Vulnerability Researcher*III

BTS Software Solutions

Corridor North (MD)

On-site

USD 260,000 - 300,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

100% company-paid health benefits
PTO
401(k) matching
vesting from day one

Job summary

BTS Software Solutions is seeking a Vulnerability Researcher III to join their team in Annapolis Junction, MD. The role involves active debugging, source code analysis, and development of exploits against vulnerabilities.

The ideal candidate will have programming experience across multiple languages, a deep understanding of security vulnerabilities, and experience in both hardware and software reverse engineering.

Competitive salary range of $260,000 to $300,000 and comprehensive benefits offered.

Qualifications

  • Experience with vulnerability discovery efforts within the last twelve months.
  • Ability to discover multiple previously unknown vulnerabilities (0-day) across versions.

Responsibilities

  • Debug software and troubleshoot issues.
  • Perform source code analysis for software flaws.
  • Develop proof-of-concept exploits and conduct vulnerability analysis.
  • Lead projects and serve as a subject-matter expert.

Skills

Programming in Assembly, C, C#, C++, Perl, or Python
Experience with Unix/Windows system APIs
Understanding of virtual function tables in C++
Knowledge of heap allocation strategies and protections
Kernel programming experience (WDK / Unix/Linux)
Hardware/Software reverse engineering
Experience analyzing embedded devices
Ability to exploit common vulnerability patterns

Education

Qualifications of a CNO Vulnerability Researcher/Analyst II

Tools

IDA Pro
Ghidra
Binary Ninja

Job description

Vulnerability Researcher III

REQ ID: 976-03

Company: BTS Software Solutions is seeking a Vulnerability Researcher III with an active TS/SCI w/ POLY to join our team in Annapolis Junction, MD.

What You'll Get To Do:
  • Actively debug software and troubleshoot issues with software crashes and programmatic flow.
  • Perform source code analysis to discover software flaws and provide documentation on the impact and severity of the flaw.
  • Develop proof‑of‑concept exploits against research targets, prototypes, and hands‑on demonstrations of vulnerability analysis results.
  • Provide and author technical presentations on assigned projects, and lead reverse engineering and vulnerability research.
  • Lead efforts to debug software and troubleshoot issues with software crashes and programmatic flow.
  • Develop robust exploits (advancements beyond initial proof‑of‑concept such as version coverage, decreased failure rate, handling edge cases, etc.) against research targets, prototypes, and hands‑on demonstrations of vulnerability analysis results.
  • Edit, approve and participate in technical presentations on assigned projects.
  • Serve as a subject‑matter expert and leader of at least one technology area responsible for reverse engineering and vulnerability analysis.
You’ll Bring These Skills:
  • Experience programming in Assembly, C, C#, C++, Perl, or Python, with a focus on understanding system interactions with these libraries in production‑style environments.
  • Use of Unix/Windows system APIs.
  • Understanding of virtual function tables in C++.
  • Knowledge of heap allocation strategies and protections.
  • Experience with very large software projects (a plus).
  • Kernel programming experience (WDK / Unix/Linux) – a significant plus.
  • Hardware/Software reverse engineering, including the use of tools such as IDA Pro, Ghidra, Binary Ninja to identify abstract concepts about code flow.
  • Experience analyzing embedded devices for hardware reverse engineering, focusing on identifying the software stack and points of entry to the hardware.
  • Ability to merge low‑level knowledge of C/C++ compilation with a nuanced understanding of system design to identify and exploit common vulnerability patterns, including user‑mode stack‑based buffer overflows and heap‑based exploitation strategies.
Education / Qualifications:
  • Meets all qualifications of a CNO Vulnerability Researcher/Analyst II, but with increased experience and skill levels.
  • Proven results from participation in vulnerability discovery efforts within the last twelve (12) months.
  • Demonstrated ability to discover multiple previously unknown vulnerabilities (0‑day) across multiple versions of similar technologies.

Pay Range: $260,000 to $300,000

Benefits: 100% company‑paid health benefits, PTO, 401(k) matching and vesting from day one, and other perks. For more details, visit www.unleashbts.com/careers/.

BTS Software Solutions is an Equal Opportunity Employer (EOE). All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other basis as protected by federal, state, or local law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vulnerability Researcher II
Vulnerability Researcher II

BTS Software Solutions • Corridor North (MD)

On-site
USD 200,000 - 260,000
Company-paid health benefits
PTO
401K matching
System Vulnerability Analyst (Level I-IV)
System Vulnerability Analyst (Level I-IV)

BTS • Columbia (MD)

On-site
USD 110,000 - 220,000
Competitive health benefits
PTO
401K matching
System Vulnerability Analyst (Level I-IV)
System Vulnerability Analyst (Level I-IV)

BTS Software Solutions • Corridor North (MD)

On-site
USD 110,000 - 220,000
Health benefits
PTO
401K matching
Senior Vulnerability Researcher — Exploit & RE Lead
Senior Vulnerability Researcher — Exploit & RE Lead

BTS Software Solutions • Corridor North (MD)

On-site
USD 260,000 - 300,000
100% company-paid health benefits
PTO
401(k) matching
+1
Senior Vulnerability Researcher (TS/SCI)
Senior Vulnerability Researcher (TS/SCI)

BTS Software Solutions • Corridor North (MD)

On-site
USD 200,000 - 260,000
Company-paid health benefits
PTO
401K matching
Intrusion Analyst (Levels I-III)
Intrusion Analyst (Levels I-III)

BTS • Columbia (MD)

On-site
USD 100,000 - 190,000
Competitive health benefits package
PTO
401K matching
vulnerability researcher
vulnerability researcher

NPAworldwide • Saint Petersburg (FL)

On-site
USD 156,000 - 234,000
Relocation assistance
Vulnerability Researcher-Mid
Vulnerability Researcher-Mid

NetSage • Maryland

On-site
USD 90,000 - 120,000
EXPLOITATION ANALYST (Levels I-IV)
EXPLOITATION ANALYST (Levels I-IV)

BTS • Columbia (MD)

On-site
USD 120,000 - 260,000
Competitive health benefits
PTO
401K matching
Vulnerability Researcher - Hybrid - TS/SCI Arlington, VA
Vulnerability Researcher - Hybrid - TS/SCI Arlington, VA

Stanley Reid & Company • Arlington (VA)

Hybrid
USD 120,000 - 190,000
Hybrid work arrangement