Senior Vulnerability Engineer

Anduril Industries, Inc.

Boston (MA)

On-site

USD 152,000 - 253,000

Full time

21 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Anduril Industries, Inc. in Boston, MA is seeking a Vulnerability Engineer to uncover novel vulnerabilities across embedded systems, firmware, and hardware/software boundaries. You will design research plans, build tooling, and collaborate with engineering teams to drive remediation and produce rigorous technical reports.

The role requires hands-on experience in vulnerability research, debugging, and hardware analysis, with eligibility for a U.S. security clearance.

Qualifications

  • Strong experience discovering vulnerabilities in firmware, applications, network services, embedded Linux systems, drivers, protocols, IoT devices, or hardware-adjacent systems.
  • Proficiency with programming languages such as Python, C, C++, Rust, or Go for vulnerability research and tooling.
  • Experience with fuzzing, harness development, crash triage, exploitability analysis, source-code review, binary analysis, or dynamic instrumentation.
  • Ability to reason about memory corruption, logic flaws, authentication and authorization failures, unsafe parsing, concurrency issues, insecure update flows, and trust-boundary failures.
  • Hands-on familiarity with Linux, embedded systems, networking, debugging, and common security research tooling.
  • Ability to communicate vulnerability impact, reproduction steps, and mitigation options clearly to both research and engineering audiences.
  • Demonstrated bias toward practical, mission-enabling security outcomes rather than purely theoretical findings.
  • Must be eligible to obtain and maintain a U.S. security clearance.
  • Experience evaluating vulnerabilities across embedded protection mechanisms such as secure boot, firmware update paths, key storage, memory protection, and debug interface controls.
  • Comfort working with lab-based vulnerability validation using hardware interfaces, protocol analyzers, debuggers, or instrumented test setups.

Responsibilities

  • Find novel vulnerabilities in software, firmware, embedded systems, protocols, update paths, device interfaces, and hardware/software integration boundaries.
  • Design and execute vulnerability research plans that combine code review, reverse engineering, fuzzing, emulation, dynamic instrumentation, hardware analysis, and adversarial testing.
  • Build custom fuzzers, harnesses, emulators, instrumentation, triage workflows, and proof-of-concept tooling to turn research hypotheses into reproducible findings.
  • Analyze root cause, exploitability, operational impact, and mitigation options for discovered vulnerabilities.
  • Partner with reverse engineers, product security engineers, embedded software engineers, hardware engineers, and systems teams to validate findings and drive practical remediation.
  • Write clear technical reports that include evidence, reproduction steps, exploitability assessment, impact, mitigations, and follow-on research opportunities.
  • Design hardware-in-the-loop vulnerability experiments that combine software exploitation, protocol analysis, physical interfaces, and lab instrumentation.
  • Develop tooling to automate experiment orchestration, device interaction, data collection, crash triage, and vulnerability reproduction.

Skills

Vulnerability discovery
Embedded systems
Programming languages
Fuzzing & instrumentation
Linux familiarity
Communication of findings

Tools

Ghidra
IDA Pro
Binary Ninja
QEMU
Frida
gdb/lldb

Job description

Boston, Massachusetts, United States; Costa Mesa, California, United States; Washington, District of Columbia, United States


Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril’s family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years.


ABOUT THE TEAM

Anduril Cyber is hiring a Vulnerability Engineer to discover novel vulnerabilities in hardware and software systems and turn that research into rigorous technical artifacts. The role is focused on original vulnerability discovery across embedded systems, firmware, applications, protocols, hardware/software boundaries, and system integrations.


ABOUT THE JOB


  • Find novel vulnerabilities in software, firmware, embedded systems, protocols, update paths, device interfaces, and hardware/software integration boundaries.

  • Design and execute vulnerability research plans that combine code review, reverse engineering, fuzzing, emulation, dynamic instrumentation, hardware analysis, and adversarial testing.

  • Build custom fuzzers, harnesses, emulators, instrumentation, triage workflows, and proof-of-concept tooling to turn research hypotheses into reproducible findings.

  • Analyze root cause, exploitability, operational impact, and mitigation options for discovered vulnerabilities.

  • Partner with reverse engineers, product security engineers, embedded software engineers, hardware engineers, and systems teams to validate findings and drive practical remediation.

  • Write clear technical reports that include evidence, reproduction steps, exploitability assessment, impact, mitigations, and follow-on research opportunities.

  • Design hardware-in-the-loop vulnerability experiments that combine software exploitation, protocol analysis, physical interfaces, and lab instrumentation.

  • Develop tooling to automate experiment orchestration, device interaction, data collection, crash triage, and vulnerability reproduction.


REQUIRED QUALIFICATIONS


  • Strong experience discovering vulnerabilities in firmware, applications, network services, embedded Linux systems, drivers, protocols, IoT devices, or hardware-adjacent systems.

  • Proficiency with one or more programming languages used for vulnerability research and tooling, such as Python, C, C++, Rust, or Go.

  • Experience with fuzzing, harness development, crash triage, exploitability analysis, source-code review, binary analysis, or dynamic instrumentation.

  • Ability to reason about memory corruption, logic flaws, authentication and authorization failures, unsafe parsing, concurrency issues, insecure update flows, and trust-boundary failures.

  • Hands-on familiarity with Linux, embedded systems, networking, debugging, and common security research tooling.

  • Ability to communicate vulnerability impact, reproduction steps, and mitigation options clearly to both research and engineering audiences.

  • Demonstrated bias toward practical, mission-enabling security outcomes rather than purely theoretical findings.

  • Must be eligible to obtain and maintain a U.S. security clearance.

  • Experience evaluating vulnerabilities across embedded protection mechanisms such as secure boot, firmware update paths, key storage, memory protection, and debug interface controls.

  • Comfort working with lab-based vulnerability validation using hardware interfaces, protocol analyzers, debuggers, or instrumented test setups.


PREFERRED QUALIFICATIONS


  • Experience finding vulnerabilities in boot chains, firmware update mechanisms, device identity systems, cryptographic integrations, anti-tamper mechanisms, or programmable-logic-backed systems.

  • Experience with advanced vulnerability research techniques such as coverage-guided fuzzing, symbolic execution, differential testing, fault injection, protocol state modeling, or hardware-in-the-loop testing.

  • Familiarity with reverse-engineering tools such as Ghidra, IDA Pro, Binary Ninja, QEMU, Frida, gdb/lldb, or comparable frameworks.

  • Background in embedded, aerospace, robotic, RF, or cyber-physical systems and the ways their threat models differ from conventional enterprise software.

  • Track record of producing high-quality vulnerability research artifacts, internal tooling, conference-quality writeups, CVEs, or comparable technical outputs.

  • Experience applying side-channel analysis, fault injection, black-box testing, or hardware-assisted fuzzing to embedded systems.

  • Experience with RF protocols, cryptographic protocol analysis, FPGA/SoC security, signal processing, or board-level vulnerability assessment.

  • Demonstrated technical leadership, mentorship, or ownership of complex vulnerability research efforts from hypothesis through reproducible technical artifact.


US Salary Range


$191,000 - $253,000 USD


The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Anduril's total compensation package. Additionally, Anduril offers top-tier benefits for full-time employees, including:


At Anduril, we invest in our people. Our comprehensive, competitive benefits package (available at little to no cost to employees) ensures you’re supported in health, recovery, and whatever comes next. For more information, Explore Our Benefits .


Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiringprocess or thereafter. Any information that you do provide will be recorded and maintained in aconfidential file.


As set forth in Anduril Industries’s Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.


If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection.As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measurethe effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categoriesis as follows:


A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.


A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.


An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.


An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

"
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Vulnerability Engineer
Senior Vulnerability Engineer

Anduril-1 • Boston (MA)

On-site
USD 191,000 - 253,000
Senior Reverse Engineer, Cyber
Senior Reverse Engineer, Cyber

Anduril-1 • Boston (MA)

On-site
USD 191,000 - 253,000
Senior Cloud Infrastructure Engineer
Senior Cloud Infrastructure Engineer

Anduril-1 • Washington

On-site
USD 146,000 - 194,000
Staff Program Manager
Staff Program Manager

Anduril Industries, Inc. • Costa Mesa (CA), Northern (KY)

Hybrid
USD 166,000 - 220,000
Equity grants
Comprehensive benefits
Competitive compensation
Software Engineer, Strategic Defense
Software Engineer, Strategic Defense

Anduril Industries, Inc. • Costa Mesa (CA), Northern (KY)

Hybrid
USD 166,000 - 220,000
Equity grants
Benefits package
Health insurance
Software Engineer, Strategic Defense
Software Engineer, Strategic Defense

Anduril-1 • Costa Mesa (CA)

On-site
USD 166,000 - 220,000
Electrical Engineer
Electrical Engineer

Anduril-1 • Waltham (MA)

On-site
USD 129,000 - 171,000
Security Software Engineer, Endpoint Security
Security Software Engineer, Endpoint Security

Anduril-1 • Boston (MA)

On-site
USD 166,000 - 220,000
Staff Software Engineer, Frontend Platform
Staff Software Engineer, Frontend Platform

Anduril Industries, Inc. • Costa Mesa (CA), Northern (KY)

Hybrid
USD 220,000 - 292,000
Equity grants
Comprehensive benefits
Staff Technical Program Manager, Advanced Effects - Active Clearance
Staff Technical Program Manager, Advanced Effects - Active Clearance

Anduril Industries, Inc. • Costa Mesa (CA), Northern (KY)

Hybrid
USD 191,000 - 253,000
Equity grants
Competitive benefits