Research Innovations Incorporated

Vulnerability Researcher I/II (Cyber264)

Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in security research and vulnerability analysis
  • Proficient in wireless networking and security protocols
  • Strong understanding of exploit mitigations and bypass techniques
  • Experience with operating system internals across major platforms
  • Programming skills in Python3 and C for security research
  • Excellent communication skills, both verbal and written
  • Familiar with low-level architectures like x86, ARM, or MIPS

Responsibilities

  • Conduct in-depth reverse engineering and vulnerability analysis across diverse architectures
  • Analyze operating systems and applications to identify security strengths and weaknesses
  • Enhance functionality by adding features to undocumented interfaces
  • Model in-memory application behavior to identify vulnerabilities
  • Develop mobile and embedded systems related to vulnerability research
  • Participate in a mentorship program, sharing knowledge with colleagues

Benefits

  • Flexible work schedules
  • Comprehensive health insurance coverage
  • Paid time off from day one
  • 401k plan with company match
  • Paid parental leave
  • Access to wellness programs
  • Comfortable office amenities including community game room and massage chair
Full Job Description
Position Title: Security Researcher
Location: St. Petersburg, FL | Melbourne, FL | San Antonio, TX
Clearance Requirement: Top Secret/SCI
Employment type: Full Time


We are seeking security researchers to independently explore and exploit complex systems, from kernels to embedded platforms, to solve the unsolvable. This role combines deep technical problem-solving with real-world impact on defense and homeland security systems. Get s#it done.

This position requires an Active US Top Secret security clearance, and the ability to upgrade to TS/SCI Special Access Program access

WHAT YOU WILL BE DOING

  • Conducting in-depth reverse engineering and vulnerability analysis across various architectures and platforms, including x86/64, ARM, PowerPC, and more
  • Researching and analyzing operating system and application internals, identifying and understanding security strengths and weaknesses of those systems
  • Developing and enhancing functionality by adding features and capabilities to undocumented interfaces
  • Modeling and analyzing in-memory compiled application behavior to identify potential vulnerabilities and improve security measures
  • Developing and understanding mobile/embedded systems and kernel modules, particularly related to vulnerability research
  • Participating actively in our extensive Vulnerability Research mentorship program, sharing knowledge and collaborating with colleagues


WHAT YOU HAVE DONE

  • Proficient understanding of wireless networking and associated security protocols, such as Wi-Fi (802.11), Bluetooth, or cellular networks (2G/3G/4G/5G). Familiarity with common vulnerabilities and attack vectors in wireless communication
  • Strong grasp of legacy exploit mitigations and bypass techniques, including but not limited to Address Space Layout Randomization (ASLR), Data Execution Prevention (DEP/NX), Stack Cookies (Canaries), and Control Flow Integrity (CFI). Experience in identifying and circumventing these security measures
  • In-depth knowledge of both security and network fundamentals, such as cryptography, authentication, access control, and network protocols (TCP/IP, UDP, DNS, HTTP, etc.). Understanding the security implications and potential vulnerabilities associated with these concepts
  • Programming experience with both scripted languages (preferably Python3) and compiled languages (preferably C). Ability to write efficient and secure code for vulnerability research and exploit development purposes
  • Familiarity with low-level architectures such as x86, ARM, or MIPS. Understanding the underlying principles, instruction sets, and memory models of these architectures for vulnerability identification and analysis
  • Experience with operating system internals and implementations, including Windows, Linux, or macOS. Knowledge of system structures, process management, memory management, and security mechanisms at the kernel level
  • Excellent oral, written, and interpersonal communication skills, with the ability to effectively convey complex technical concepts and interact with customers and team members alike


EVEN BETTER

  • Experience with vulnerability research and reverse engineering of real-time operating systems (RTOS), such as FreeRTOS, QNX, or VxWorks. Understanding the unique security challenges and attack vectors specific to RTOS environments
  • Bachelor's or postgraduate degree in Computer Science, Computer Engineering, or a related field
  • Experience with software protection and binary armoring techniques, such as anti-debugging, code obfuscation, or tamper resistance. Understanding the methods employed to protect software from reverse engineering and vulnerability discovery
  • Proficiency in agile development methodologies, including Scrum or Kanban, for efficient collaboration and iterative development in a cybersecurity context
  • Familiarity with low-level iOS/Android development and associated security considerations, such as jailbreaking or rooting, application sandboxing, or secure interprocess communication (IPC)
  • Knowledge of hypervisors and their security implications, including virtualization-based security, guest escape vulnerabilities, or hypervisor-based rootkits
  • Proficiency in malware analysis, including static and dynamic analysis techniques, behavioral analysis, and code deobfuscation. Experience in identifying and analyzing malware samples to understand their capabilities and potential vulnerabilities
  • Experience with constraint solving techniques, such as symbolic execution, theorem proving, or model checking, for vulnerability identification, verification, and exploit generation
  • Background in machine learning, particularly in the context of vulnerability analysis and detection, such as using ML techniques to identify patterns in code or analyze network traffic for anomaly detection


We also offer all employees comprehensive benefits including: flexible work schedules, health insurance coverage, paid time off, 401k with a company match, paid parental leave, access to wellness programs and much more. You get this all from day one, and all paid for by RII.

It's all part of another of our core values: Stay human. It's why our comfortable and colorful offices such as our headquarters, include a community game room, pantry, massage chair, and an escape room, among other amenities. It's why we have community ambassadors and regular community events.

#LI-AC1

About Research Innovations Incorporated

Research Innovations Incorporated (RII) is a technology company that provides software and systems engineering services to government and commercial clients. The company was founded in 1999 and is headquartered in Reston, Virginia. RII's services include software development, systems engineering, and data analytics. The company has worked with a variety of clients, including the Department of Defense, the Department of Homeland Security, and the National Institutes of Health. RII is committed to innovation and has received several awards for its work, including the 2019 Innovation Award from the Northern Virginia Chamber of Commerce.
Learn more about Research Innovations Incorporated
Size
200 employees
Industry
Net Income
$5 million
Founded
1999
5 Year Trend
+20%
Revenue
$25 million

Similar Jobs

More Jobs at Research Innovations Incorporated

More Information Technology Jobs

Find similar Vulnerability Researcher I/II (Cyber264) jobs: