Job Title: Junior 5G Vulnerability Researcher
Job Category: Engineering
Time Type: Full time
Minimum Clearance Required to Start: None
Employee Type: Regular
Percentage of Travel Required: None
Type of Travel: None
* * *
The Opportunity:
We are seeking a Vulnerability Researcher to join our 5G security team, focusing on protocol analysis and firmware reverse engineering. This role is for a practitioner with a strong systems background who is ready to take ownership of research tasks within complex telecommunications stacks. You will work as part of a high-performing group, identifying security flaws in 3GPP protocols and proprietary telecom binaries while developing the automated tooling necessary to secure national mobile infrastructure.
Responsibilities:
- Execute research into 3GPP protocols (NGAP, GTP, etc.) to identify crashes and logic flaws using stateful fuzzing techniques.
- Perform static and dynamic analysis on compiled telecom binaries and firmware to understand undocumented protocol logic.
- Support the development of custom Python3 scripts for protocol decoding and automating analysis of "closed-box" systems.
- Assist in mapping state machines within 5G session management flows using symbolic or concolic execution tJools.
- Analyze signaling and data plane components to identify potential attack surfaces in 5G Core and RAN environments.
- Use debugging tools and packet analysis software (e.g., Wireshark) to inspect protocol traffic and hardware state.
- Document research findings and contribute to the development of technical security reports.
Qualifications:
Required:
- 3–5 years of professional experience in software exploitation, reverse engineering, or protocol development.
- Proficiency in software development (C/C++, Python).
- Working knowledge of networking protocols (TCP/IP, SCTP, HTTP/2).
- Experience with disassembly tools such as IDA Pro, Ghidra, or Binary Ninja.
- Foundational understanding of binary analysis and memory corruption primitives.
- Demonstrated ability to conduct independent technical research and analyze complex software systems.
- Must be a US Citizen and able to obtain/maintain a security clearance
Desired:
- An active TS SCI clearance.
- Experience with software-defined radio (SDR) or cellular testing equipment.
- Working knowledge of cellular networking protocols (3G, 4G, 5G).
- Familiarity with Linux-based telecom network functions.
- Participation in security research projects or CTFs with a focus on networking or pwnable challenges.
This position is contingent on funding and may not be filled immediately. However, this position is representative of positions within CACI that are consistently available. Individuals who apply may also be considered for other positions at CACI.
Pay Range:
There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits.
The proposed salary range for this position is:
$79,400 - $162,700