Full-Time

Vulnerability Researcher

Confirmed live in the last 24 hours

Arsiem Corporation

Arsiem Corporation

11-50 employees

IT consulting and cybersecurity for governments

Consulting
Cybersecurity

Compensation Overview

$148k - $235kAnnually

Senior, Expert

No H1B Sponsorship

Odenton, MD, USA

This position requires an active TS/SCI with a polygraph. You must be a US Citizen for consideration.

US Top Secret Clearance, US Citizenship Required

Category
Cybersecurity
IT & Security
Required Skills
Python
Operating Systems
C#
Perl
Assembly
C/C++

You match the following Arsiem Corporation's candidate preferences

Employers are more likely to interview you if you match these preferences:

Degree
Experience
Requirements
  • Bachelor's Degree in Computer Science or related field, or minimum two (2) years experience in computer science, information systems, or network engineering
  • Minimum two (2) years experience programming in Assembly, C, C#, C++, Perl, or Python
  • Minimum two (2) years of demonstrated experience in either hardware or software reverse engineering
  • Minimum four (4) years experience programming in Assembly, C, C#, C++, Perl, or Python for a production environment (for Level 2)
  • Minimum of five (5) years contiguous experience in computer science, information systems, or network engineering; or Bachelor's Degree in Computer Science or related field plus minimum three (3) years contiguous experience (for Level 2)
  • Minimum four (4) years demonstrated experience in either hardware or software reverse engineering (for Level 2)
  • Proven results from participation in vulnerability discovery efforts within the last twelve (12) months (for Level 3)
  • Demonstrated ability to discover multiple previously unknown vulnerabilities (0-day) across multiple versions of similar technologies (for Level 3)
  • Demonstrated ability to discover multiple previously unknown vulnerabilities (0-day) that achieve reliable remote code execution and/or reliable privilege escalation (for Level 3)
Responsibilities
  • Provide engineering and vulnerability research results related to hardware components, software applications, and operating systems to determine functionality, code structure, and system design for use in the discovery of initial access capabilities
  • Actively debug software and troubleshoot issues with software crashes and programmatic flow
  • Provide written reports, proof-of-concept code, prototypes, and hands-on demonstrations of reverse engineering and vulnerability analysis results
  • Provide/author and participate in technical presentations on assigned projects (for Level 1)
  • Ability to perform source code analysis in an effort to discover software flaws, and provide/author documentation on the impact and severity of the flaw (for Level 2)
  • Ability to develop proof-of-concept exploits against research targets, prototypes, and hands-on demonstrations of vulnerability analysis results (for Level 2)
  • Lead reverse engineering and vulnerability research of hardware components, software applications, and operating systems to determine functionality, code structure, and circuit design for the use in the discovery of initial access capabilities (for Level 2)
  • Lead efforts to debug software and troubleshoot issues with software crashes and programmatic flow (for Level 3)
  • Ability to develop robust exploits (advancements beyond initial proof-of-concept such as version coverage, decreased failure rate, handling edge cases, etc.) against research targets, prototypes, and hands-on demonstrations of vulnerability analysis results (for Level 3)
  • Edit/Approve and participate in technical presentations on assigned projects (for Level 3)
  • Subject Matter Expert and Leader of at least one technology area responsible for reverse engineering and vulnerability analysis of hardware components, software applications, and operating systems to determine functionality, code structure, and circuit design for the use in the discovery of initial access capabilities (for Level 3)
Desired Qualifications
  • Experience programming in Assembly, C, C#, C++, Perl, or Python with a focus on an understanding of system interactions with these libraries vs. production-style environments
  • Use of Unix/Windows system API’s
  • Understanding of virtual function tables in C++
  • Heap allocation strategies and protections
  • Experience with very large software projects a plus
  • Kernel programming experience (WDK / Unix||Linux) a significant plus
  • Hardware/Software reverse engineering, which often includes the use of tools (e.g., IDA Pro, Ghidra, Binary Ninja) to identify abstract concepts about the code flow of an application
  • For Hardware reverse engineering, candidates are expected to have performed analysis of embedded devices, focusing primarily on identifying the software stack and points of entry to the hardware (e.g., not interested in FPGA reverse engineering, or other circuit reverse engineering)
  • Candidates who can merge low-level knowledge about the compilation of C/C++ code with a nuanced understanding of system design to identify and exploit common vulnerability patterns. Candidates should be comfortable with, at a minimum, user-mode stack-based buffer overflows, and heap-based exploitation strategies.

ARSIEM Corporation provides advanced IT consulting services, specializing in multiple areas including cybersecurity, enterprise architecture and development, and applications development, predominantly for government clients. The firm is distinguished by its deep commitment to cybersecurity and robust IT solutions that ensure enhanced protection and efficient digital infrastructures. This commitment to leveraging cutting-edge technologies in specialized areas of IT makes ARSIEM Corporation an excellent workplace for professionals aiming to actively contribute to significant, high-impact projects within the government sector.

Company Size

11-50

Company Stage

N/A

Total Funding

N/A

Headquarters

Baltimore, Maryland

Founded

2013

Growth & Insights

Headcount

6 month growth

0%

1 year growth

-2%

2 year growth

0%