← Back to jobs

Sr. Vulnerability Researcher (US)

Company
VulnCheck
Location
United States
Work type
Full Time · Remote
Posted
2026-09-08

Job description

About the Role

We’re looking for a Senior Vulnerability Researcher to join our agentic vulnerability discovery team. This role sits within our Initial Access Intelligence group, which delivers exploits, detections, and other artifacts designed for active cyber defense. You'll work with a seasoned team of hackers and threat researchers to find and weaponize new vulnerabilities across a range of operating systems, platforms, and devices — before adversaries do.

You'll drive original research from exposure analysis and reverse engineering through vulnerability discovery and weaponized exploit development. You'll also help push the state of the art in how VulnCheck finds bugs by applying novel agentic approaches to vulnerability discovery and exploit creation. This is a 100% remote role based in the United States.

Why Join VulnCheck?

VulnCheck stands behind its mission to influence how organizations worldwide understand, assess, and remediate security vulnerabilities — and to deliver intelligence-based solutions that change the world.

You'll be joining a collaborative, supportive environment that values intellectual curiosity, technical mastery, and personal growth. (And more, below!)

Leverage your expertise: Work on cutting-edge threat intelligence initiatives that matter, alongside the top domain experts in the field.
Shape the industry: Influence how vulnerabilities are classified, scored, mapped, and remediated at scale for enterprise customers and for the entire cybersecurity industry.
Grow your impact: Collaborate with global partners, lead high-visibility research, and drive standards across the security community.
Innovate and explore: Conduct original research and develop tooling — including agentic and automated approaches — for finding and understanding new vulnerabilities.

What You'll Do

Conduct vulnerability research to identify net-new vulnerabilities across a range of operating systems, platforms, and devices
Reverse engineer a variety of firmware and software
Author original exploits, network rules (Suricata / Snort), and other artifacts (e.g., Docker containers, version scanners, ASM queries) to accompany new vulnerability finds
Apply and expand agentic approaches to scale vulnerability discovery and exploit development

What You'll Bring

5+ years of full-time vulnerability research experience, including experience targeting networking device firmware, embedded Linux/RTOS-based systems, and/or network protocols
Demonstrable experience with agentic approaches to vulnerability discovery and exploit development
Experience developing original (weaponized) exploit code
Comfort acquiring, unpacking, and analyzing target firmware and appliances, including reasoning about network protocols and unauthenticated attack surface
Familiarity with embedded architectures (MIPS, ARM) and firmware extraction/unpacking (e.g., binwalk).
Experience with dynamic analysis and debugging on embedded/emulated targets (e.g., QEMU)
Working knowledge of common networking protocols (TCP/IP, routing protocols, VPN protocols such as IPsec/SSL-VPN, SNMP, etc.).
Strong reverse engineering skills, including static and dynamic analysis of compiled binaries and firmware (VulnCheck uses Ghidra for reversing)
Strong command of memory corruption and other vulnerability classes (e.g., stack and heap overflows, use-after-free, type confusion, integer errors, command and path injection, authentication and logic flaws)
Solid working knowledge of C/C++ and at least one scripting language (e.g., Python)
Experience working on technical projects remotely, alone, and on small teams.

Preferred Qualifications

Prior cybersecurity work experience (at a vendor or in government)
A track record of discovering new vulnerabilities (e.g., CVEs, advisories, exploits, or published research)
Able to share example research or exploit code written

Original source