Vulnerabilities Security Researcher SME

Remote Full-time
• **We are unable to sponsor for this permanent full-time role***
• **Position is bonus eligible***

Prestigious Enterprise Company is currently seeking an Expert Vulnerabilities Security Researcher. Candidate will be responsible for analyzing systems, software, architectures, and strategies to discover impactful, unknown vulnerabilities and security weaknesses, including those affecting AI/ML systems and AI-enabled technologies and services. This work proactively identifies classes of vulnerabilities and exploitation opportunities that inform mitigation strategies and secure design.

The role involves performing manual source code review, binary analysis, vulnerability assessments, dynamic testing, threat modeling, and security architecture review. The researcher conducts ongoing analysis of real-world adversaries, exploitation methods, and emerging attack surface and offensive security techniques to guide research priorities. Development of custom tooling and automation is required to augment manual vulnerability discovery.

Responsibilities:

Conducts research to identify highly impactful, unknown vulnerabilities in a wide variety of applications and technologies, including AI-enabled applications and services

Performs vulnerability assessments using industry best practices on various environments, including web applications, APIs, and cloud infrastructure

Develops and manages testing methodologies that adhere to common security guidelines and NIST standards

Conducts an evaluation of cloud security configurations, identifies prevalent vulnerabilities in cloud security controls, and improves and maintains cloud testing standards

Provides detailed reports with proof of vulnerabilities, guidance, and advice to support customer teams through vulnerability remediation

Develops and communicates comprehensive and accurate reports and presentations for client stakeholders including technical staff and executive leadership

Maintains communication with management regarding development within assigned responsibilities and performs special projects as required

Researches and develops innovative techniques, tools, and methodologies for vulnerability research and red team activities

Develops leadership-level communications, including management-specific metrics, white papers, procedures, thought position papers, etc.

This list is not all-inclusive, and you are expected to perform other cybersecurity-congruent duties as requested or assigned

Qualifications:

7+ years of professional work experience in the cybersecurity industry with Bachelor’s degree in Computer Science, Management Information Systems, or a related field, or equivalent work experience.

Understanding of all phases of adversary emulation operations, including reconnaissance, social engineering, exploitation, post-exploitation, covert techniques, lateral movement, and data exfiltration.

Extensive experience in offensive cybersecurity roles, such as red teaming, penetration testing (e.g., web, infrastructure, cloud), and purple team exercises across cloud and on-prem environments.

Robust understanding of contemporary security theory, application exploitation techniques, and attack vectors, including the vulnerability lifecycle and scanning methodologies (SAST, DAST, IAST, RASP).

Experience developing and managing testing methodologies that adhere to common security guidelines such as OWASP and frameworks such as NIST 800 or MITRE ATT&CK.

Solid understanding of computer architecture and organization with respect to binary analysis and exploitation.

Ability to analyze, create, and debug shellcode and other low-level exploits.

Experience developing custom security software (offensive or defensive) in one or more compiled languages.

Demonstrated ability to reverse engineer binaries, enumerate vulnerabilities in compiled software, and provide working exploits (e.g., CVEs, public acknowledgements, or the ability to demonstrate on demand).

Familiarity with automated security analysis and fuzzing tools (e.g., AFL and Peach).

Demonstrated ability to discover vulnerabilities via static analysis and source code review.

Working understanding of key programming languages and frameworks (e.g., Java, Node.js, Python, JSP), including the ability to quickly learn new languages, understand their security implications, and enumerate vulnerabilities in custom-developed software packages.

Familiarity with scripting and programming in Python, PowerShell, or C#, with the ability to create and customize tools.

Apply Now

Apply Now
Apply Now

Similar Opportunities

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote Full-time

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote Full-time

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote Full-time

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote Full-time

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote Full-time

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote Full-time

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote Full-time

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote Full-time

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote Full-time

USPS Office Helper

Remote Full-time

Experienced Remote Data Entry Specialist – Full-Time Opportunity for Accurate and Detail-Oriented Professionals at arenaflex

Remote Full-time

**Experienced Remote Data Entry Specialist – Join arenaflex's Dynamic Team and Soar to New Heights**

Remote Full-time

Sales Development Representative; Remote – North Carolina | Tech Sales

Remote Full-time

Online Typing Jobs - Part-Time or Full-Time

Remote Full-time

Southwest Airlines Data Entry At Home- No Experience/Entry Level ?...

Remote Full-time

[PART_TIME Remote] Customer Service Agent - PT- Remote WFH After

Remote Full-time

Athletics Bus Driver (Part-time)

Remote Full-time

Remote Corporate Counsel

Remote Full-time

Delta Airline Jobs In Michigan $26/Hour

Remote Full-time

Associate Technical Account Manager

Remote Full-time
← Back to Home