Security Product Reverse Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Security Product Reverse Engineer (Cybersecurity): Perform reverse engineering of security products to identify vulnerabilities, weaknesses, and design flaws with an accent on low-level system analysis across modern operating systems. Focus on conducting vulnerability research on OS internals, developing exploits, and supporting Computer Network Exploits against security appliances.
Location: Onsite at customer site in Sterling, VA. Current TS/SCI with Poly Clearance required.
Company
provides cyber operations, vulnerability research, data intelligence, and mission support services to intelligence community, defense, and commercial customers.
What you will do
- Perform reverse engineering of security products to identify vulnerabilities, weaknesses, and design flaws
- Conduct source code analysis and comprehensive code audits
- Develop, test, and debug tooling and exploits in C, C++, and Python
- Analyze binaries and firmware using IDA Pro, Ghidra, and other tools
- Conduct vulnerability research on operating system internals and security mechanisms
- Support development and testing of Computer Network Exploits against commercial and embedded security products
- Document findings and communicate technical results to stakeholders
Requirements
- Current TS/SCI with Poly Clearance
- Minimum 3 years developing, testing, and debugging software in C, C++, and Python
- Minimum 3 years using IDA Pro and/or Ghidra for reverse engineering
- Minimum 3 years performing source code analysis and code auditing
- At least 3 years hands-on Vulnerability Research experience in Windows internals, Linux kernel, or macOS internals
- Minimum 5 years developing and testing CNEs against personal security products, security appliances, or embedded OS security solutions
Nice to have
- Strong understanding of operating system internals and memory management
- Experience with obfuscation, anti-debugging, and anti-reverse engineering techniques
- Familiarity with exploit mitigations and bypass strategies
- Excellent analytical, problem-solving, and documentation skills
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →