Exploit Developer

CoStar Group

$108K — $162K *

clock More than 8w ago

compensation-icon

Experience:Not Specified

bookmark empty
report an issue with job

Job Description

STR is hiring a Exploit Developer who has a passion for research and analysis of vulnerabilities in cyber physical systems. Work must be performed onsite.

What you will do:
  • Reverse engineering complex software or firmware targets, ranging from typical Windows/Linux binaries to embedded firmware running non-traditional computer architectures and operating systems
  • Developing and applying automated reverse engineering and binary analysis tools to characterize protocols, interfaces, and functionality of target systems
  • Developing innovative cybersecurity solutions
  • Working in multi-discipline teams to tackle challenging problems from a wide variety of technologies to develop innovative cybersecurity solutions
  • Performing vulnerability weaponization, exploit development, payload development, and exploit mitigation on a variety of challenging targets
  • Developing custom emulation solutions to enable dynamic analysis
  • Documenting, demonstrating, and presenting research
  • Solving real world problems that have an impact on national security

Who you are:
  • This position requires an Active Secret security clearance and the ability to obtain a Top Secret (TS) clearance, for which U.S. citizenship is needed by U.S. Government.
  • BS, MS or PhD in Computer Science, Computer Engineering, Cybersecurity or related field (or equivalent work experience)
  • Experience with binary analysis of software/firmware
  • Experience with disassembly tools, such as IDA Pro, Binary Ninja, or Ghidra
  • Proficiency in one or more programming languages: C/C++, Python, etc.
  • Proficiency in one or more Assembly Languages: x86, ARM, etc.
  • General understanding of reverse engineering fundamentals: memory layout, calling conventions, etc.

Nice to have:
  • Active Security Clearance at the Top Secret (TS) level
  • Vulnerability research and analysis
  • Knowledge of weaponizing discovered vulnerabilities into exploits
  • Implant or software patch development
  • Familiarity with binary emulation or vulnerability research, including tools such as QEMU or AFL++
  • Operating system internals including memory/process/thread management
  • Embedded systems or firmware analysis
  • Knowledge of anti-reverse engineering techniques
  • Analyzing protocols or message structures
  • Knowledge of binary file structures and formats
  • Developing automated reverse engineering or software analysis tools
  • Developing disassembler/decompiler modules
  • Debugging software without source code
  • Analyzing and reconstructing code/data flow
  • Knowledge of intrusion detection and anti-malware systems and techniques


STR is a growing technology company with locations near Boston, MA, Arlington, VA, near Dayton, OH, Melbourne, FL, and Carlsbad, CA. We specialize in advanced research and development for defense, intelligence, and national security in: cyber; next generation sensors, radar, sonar, communications, and electronic warfare; and artificial intelligence algorithms and analytics to make sense of the complexity that is exploding around us.

STR is committed to creating a collaborative learning environment that supports deep technical understanding and recognizes the contributions and achievements of all team members. Our work is challenging, and we go home at night knowing that we pushed the envelope of technology and made the world safer.

STR is not just any company. Our people, culture, and attitude along with their unique set of skills, experiences, and perspectives put us on a trajectory to change the world. We can't do it alone, though - we need fellow trailblazers. If you are one, join our team and help to keep our society safe! Visit us at www.str.us for more info.

STR is an equal opportunity employer. We are fully dedicated to hiring the most qualified candidate regardless of race, color, religion, sex (including gender identity, sexual orientation and pregnancy), marital status, national origin, age, veteran status, disability, genetic information or any other characteristic protected by federal, state or local laws.

If you need a reasonable accommodation for any portion of the employment process, email us at [redacted] and provide your contact info.

Pursuant to applicable federal law and regulations, positions at STR require employees to obtain national security clearances and satisfy the requirements for compliance with export control and other applicable laws.
CoStar Group is a provider of information, analytics and marketing services to the commercial property industry in the United States, Canada, the United Kingdom, France, Germany, and Spain. Founded in 1987 by Andrew C. Florance, the company has grown to include online database CoStar and many online marketplaces, including Apartments.com, LoopNet, Lands of America, and BizBuySell.

CoStar Group was founded in 1987 by Andrew C. Florance in Washington, D.C.

In 1998, the company became a public company via an initial public offering on the NASDAQ, raising $22.5 million.

In 2004, CoStar Group, Inc. v. LoopNet, Inc. became a landmark case in copyright law.

In October 2009, the company acquired a building in Washington, D.C., now its headquarters, from the Mortgage Bankers Association for $41.3 million. The building had sold 2 years earlier for $79 million and the company claims it used its analytics data to know the right time to buy.

In April 2012, CoStar Group acquired LoopNet for $860 million.

In April 2014, the company acquired Apartments.com for $585 million.

In April 2015, the company acquired Apartment Finder for $170 million. In July, the company acquired Belbex an online marketplace and information provider for commercial property based in Spain.

In February 2017, the company acquired Westside Rentals.

In February 2018, the company acquired ForRent.com from Dominion Enterprises for $350 million in cash and $35 million in stock. In October, the company acquired Realla.co an online marketplace for commercial property based in the United Kingdom. In November, the company acquired Cozy Services for $68 million.
stats icon
Total value of jobs:
$207,488,606
stats icon
Total Jobs:
77
stats icon
Average Pay:
$132,495
stats icon
% Masters:
28%

More Jobs at STR

$70K — $110K *

Today

• Not Specified years exp

Hospitality & Recreation

In-Person

$80K — $130K *

Today

• Not Specified years exp

Hospitality & Recreation

In-Person

$80K — $130K *

Today

• Not Specified years exp

Hospitality & Recreation

In-Person

$150K — $200K *

3d ago

• Not Specified years exp

Hospitality & Recreation

In-Person

$80K — $120K *

2w ago

• Not Specified years exp

Hospitality & Recreation

In-Person

Find similar Threat Analyst jobs: