Sr. Exploit Developer (US)

VulnCheck Inc.

United States

Remote

USD 180,000 - 260,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Unlimited PTO
Parental leave
Healthcare coverage
401(k) match

Job summary

vulncheck is seeking a senior exploit developer for the Initial Access Intelligence team. The role focuses on reverse engineering and crafting original exploit code where public PoC is missing, spanning from root-cause analysis to detection engineering.

This fully remote position is within the United States, with priority for candidates in Massachusetts, Maryland, or Austin, Texas. You will contribute to an open-source exploit framework and develop ASM queries and detection rules to surface

Qualifications

  • Experience writing exploit code for remote-code-execution and initial access vulnerabilities without authentication.
  • Strong reverse engineering skills with a track record of producing working exploit code.
  • Experience working on technical projects remotely, independently, and in small teams.
  • Ability to share example exploit code as part of the application process.

Responsibilities

  • Reverse engineer software to identify the root cause of vulnerabilities.
  • Author original exploits for initial access vulnerabilities when little or no public PoC exists.
  • Implement network and host detections (Suricata/Snort, YARA) to identify exploitation on the wire.
  • Write Attack Surface Management queries using Shodan, Censys, FOFA, and ZoomEye to surface vulnerable systems.
  • Contribute to local and other exploit types, and to an open-source exploit framework.

Skills

Exploit development experience
Reverse engineering
Remote work experience
Code sharing during application

Job description

Role overview

A senior exploit developer role on an Initial Access Intelligence team, focused on reverse engineering and crafting original exploit code where public proof-of-concept material is missing. Work spans from root-cause analysis through detection engineering and attack surface queries, with opportunities to contribute to an open-source exploit framework. It is a fully remote position, with priority given to candidates based in Massachusetts, Maryland, or Austin, Texas.

Responsibilities
  • Reverse engineer software to identify the root cause of vulnerabilities.
  • Author original exploits for initial access vulnerabilities, particularly when little or no public proof-of-concept code exists.
  • Implement network and host detections, such as Suricata/Snort signatures and YARA rules, to identify exploitation on the wire.
  • Write Attack Surface Management queries using platforms like Shodan, Censys, FOFA, and ZoomEye to surface vulnerable systems likely to be targeted.
  • Contribute occasionally to local and other exploit types, and to an open-source exploit framework.
Requirements
  • Prior experience writing exploit code for remote-code-execution or other initial access vulnerabilities that do not require authentication to exploit.
  • Demonstrated reverse engineering skills and a track record of producing working exploit code.
  • Experience working on technical projects remotely, independently, and as part of small teams.
  • Ability to share example exploit code as part of the application process.
Nice to have
  • Prior cybersecurity work experience at a vendor or in government.
  • Familiarity with crafting network and host-based detection rules and ASM queries for finding exposed systems.
  • Experience contributing to open-source security tooling or exploit frameworks.
Benefits and work setup
  • Fully remote within the United States.
  • Unlimited paid time off, generous paid parental leave, and comprehensive healthcare coverage.
  • 401(k) plan with company match and reimbursement for cell phone and internet expenses.
  • Ongoing professional development and clear career-advancement opportunities within a growing research organization.
  • Note: employment is contingent on the ability to authorize access under applicable U.S. export control regulations.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Exploit Developer — Remote Initial-Access
Senior Exploit Developer — Remote Initial-Access

VulnCheck • Boston (MA)

On-site
USD 150,000 - 230,000
Unlimited PTO
401k plan with company match
Healthcare coverage
+4
Senior Exploit Research Engineer (Remote)
Senior Exploit Research Engineer (Remote)

VulnCheck Inc. • United States

Remote
USD 180,000 - 260,000
Unlimited PTO
Parental leave
Healthcare coverage
+1
Sr. Exploit Developer (US)
Sr. Exploit Developer (US)

VulnCheck Inc. • Maryland

On-site
USD 100,000 - 150,000
Unlimited PTO
401k plan with company match
Comprehensive healthcare coverage
+5
Senior Exploit Engineer - Remote, Initial-Access Focus
Senior Exploit Engineer - Remote, Initial-Access Focus

VulnCheck Inc. • United States

Remote
USD 180,000 - 240,000
Equity program
Health coverage
Unlimited PTO
+5
Senior Exploit Developer - Remote Threat Intelligence
Senior Exploit Developer - Remote Threat Intelligence

VulnCheck • Columbia (MD)

On-site
USD 140,000 - 190,000
Unlimited PTO
401k with company match
Healthcare coverage
+6
Senior Exploit Engineer — Remote, Reverse Engineering
Senior Exploit Engineer — Remote, Reverse Engineering

VulnCheck • Austin (TX)

On-site
USD 100,000 - 150,000
Unlimited PTO
401k plan
Healthcare coverage
+5
Senior Exploit Engineer - Remote Threat Intelligence
Senior Exploit Engineer - Remote Threat Intelligence

VulnCheck Inc. • Maryland

On-site
USD 100,000 - 150,000
Unlimited PTO
401k plan with company match
Comprehensive healthcare coverage
+5
Senior Vulnerability Researcher — Remote Exploit Intelligence
Senior Vulnerability Researcher — Remote Exploit Intelligence

VulnCheck • Austin (TX)

On-site
USD 150,000 - 230,000
Flexible time off
401(k) with match
Healthcare coverage
+2
Senior Vulnerability Researcher Remote, Exploit Intelligence
Senior Vulnerability Researcher Remote, Exploit Intelligence

VulnCheck • Lexington (VA)

On-site
USD 150,000 - 230,000
Generous time off
Comprehensive healthcare coverage
Remote-friendly environment
+2
Exploit Developer - TS/SCI Full Scope Polygraph
Exploit Developer - TS/SCI Full Scope Polygraph

GRIMM • Maryland

On-site
USD 90,000 - 120,000