Software Reverse Engineer

Peraton

$135K — $216K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree with 8+ years of relevant experience; OR Master's degree with 6+ years of relevant experience; OR PhD with 3+ years of relevant experience in fields such as Cybersecurity or Software Engineering.
  • Active TS/SCI clearance with Polygraph required.
  • 3+ years of experience in software reverse engineering, with a preference for malware analysis or vulnerability research backgrounds.
  • Strong understanding of Windows and Linux internals, x86/x64 and ARM architectures.
  • Experience with static analysis tools like IDA Pro, Ghidra, and debugging tools like WinDbg.

Responsibilities

  • Conduct comprehensive analysis of software and firmware to identify vulnerabilities.
  • Utilize virtualization and sandboxing tools to observe software in real-time environments.
  • Perform live debugging to analyze code execution and validate findings against static analysis.
  • Use advanced reverse engineering tools to decompile software and uncover hidden functionalities.
  • Investigate and develop proof-of-concept exploits for identified vulnerabilities.
  • Utilize a specialized toolchain for thorough analysis and exploitation.
  • Mentor junior engineers in software reverse engineering methodologies and tools.

Benefits

  • Opportunities for professional development and skill enhancement.
  • Mentorship responsibilities provide leadership experience.
  • Cutting-edge technology and projects in a dynamic environment.
  • Possibility for work in collaborative team settings.
  • Supportive corporate culture that prioritizes cybersecurity advancements.
Full Job Description
Responsibilities

Peraton is seeking a highly skilled and experienced Senior Software Reverse Engineer to join our team in Bethesda, MD.  In this role, you will perform in-depth analysis of software, firmware, and hardware systems to uncover its true functionality, identify vulnerabilities, and understand their operational context. This position requires a holistic approach, combining dynamic system analysis, static binary reverse engineering, and document exploitation to reveal not just what a system does, but why and how it supports its mission objectives.

Key Responsibilities:

  • System Analysis:Conduct comprehensive analysis of compiled software and binaries. Employ forensic techniques to extract critical artifacts, understand system architecture, and identify key software components.
  • Dynamic System & Environment Analysis:Utilize virtualization and sandboxing environments (VMware, KVM/QEMU) to run and observe software in its native operating environment. Perform system call tracing, network monitoring, and file system analysis to reveal real-time behaviors and interactions.
  • Live Debugging and Analysis:Perform live, on-system debugging to step through code execution in real-time. Correlate dynamic findings with static analysis from Ghidra/IDA Pro to validate assumptions, understand complex logic, and uncover obfuscated functionality.
  • Static Reverse Engineering:Use advanced reverse engineering tools, with a focus on Ghidra and IDA Pro, to decompile and disassemble software. Analyze code paths, extract indicators, and uncover hidden or malicious logic not apparent through dynamic analysis alone.
  • Vulnerability and Capability Research:Investigate and identify vulnerabilities, undocumented features, and novel capabilities within target systems. Develop proof-of-concept exploits and assess their potential operational impact. Model and simulate specific features and functions to understand how software was developed, compiled, and deployed.
  • Tool Chain Mastery:Employ a specialized toolchain for analysis, including disk imagers, virtual machine managers, network scanners, and debuggers to perform end-to-end exploitation.
  • Mentorship:Mentor junior engineers in SWRE methodologies, tools, and techniques.
Qualifications

Required Qualifications:

  • Bachelor's degree with 8+ years of relevant experience; OR Master's degree with 6+ years of relevant experience; OR PhD with 3+ years of relevant experience. A degree within one of the following fields is highly desired: Information Technology, Cybersecurity, Computer Science, Information Systems, Data Science, or Software Engineering. In lieu of a degree, an additional 4 years of relevant experience may be considered.
  • Active TS/SCI clearance with Polygraph is required.
  • 3+ years of demonstrated experience in software reverse engineering, with a preference for backgrounds in material exploitation, malware analysis, or vulnerability research.
  • Understanding of Windows and Linux operating system internals, x86/x64 and ARM assembly, and CPU architecture.
  • Experience with static analysis tools such as IDA Pro, Ghidra, and Binary Ninja.
  • Experience with debugging tools such as WinDbg, GDB, and similar platforms.
  • Experience with virtualization, sandboxing, and emulation tools such as VMware, KVM, QEMU, and others.
  • Experience with the SWRE toolchain, including network analysis tools (Wireshark, nmap) and Linux command-line proficiency.
  • Experience with forensic disk image analysis to mount, modify, and extract artifacts from raw disk images.
  • Ability to unpack, de-obfuscate, and analyze highly complex malicious applications.
  • Experience in Linux/Unix environments, including advanced command-line operations and system-level administration.
  • Knowledge of low-level programming languages (C, C++, Assembly) and scripting languages such as Python, Java, or .NET.
  • A solid understanding of common security practices and the ability to identify security flaws in software architecture.

Desired Qualifications:

  • Active DoD 8570, IAT Level II Certification.
  • Knowledge of advanced firmware analysis techniques and methodologies.
  • Knowledge of secure boot processes.
  • Familiarity with hardware-level attack techniques such as side-channel analysis or fault injection.
  • Experience with Field Programmable Gate Array (FPGA) development.
  • Experience monitoring hardware-level buses and interfaces such as i2C, USB, or JTAG.
  • Familiarity with risk assessment and mitigation strategies for firmware vulnerabilities.
  • Strong documentation skills to maintain detailed records of analysis processes and findings.
Target Salary Range$135,000 - $216,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

Similar Jobs

More Jobs at Peraton

More Information Technology Jobs

Find similar Software Reverse Engineer jobs: