooling.
  • Experience with fuzzing, crash triage, exploitability analysis, code review, binary analysis, or dynamic instrumentation.
  • Ability to reason about memory corruption, logic flaws, authentication/authorization failures, and unsafe parsing.
  • Hands-on familiarity with Linux, embedded systems, networking, debugging, and security research tooling.
  • Clear communication of vulnerability impact, reproduction steps, and mitigations to research and engineering teams.
  • Bias toward practical, mission-enabling security outcomes and a track record of producing artifacts.

Responsibilities

  • Find novel vulnerabilities in firmware, applications, network services, and embedded systems.
  • Design and execute vulnerability research plans combining code review, fuzzing, emulation, and hardware analysis.
  • Build custom fuzzers, harnesses, and tooling to reproduce findings.
  • Analyze exploitability, impact, and mitigations for discovered vulnerabilities.
  • Collaborate with cross-disciplinary teams to validate findings and drive remediation.
  • Write clear technical reports with evidence, steps, and follow-on research opportunities.
  • Design hardware-in-the-loop experiments combining software exploitation and lab instrumentation.
  • Develop tooling to automate experiments and data collection.

Skills

Vulnerability research
Hardware security
Fuzzing
Reverse engineering
Linux/Embedded systems

Tools

Ghidra
IDA Pro
Binary Ninja
QEMU
Frida
gdb/lldb

Job description

ABOUT THE TEAM

Anduril Cyber is hiring a Vulnerability Engineer to discover novel vulnerabilities in hardware and software systems and turn that research into rigorous technical artifacts. The role is focused on original vulnerability discovery across embedded systems, firmware, applications, protocols, hardware/software boundaries, and system integrations.

ABOUT THE JOB
  • Find novel vulnerabilities in software, firmware, embedded systems, protocols, update paths, device interfaces, and hardware/software integration boundaries.
  • Design and execute vulnerability research plans that combine code review, reverse engineering, fuzzing, emulation, dynamic instrumentation, hardware analysis, and adversarial testing.
  • Build custom fuzzers, harnesses, emulators, instrumentation, triage workflows, and proof-of-concept tooling to turn research hypotheses into reproducible findings.
  • Analyze root cause, exploitability, operational impact, and mitigation options for discovered vulnerabilities.
  • Partner with reverse engineers, product security engineers, embedded software engineers, hardware engineers, and systems teams to validate findings and drive practical remediation.
  • Write clear technical reports that include evidence, reproduction steps, exploitability assessment, impact, mitigations, and follow-on research opportunities.
  • Design hardware-in-the-loop vulnerability experiments that combine software exploitation, protocol analysis, physical interfaces, and lab instrumentation.
  • Develop tooling to automate experiment orchestration, device interaction, data collection, crash triage, and vulnerability reproduction.
REQUIRED QUALIFICATIONS
  • Strong experience discovering vulnerabilities in firmware, applications, network services, embedded Linux systems, drivers, protocols, IoT devices, or hardware‑adjacent systems.
  • Proficiency with one or more programming languages used for vulnerability research and tooling, such as Python, C, C++, Rust, or Go.
  • Experience with fuzzing, harness development, crash triage, exploitability analysis, source‑code review, binary analysis, or dynamic instrumentation.
  • Ability to reason about memory corruption, logic flaws, authentication and authorization failures, unsafe parsing, concurrency issues, insecure update flows, and trust‑boundary failures.
  • Hands‑on familiarity with Linux, embedded systems, networking, debugging, and common security research tooling.
  • Ability to communicate vulnerability impact, reproduction steps, and mitigation options clearly to both research and engineering audiences.
  • Demonstrated bias toward practical, mission‑enabling security outcomes rather than purely theoretical findings.
  • Must be eligible to obtain and maintain a U.S. security clearance.
  • Experience evaluating vulnerabilities across embedded protection mechanisms such as secure boot, firmware update paths, key storage, memory protection, and debug interface controls.
  • Comfort working with lab‑based vulnerability validation using hardware interfaces, protocol analyzers, debuggers, or instrumented test setups.
PREFERRED QUALIFICATIONS
  • Experience finding vulnerabilities in boot chains, firmware update mechanisms, device identity systems, cryptographic integrations, anti‑tamper mechanisms, or programmable‑logic‑backed systems.
  • Experience with advanced vulnerability research techniques such as coverage‑guided fuzzing, symbolic execution, differential testing, fault injection, protocol state modeling, or hardware‑in‑the‑loop testing.
  • Familiarity with reverse‑engineering tools such as Ghidra, IDA Pro, Binary Ninja, QEMU, Frida, gdb/lldb, or comparable frameworks.
  • Background in embedded, aerospace, robotic, RF, or cyber‑physical systems and the ways their threat models differ from conventional enterprise software.
  • Track record of producing high‑quality vulnerability research artifacts, internal tooling, conference‑quality writeups, CVEs, or comparable technical outputs.
  • Experience applying side‑channel analysis, fault injection, black‑box testing, or hardware‑assisted fuzzing to embedded systems.
  • Experience with RF protocols, cryptographic protocol analysis, FPGA/SoC security, signal processing, or board‑level vulnerability assessment.
  • Demonstrated technical leadership, mentorship, or ownership of complex vulnerability research efforts from hypothesis through reproducible technical artifact.
US Salary Range

$191,000 - $253,000 USD

The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Anduril's total compensation package. Additionally, Anduril offers top-tier benefits for full-time employees, including:

At Anduril, we invest in our people. Our comprehensive, competitive benefits package (available at little to no cost to employees) ensures you’re supported in health, recovery, and whatever comes next. For more information, Explore Our Benefits .

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Vulnerability Engineer
Senior Vulnerability Engineer

XYZ Venture Capital • Washington

On-site
USD 191,000 - 253,000
Benefits package
Equity grants
Competitive compensation
Senior Vulnerability Engineer
Senior Vulnerability Engineer

Anduril Industries • Washington

On-site
USD 191,000 - 253,000
Senior Vulnerability Research Engineer
Senior Vulnerability Research Engineer

XYZ Venture Capital • Washington

On-site
USD 191,000 - 253,000
Benefits package
Equity grants
Competitive compensation
Senior Reverse Engineer, Cyber
Senior Reverse Engineer, Cyber

XYZ Venture Capital • Washington

On-site
USD 191,000 - 253,000
Benefits package
Senior Cyber Software Engineer
Senior Cyber Software Engineer

Linuxconfig • Irvine (CA), Northern (KY)

Hybrid
USD 191,000 - 253,000
Equity grants
Benefits package
Senior Cyber Software Engineer
Senior Cyber Software Engineer

Triwill Group • Irvine (CA), Washington

On-site
USD 191,000 - 253,000
Equity grants
Benefits package
Health benefits
Vulnerability Engineer - Firmware & Hardware Security
Vulnerability Engineer - Firmware & Hardware Security

Anduril Industries • Washington

On-site
USD 191,000 - 253,000
Manager, Product Security Foundations
Manager, Product Security Foundations

Slope • Costa Mesa (CA)

On-site
USD 191,000 - 253,000
Senior Software Engineer
Senior Software Engineer

Xapply • Bellevue (WA)

On-site
USD 191,000 - 253,000
Security Software Engineer, Endpoint Security
Security Software Engineer, Endpoint Security

Anduril-1 • Seattle (WA)

On-site
USD 166,000 - 220,000
Equity grants
Comprehensive benefits