Vulnerabilities Security Researcher

Request Technology, LLC

United States

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Bonus eligibility

Job summary

A prestigious enterprise company is seeking an Expert Vulnerabilities Security Researcher. This role involves analyzing systems to discover vulnerabilities, particularly in AI/ML technologies. Candidates should have 7+ years of experience in offensive cybersecurity roles, including red teaming and penetration testing. Key responsibilities include performing vulnerability assessments and developing methodologies. The position offers opportunities for advancement and is located in the United States, with competitive compensation and bonus eligibility.

Qualifications

  • 7+ years of professional work experience in the cybersecurity industry.
  • Experience in offensive cybersecurity roles like red teaming and penetration testing.
  • Ability to analyze and create low-level exploits.

Responsibilities

  • Conduct research to identify impactful vulnerabilities in various applications.
  • Perform vulnerability assessments on web applications, APIs, and cloud infrastructure.
  • Develop and communicate accurate reports for client stakeholders.

Skills

Cybersecurity experience
Offensive security roles
Vulnerability assessment
Analysis and debugging
Programming in Python
Cloud security

Education

Bachelor’s degree in Computer Science or related field

Tools

AFL
Peach

Job description

***We are unable to sponsor for this permanent full-time role***

***Position is bonus eligible***

Prestigious Enterprise Company is currently seeking an Expert Vulnerabilities Security Researcher. Candidate will be responsible for analyzing systems, software, architectures, and strategies to discover impactful, unknown vulnerabilities and security weaknesses, including those affecting AI/ML systems and AI-enabled technologies and services. This work proactively identifies classes of vulnerabilities and exploitation opportunities that inform mitigation strategies and secure design.

The role involves performing manual source code review, binary analysis, vulnerability assessments, dynamic testing, threat modeling, and security architecture review. The researcher conducts ongoing analysis of real-world adversaries, exploitation methods, and emerging attack surface and offensive security techniques to guide research priorities. Development of custom tooling and automation is required to augment manual vulnerability discovery.

Responsibilities
  • Conducts research to identify highly impactful, unknown vulnerabilities in a wide variety of applications and technologies, including AI-enabled applications and services
  • Performs vulnerability assessments using industry best practices on various environments, including web applications, APIs, and cloud infrastructure
  • Develops and manages testing methodologies that adhere to common security guidelines and NIST standards
  • Conducts an evaluation of cloud security configurations, identifies prevalent vulnerabilities in cloud security controls, and improves and maintains cloud testing standards
  • Provides detailed reports with proof of vulnerabilities, guidance, and advice to support customer teams through vulnerability remediation
  • Develops and communicates comprehensive and accurate reports and presentations for client stakeholders including technical staff and executive leadership
  • Maintains communication with management regarding development within assigned responsibilities and performs special projects as required
  • Researches and develops innovative techniques, tools, and methodologies for vulnerability research and red team activities
  • Develops leadership-level communications, including management-specific metrics, white papers, procedures, thought position papers, etc.
  • This list is not all-inclusive, and you are expected to perform other cybersecurity-congruent duties as requested or assigned
Qualifications
  • 7+ years of professional work experience in the cybersecurity industry with Bachelor’s degree in Computer Science, Management Information Systems, or a related field, or equivalent work experience.
  • Understanding of all phases of adversary emulation operations, including reconnaissance, social engineering, exploitation, post-exploitation, covert techniques, lateral movement, and data exfiltration.
  • Extensive experience in offensive cybersecurity roles, such as red teaming, penetration testing (e.g., web, infrastructure, cloud), and purple team exercises across cloud and on-prem environments.
  • Robust understanding of contemporary security theory, application exploitation techniques, and attack vectors, including the vulnerability lifecycle and scanning methodologies (SAST, DAST, IAST, RASP).
  • Experience developing and managing testing methodologies that adhere to common security guidelines such as OWASP and frameworks such as NIST 800 or MITRE ATT&CK.
  • Solid understanding of computer architecture and organization with respect to binary analysis and exploitation.
  • Ability to analyze, create, and debug shellcode and other low-level exploits.
  • Experience developing custom security software (offensive or defensive) in one or more compiled languages.
  • Demonstrated ability to reverse engineer binaries, enumerate vulnerabilities in compiled software, and provide working exploits (e.g., CVEs, public acknowledgements, or the ability to demonstrate on demand).
  • Familiarity with automated security analysis and fuzzing tools (e.g., AFL and Peach).
  • Demonstrated ability to discover vulnerabilities via static analysis and source code review.
  • Working understanding of key programming languages and frameworks (e.g., Java, Node.js, Python, JSP), including the ability to quickly learn new languages, understand their security implications, and enumerate vulnerabilities in custom-developed software packages.
  • Familiarity with scripting and programming in Python, PowerShell, or C#, with the ability to create and customize tools.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Vulnerability Analyst
Senior Vulnerability Analyst

PRI Global • O’Fallon (MO)

On-site
USD 110,000 - 160,000
Senior Security Researcher
Senior Security Researcher

Clarityinnovates • United States

On-site
USD 80,000 - 120,000
vulnerability researcher
vulnerability researcher

NPAworldwide • Saint Petersburg (FL)

On-site
USD 156,000 - 234,000
Relocation assistance
Security Engineer
Security Engineer

SambaSafety (Safety Holdings, Inc.) • United States

Remote
USD 110,000 - 150,000
Senior Security Researcher
Senior Security Researcher

Clarity Innovations • United States

On-site
USD 90,000 - 130,000
Senior Security Test & Evaluation Analyst
Senior Security Test & Evaluation Analyst

Veriipro • Washington

On-site
USD 130,000 - 190,000
Senior Reverse Engineering/Vulnerability Research Engineer
Senior Reverse Engineering/Vulnerability Research Engineer

Clarityinnovates • Columbus (OH)

On-site
USD 85,000 - 115,000
Principal Reverse Engineering/Vulnerability Research Engineer
Principal Reverse Engineering/Vulnerability Research Engineer

Clarity Innovations • Herndon (VA)

On-site
USD 150,000 - 230,000
Senior Security Researcher
Senior Security Researcher

Palo Alto Networks, Inc. • Santa Clara (CA)

On-site
USD 139,000 - 226,000
Sr. Cyber Engineer (AI)
Sr. Cyber Engineer (AI)

Nava • Chantilly (VA)

On-site
USD 120,000 - 160,000
Generous medical insurance
100% company paid dental insurance
401k plan with generous match
+2