Lead Vulnerability Researcher ($285k+/year + Sign-On Bonus)

Two Six Technologies

$285K — $300K *
Technical Services
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Doctorate in Computer Science, Computer/Electrical Engineering, or related field with 4 years of relevant experience, or equivalent educational and experiential background.
  • Proficiency in programming languages C/C++, Python, and familiarity with ISA (e.g., x86/ARM/MIPS).
  • Experience in Linux command-line environments and reverse engineering tools like IDA Pro, Binary Ninja, or Ghidra.
  • Knowledgeable in vulnerability research tools including emulators and fuzzers.
  • Skilled in using software debuggers such as GDB or WinDbg.
  • Active TS/SCI clearance with Polygraph required.

Responsibilities

  • Lead vulnerability identification across hardware, software, and operational systems.
  • Develop proof of concept (PoC) code for identified vulnerabilities.
  • Reverse-engineer embedded systems to identify vulnerabilities.
  • Review source code for potential risks and vulnerabilities.
  • Assess the impact of vulnerabilities on mission outcomes and operational effectiveness.
  • Propose operationally effective countermeasures based on attack techniques.
  • Mentor junior engineers, fostering their development and reviewing methodologies.

Benefits

  • Comprehensive health, dental, and vision coverage.
  • 401(k) matching with contributions.
  • Paid professional development and tuition assistance.
  • Flexible PTO with rollover options and annual payout opportunities.
  • Sign-on bonus starting at $25,000 for qualified hires.
Full Job Description
Compensation & Incentive Highlights
  • Target Base Salary: $285,000+ (Final salary is determined based on candidate qualifications and experience alignment with open roles)
  • Sign-On Bonus: Starting at $25,000 for qualified FSP hires.
  • Benefits & Flexible PTO: Comprehensive health, dental, and vision coverage, 401(k) matching, paid professional development, tuition assistance, and flexible PTO with rollover options and annual payout opportunities.

Overview of Opportunity

Join the Trusted Electronics & Effects team at Two Six Technologies, where you'll lead vulnerability research across hardware, software, and operational systems. Working side by side with engineers and security researchers, you'll guide investigations, identify critical vulnerabilities, and develop countermeasures with operational impact. Our fast-growing roster of government customers relies on us to deliver advanced security solutions, and we're looking for a Lead Vulnerability Researcher to provide technical leadership and mentorship.

This role requires regular on-site support at the Linthicum, Maryland customer site.

What you will do:
  • Lead the identification of vulnerabilities and attacks across hardware, software, personnel, logistics, procedures, and physical security.
  • Develop proof of concept (PoC) code for identified vulnerabilities
  • Reverse-engineer targeted embedded systems to identify vulnerabilities
  • Review source code looking for risks and vulnerabilities
  • Analyze the effects of vulnerabilities on mission outcomes and operational effectiveness.
  • Compare system attack techniques and propose operationally effective countermeasures
  • Produce reports, briefings, and perspectives on actual and potential attacks
  • Provide technical leadership on research efforts, prioritizing investigations, reviewing methodologies, and overseeing proof-of-concepts.
  • Mentor and guide junior engineers and researchers, reviewing technical approaches and fostering skill development.

What you will need (Basic Qualifications):
  • Doctorate in Computer Science, Computer/Electrical Engineering, or a related field and 4 years of relevant experience, OR Master's degree and 6 years of relevant experience, OR Bachelor's degree and 8 years of relevant experience, OR Associate's degree and 10 years of relevant experience.
    • Relevant experience: computer/information systems design/development, programming, information/cyber/network security, reverse-engineering, vulnerability analysis, penetration testing, computer forensics, information assurance, or systems engineering
  • Proficiency in C/C++, Python, and at least one ISA (e.g. x86/ARM/MIPS)
  • Proficiency in Linux command-line environments
  • Experience using a decompiler such as IDA Pro, Binary Ninja, or Ghidra
  • Experience using vulnerability research tools such as emulators or fuzzers
  • Experience using a software debugger such as GDB or WinDbg
  • Ability to work on-site at Linthicum, Maryland customer site regularly.

Nice If You Have (Preferred):
  • Experience translating vulnerabilities into operationally relevant impact assessments and countermeasures.
  • Experience producing client-facing technical briefings for operational stakeholders
  • Experience using a hardware debugger
  • Experience with UART, SPI, I2C
  • Experience with common secure communications such as TLS or SSH
  • Familiarity with embedded firmware, RTOS, or networked systems
  • Familiarity with high-side environments

Security Clearance:
  • Active TS/SCI clearance with Polygraph required

#LI-AM1

#LI-ONSITE

Two Six Technologies is committed to providing competitive and comprehensive compensation packages that reflect the value we place on our employees and their contributions. We believe in rewarding skills, experience, and performance. Our offerings include but are not limited to, medical, dental, and vision insurance, life and disability insurance, retirement benefits, paid leave, tuition assistance and professional development.

The projected salary range listed for this position is annualized. This is a general guideline and not a guarantee of salary. Salary is one component of our total compensation package and the specific salary offered is determined by various factors, including, but not limited to education, experience, knowledge, skills, geographic location, as well as contract specific affordability and organizational requirements.

Salary Range

$284,999-$300,000 USD

Similar Jobs

More Jobs at Two Six Technologies

More Technical Services Jobs

Find similar Lead Vulnerability Researcher ($285k+/year + Sign-On Bonus) jobs: