Vulnerability Researcher

Legion X

Arlington (VA)

Hybrid

USD 120,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Legion X is seeking a Vulnerability Researcher to turn discovered vulnerabilities into PoCs across firmware and software. You will analyze binaries on architectures like x86 and ARM, identify vulnerabilities, and document your findings for both technical and non-technical audiences.

You must be a firmware reverse engineer capable of turning analysis into practical exploits. Hybrid work with some Northern Virginia commute is preferred, remote work possible.

Qualifications

  • Experience reversing firmware and software to identify vulnerabilities.
  • Strong cyber vulnerability research capabilities with proven documentation.
  • Proficient in protocol analysis and communicating complex findings.
  • Ability to turn findings into PoCs for multiple devices and firmware types.
  • Comfortable working in a small team with ownership of results.

Responsibilities

  • Analyze binaries across architectures (e.g., x86, ARM, PowerPC).
  • Identify, explain, and exploit vulnerabilities in reverse engineered code.
  • Develop PoC demonstrations and document findings for non-technical audiences.
  • Integrate work into government systems or commercial deployments.
  • Collaborate with engineering leads and adapt to varied tasks in a small company.

Skills

Firmware reverse engineering
Cyber vulnerability research
Protocol analysis
Written and verbal communication
Self-motivation and drive
Interest in the work
C/C++ programming
Hands-on hardware experience
RF experience
Firmware programming experience
Ghidra/IDA Pro

Tools

Ghidra
IDA Pro

Job description

Legion X is a cyber services company headquartered in Reston, VA that develops on-demand, custom cyber solutions through applied research, prototyping, and engineering services. We are a small, tight-knit company built and run by engineers who pursue the most interesting and impactful cyber vulnerability research we can find.We take on tasks like vulnerability assessments, exploit development, cyber vulnerability research, penetration tests, firmware reverse engineering, hardware reverse engineering, customized test rigs, capability development, and CNO support for both government and commercial customers.Our vision is to be the premier cyber vulnerability research and red team outfit in the nation.

We are a small, new company embracing what we believe to be the best and most efficient ways of working in the modern era of cybersecurity.That means freedom and flexibility but also responsibility.If you are self-motivated, battle tested, and driven by the passion of understanding a system so you can exploit it, then we encourage you to apply.We are looking for experts and excellent human beings we want to work with for a long time, and are willing to explore equity options for applicants so that the best come, stay, and win together.

The Role

(Hybrid with some commute to Northern Virginia is preferred, but fully remote is possible)

You are applying for the role of Vulnerability Researcher.The role is a technical individual performer with room for advancement as Legion X grows.That includes opportunities to specialize and promote as an individual performer or stay technical while building and leading teams.A Vulnerability Researcher is an experienced code exploiter that can turn a discovered vulnerability into a proof-of-concept on a wide variety of devices and software/firmware types.You must be a firmware/software reverse engineer who can analyze functionality of a binary with little to no help or outside input, and successfully identify, explain, and exploit discovered vulnerabilities.You must be able to document and explain your work to a non-technical audience.You must also be comfortable integrating your work into government systems in support of cyber operations or into commercial systems in support of systems hardening.

You will be expected to receive and execute tasks from engineering leads, analyze binary files that use a variety processor architectures (e.g. x86, ARM, PowerPC, etc.), use popular reverse engineering tools like Ghidra/IdaPro/etc., identify vulnerabilities in reverse engineered code (e.g. buffer overflows, weak protocol implementation, etc.), communicate the details of those vulnerabilities verbally and in writing, build proof-of-concept demonstrations of the vulnerabilities, and employ best practice techniques per customer requirements.You will be focused on firmware found in operational technology platforms like drones, planes, industrial facilities, cars, ships, and even weapon systems.However, we also contemplate work in networking devices, communications devices, endpoint systems, and IoT devices.For this position, you must be a US citizen who is TOP SECRET clearance eligible.

You will also be expected to remain flexible with the needs of a small business.That could include supporting penetration tests, drone assessments, operational technology risk analysis, and other tasks that are not purely vulnerability research in nature but still require an attacker mindset.You should enjoy having a variety of tasks over the course of a year.

In practical terms, if we gave you a computerized component of a car and a copy of the firmware binary running on it, could you identify and technically describe its cyber vulnerabilities?Could you build a tool that demonstrates one of those vulnerabilities?

Application Requirements

Before you apply, make sure you meet these requirements or you will be rejected:

  • US Citizen with TOP SECRET clearance eligibility
  • Experience and skillset aligned with the role (firmware reverse engineering experience and skills; cyber vulnerability research skills; protocol analysis skills; communication skills; self-motivation and drive; clear interest in the work)
  • We do not have Certification or Degree requirements for this position -- your skill alone sets you apart
  • Willingness to do at least one oral technical interview (1 hour long) over a virtual conferencing solution (like Zoom) in the period of 9am - 6pm Eastern.We can possibly accommodate other times if you ask.

There are also preferred skills that will strengthen your application:

  • C/C++ programming experience
  • CNO experience
  • Hands-on hardware experience
  • RF experience
  • Firmware programming experience

There are also preferred conditions that will strengthen your application:

Local residence and willingness to commute to Reston, VA and Fairfax, VA as needed for hands-on work (we can discuss employee relocation to the area if willing)

Experience with government cyber capability development

Understand that the best applicants will be both strong technical and strong cultural fits.

Compensation

We are a small company yet we strive to compensate every employee as best we can.We manage to offer low-to-no deductible healthcare, competitive salaries, equity options, profit-sharing options, retirement benefits, fitness/gym benefits, a hardware/home office stipend, security clearances, holidays, PTO, and a firm belief in work-life balance.We also accept good ideas and are open to hearing exactly what compensates you best.

Non-Discrimination

We will not discriminate based on race, color, religion, sex (including pregnancy, sexual orientation, or gender identity), national origin, disability, age or genetic information (including family medical history) per federal law and our beliefs as a company.We base our hiring decisions on if you are the best fit for the job and customer requirements.But don't expect everyone to agree with your values when you arrive -- we expect that the best employees will come from a variety of different backgrounds and identities, but share one goal.We don't believe it is our company's job to tell you who you are or what you should value, but we do hope Legion X can be a place where you are open to share exactly who you are and what you believe, yet still find a team of other excellent people ready to work alongside you and get to know you better.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Offensive Cyber Engineer
Offensive Cyber Engineer

Cryptic Vector • Fredericksburg (VA)

On-site
USD 120,000 - 180,000
100% Company-paid medical insurance
100% Company-paid dental and vision
Competitive salary and bonus
+2
Offensive Cyber Engineer
Offensive Cyber Engineer

Crypticvector • Atlanta (GA)

On-site
USD 120,000 - 180,000
Medical insurance
Dental insurance
Vision insurance
+7
Offensive Cyber Engineer
Offensive Cyber Engineer

Cryptic Vector • Atlanta (GA)

On-site
USD 90,000 - 120,000
100% Company-paid medical insurance
100% Company-paid dental and vision insurance
Competitive salary and bonus
+5
Vulnerability Researcher
Vulnerability Researcher

Intelliforce-IT Solutions Group, LLC. • Maryland

On-site
USD 120,000 - 160,000
Ample PTO
Multiple medical plan options
Generous 401(k)
+2
Senior Vulnerability Researcher — Firmware & Exploits (Remote)
Senior Vulnerability Researcher — Firmware & Exploits (Remote)

Legion X • Arlington (VA)

Hybrid
USD 120,000 - 180,000
Lead Vulnerability Researcher ($285k+/year + Sign-On Bonus)
Lead Vulnerability Researcher ($285k+/year + Sign-On Bonus)

Socket.dev • Linthicum (MD)

On-site
USD 285,000 - 300,000
Medical insurance
Dental and vision
401(k) matching
+2
Senior Vulnerability Researcher ($250k+/year + Sign-On Bonus)
Senior Vulnerability Researcher ($250k+/year + Sign-On Bonus)

Socket.dev • Linthicum (MD)

On-site
USD 250,000 - 285,000
Health, dental, and vision
401(k) matching
Professional development
+2
Lead Vulnerability Researcher
Lead Vulnerability Researcher

RiseMe • Arlington (VA)

On-site
USD 154,000 - 231,000
Medical insurance
Dental insurance
Vision insurance
+6
Senior Vulnerability Researcher ($250k+/year + Sign-On Bonus)
Senior Vulnerability Researcher ($250k+/year + Sign-On Bonus)

Trusted Concepts, Inc. • Linthicum (MD)

On-site
USD 250,000 - 285,000
Sign-On Bonus
Health/Dental/Vision
401(k) matching
+2
Lead Vulnerability Researcher
Lead Vulnerability Researcher

Two Six Technologies • Dayton (OH)

On-site
USD 100,000 - 130,000
Medical, dental, and vision insurance
Life and disability insurance
Retirement benefits
+3