Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cleared Vulnerability Research Engineer

$154.8k - $193.5k

Bugcrowd

We are Bugcrowd. Since 2012, we've been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.

Job Summary

This role is focused on end-to-end exploit development for real-world targets. The specialist will design, develop, and validate novel vulnerability discovery and exploitation capabilities against complex software and systems. Work is conducted at the operating system, binary, and micro-architectural levels, with a strong emphasis on creating new technical capabilities. Success in this position requires the ability to independently translate an under-defined mission objective into a concrete, technically novel capability and the comfort of operating with minimal supervision, incomplete problem definitions, and delayed feedback.

Education, Experience, Knowledge, Skills, and Abilities
  • Design, develop, and validate novel vulnerability discovery and exploitation capabilities.
  • Conduct expert reverse engineering of binaries (x86-64, ARM64, etc.) using industry-standard tools.
  • Identify and exploit real-world vulnerabilities such as Use-after-free, Type confusion, Integer truncation, and Buffer overflow.
  • Demonstrate ability to discover new, novel vulnerabilities in complex systems.
  • Rapidly understand current vulnerability research and apply findings to identify new instances of vulnerability classes.
  • Employ both manual analysis and automated techniques (e.g., fuzzing) for vulnerability discovery.
  • Code and debug complex functions in C, Python, and Assembly (x86-64, ARM, etc.).
  • Independently manage and execute research objectives, including scoping, research, experimentation, validation, and iteration.
  • Travel to customer sites as required.
  • Perform on-site for extended periods of time.
Education, Experience, Knowledge, Skills, and Abilities
  • Exploit Development:
    • Expertise in reverse engineering of binaries (x86-64, ARM64, etc) using tools such as Binary Ninja, Ghidra, or IDA Pro.
    • Precise understanding of stack and heap objects and exploit-relevant vulnerabilities (e.g., Use-after-free, Type confusion, Integer truncation, Buffer overflow).
  • Vulnerability Discovery:
    • Demonstrated ability to discover new vulnerabilities, not just exploit known ones.
    • Experience with both manual analysis and automated techniques (e.g., fuzzing).
  • Languages:
    • Ability to code and debug C, Python, and Assembly (x86-64, ARM, etc).
  • Research Ownership & Autonomy:
    • Ability to independently translate an under defined mission objective into a concrete, technically novel capability.
    • Comfort operating with minimal supervision.
  • Clearance & Logistics:
    • TS/SCI clearance required (inactive SCI acceptable if SCI-clearable).
    • Ability to travel to customer sites as required.
Working Conditions and Physical Requirements

The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.
Sitting and / or standing - Must be able to remain in a stationary position 50% of the time
Carrying and / or lifting - Must be able to carry / move laptop as needed throughout the work day.
Environment - remote, work-from-home with travel to customer location in Alabama to perform work in cleared spaces.

Pay Range Disclosure

At Bugcrowd, we strive for fairness, equality and to create an environment that allows our people to perform at their very best. Our compensation philosophy is to foster a collaborative community that rewards, attracts and retains the best possible talent. The provided salary details are based on US national averages and we retain the flexibility to tailor to the needs of the business.

The national estimate for the current base range for the position is $154,800 - $193,500.

This position may also be eligible to participate in a discretionary bonus program or commission plan, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Culture
  • At Bugcrowd, we understand that diversity in the workplace is vital to a company's success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
  • We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
  • Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists-you get the point.

At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.

Disclaimer

This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.

The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).

Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required bylaw.

Any personal data you submit in connection with your application will be processed in compliance with Bugcrowd's Privacy Policy, which you may review here:

Equal Employment Opportunity:

Bugcrowd is EOE, Disability/Age Employer.


Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.


Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.

Apply at:
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Cleared Vulnerability Research Engineer in United States vacancy
  •  ...Vulnerability Research Engineer – Mid-Level Location: Northern Virginia Travel: None Clearance: Minimum active Top Secret/Active TS/SCI...  ...technical documentation and communicate technical findings clearly Collaborate with cross-functional engineering and research... 
    Suggested
    Local area

    SMFS

    Sterling, VA
    2 days ago
  • $115k - $181k

     ...Overview i3 is seeking a Vulnerability Research Engineer to support the Naval Research Laboratory’s Tactical Electronic Warfare Division. You will...  ...test and evaluation events. Document findings in clear technical reports, including diagrams, evidence, limitations... 
    Suggested
    Full time

    Integration Innovation, Inc.

    Washington DC
    4 days ago
  •  ...security, creating patches for critical vulnerabilities and building the systems that help the...  ...and testing Work with security researchers to understand and patch critical vulnerabilities...  ...: ~3+ years of software engineering experience with production systems ~... 
    Suggested
    Remote work
    Worldwide
    Flexible hours

    Socket

    United States
    1 day ago
  • $62k - $141k

     ...Job Number: R0231147 Location: Chantilly,VA,US Share job via: Share Vulnerability Research Engineer and Developer Key Role: Conduct research and analysis to identify vulnerabilities and potential threat vectors... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    United States
    3 days ago
  •  ...Windows Kernel & Vulnerability Research Engineer Chantilly, VA TS/SCI to start Key Responsibilities Conduct in-depth research into Windows internals, including system architecture, memory management, drivers, processes, and kernel-mode operations. Perform... 
    Suggested

    thejosefgroup.com

    Annapolis Junction, MD
    2 days ago
  • Description & Requirements Vulnerability Researcher Maximus conducts advanced vulnerability research to strengthen Department of War (DoW...  ...Identify zero-day and known vulnerabilities - Conduct reverse engineering and exploit development - Analyze complex hardware and... 
    Minimum wage
    Contract work
    Temporary work
    Work experience placement

    Navstar

    San Antonio, TX
    1 day ago
  •  ...Cisco Systems, Inc. is hiring for a remote role focusing on vulnerability research. The position involves developing tools for vulnerability analysis, reverse engineering, and creating proof-of-concept exploits. Candidates should have over three years of experience in... 
    Remote work

    Cisco

    Fulton, MD
    3 days ago
  • A leading research organization in Columbus, OH is seeking a Reverse Engineer. This position involves conducting vulnerability research, utilizing advanced tools like Ghidra and BinaryNinja, and working with a team of experts. Candidates should hold a Bachelor's degree... 

    Battelle

    Columbus, OH
    4 days ago
  • A leading cybersecurity and intelligence services firm in the United States seeks a qualified engineer to perform vulnerability research, reverse engineering, and tool development for complex systems. Candidates must hold a TS/SCI clearance and have a strong background... 

    Nightwing

    Brooklyn, NY
    1 day ago
  • $86.8k - $198k

     ...Job Number: R0221763 Location: Chantilly,VA,US Share job via: Share iOS Vulnerability Research Engineer and Developer, Senior Key Role: Conduct research and analysis to identify vulnerabilities and potential threat... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    United States
    3 days ago
  •  ...Regular Job Description AV is inviting experienced fully cleared software engineers and FS/CI poly analysts at all career stages to join us...  ...includes cybersecurity, network exploitation, SIGINT analysis, vulnerability assessment, penetration testing, and/or network analysis... 
    Permanent employment

    AeroVironment

    Annapolis, MD
    5 days ago
  • $86.8k - $198k

    iOS Vulnerability Research Engineer and Developer, Senior**Key Role:**Conduct research and analysis to identify vulnerabilities and potential threat vectors into systems and networks, develop computer network operations (CNO) and computer network exploitation (CNE) exploits... 
    Full time
    Contract work
    Part time
    Local area
    Remote work

    Booz Allen Hamilton

    Quantico, VA
    5 days ago
  • DepthFirst in San Francisco is seeking an experienced Research Engineer. You will build and train AI agents for discovering and remediating software vulnerabilities. Responsibilities include developing evaluation benchmarks and training procedures. The ideal candidate... 
    Work at office

    DepthFirst

    San Francisco, CA
    4 days ago
  • $170k - $210k

     ...an AI-driven pentester that discovers vulnerabilities before they’re exploited. As adversaries...  ...Role We are looking for a Security Research Engineer who ships. You will own the research and...  ..., a design decision, or a tradeoff clearly Location : United States (Remote) Salary... 
    Full time
    Remote work

    RunSybil

    New York, NY
    3 days ago
  •  ...delivers when others can’t. We conduct research and development, manage national laboratories...  ...currently seeking an aspiring Reverse Engineer to work in our Columbus, OH or Chantilly, VA offices. Do you enjoy conducting vulnerability research from scratch? Do you have... 
    Work at office
    Remote work
    Flexible hours

    Battelle

    Columbus, OH
    3 days ago
  • Senior Reverse Engineer/Vulnerability Researcher (Onsite) page is loaded## Senior Reverse Engineer/Vulnerability Researcher (Onsite)remote type: Onsite Customerlocations: Huntsville, ALtime type: Full timeposted on: Posted 7 Days Agojob requisition id: JR101408Nightwing... 
    Local area
    Remote work
    Flexible hours

    Nightwing Group

    Huntsville, AL
    1 day ago
  • A technology firm in Huntsville, AL seeks a Senior Reverse Engineer/Vulnerability Researcher to join their elite team. This role involves conducting advanced vulnerability research and reverse engineering for complex systems. Candidates must have expert-level knowledge... 

    Nightwing Group

    Huntsville, AL
    1 day ago
  •  ...Authority For Offensive Cyber Research Program You will serve as...  ...You'll partner closely with engineering, product, and operations...  ...technical bar and raise it—through clear standards, strong reviews,...  ...in malware development, vulnerability research, or exploit engineering... 
    Full time
    Work at office
    Flexible hours

    Twenty Inc.

    Washington DC
    2 days ago
  • $128k - $170k

     ...PlatformResearchgroup is seeking a Staff Research Engineer to join our diverse team of...  ...for significant trends in threats and vulnerabilities, and leverage operational workflows that...  ...able to communicate those decisions in a clear and concise manner to other members of... 
    Work experience placement
    Local area
    Worldwide
    Flexible hours
    Shift work

    lwtsquad

    Columbia, MD
    1 day ago
  • Overview Engineer/Vulnerability Module & Engagement Analyst (DETO-2026-24615): Bowhead seeks new team members in their support to the Navy’s Weapons Systems Munitions Integration and Hypersonic division. Bowhead seeks an analyst to perform Target Vulnerability characterizations... 
    For contractors
    Work at office

    UIC Arctic Response Services, LLC

    Dahlgren, VA
    21 hours ago
  • RESEARCH ENGINEER - SR. RESEARCH ENGINEER - Computational Thermofluid Engineer 18-01568 Who We Are: The Propulsion & Energy Machinery Section...  ...required. Relevant degrees will also be considered. A valid/clear driver's license is required. Special Requirements: Applicant... 

    Southwest Research Institute

    San Antonio, TX
    3 days ago
  • $109.3k - $191k

     ...Cyber Research And Development Engineer We are searching for a self-motivated Cyber Research And Development...  ...expertise in reverse engineering, vulnerability research, and software development...  ...to express technical information clearly and concisely in documents and... 
    Full time
    Work experience placement
    Remote work
    Work from home

    Penn State University

    Annapolis Junction, MD
    9 hours ago
  •  ...include cyber space operations, cyber defense and resiliency, vulnerability research, ubiquitous technical surveillance, data intelligence,...  ...the most advanced technical challenges. The team comprises engineers of multiple disciplines including vulnerability research, reverse... 

    Nightwing

    Indialantic, FL
    6 days ago
  •  ...Research Engineer San Francisco, CA $750k+ Total Comp. This is a rare opportunity to build production grade AI systems that directly...  ...workflows and validate solutions Translate field insights into clear technical and product priorities Your Skills and... 
    Work at office

    Harnham

    Santa Rosa, CA
    2 days ago
  • $225k - $300k

     ...CLEAR is building THE secure identity company of the future. Our mission is to make experiences safer and easier-physically and...  ...frictionless experiences. As a Senior Product Security Engineer, Vulnerability Management on our Product Security team you'll help run and... 
    Casual work
    Work at office
    Flexible hours

    Clear

    New York, NY
    4 days ago
  • A leading defense technology firm is inviting experienced and fully cleared software engineers and analysts of all levels to an exclusive hiring event in Maryland. Candidates will have the opportunity to engage with technical leaders, explore impactful work, and learn... 

    BlueHalo

    Annapolis, MD
    3 days ago
  • $190.58k

     ...About the Position You're an experienced engineer who combines deep technical skill with...  ...drive complex projects across Murmuration's research and data science enablement systems:...  ...capabilities and practical usability. Communicate clearly: You’ll provide actionable guidance to... 
    Full time
    Remote work
    Home office
    Flexible hours

    murmuration

    New York, NY
    3 days ago
  • $100k - $190k

     ...The Cato Institute seeks qualified candidates for the Senior Research Engineer, Applied AI position. AI tools are proliferating rapidly. Making...  ...concepts to non-technical researchers and document systems clearly Self-directed, intellectually curious, and comfortable... 
    Full time

    Cato Institute

    Washington DC
    2 days ago
  • $86.28k - $175.47k

     ...assess the performance of a variety of engineering materials that are used in a wide range...  ...team to perform fundamental and applied research through the development of advanced fatigue...  ..., and verification. ~ A valid/clear driver's license is required. ~ Salary... 
    Permanent employment
    Contract work
    Work experience placement
    Remote work

    Southwest Research Institute

    United States
    9 hours ago
  •  ...Description Job Description We are Genmo, a research lab dedicated to building open, state-of-...  ...We're seeking an exceptional Software Engineer to join our research team in advancing...  ...or personal) with generative models ~ Clear communication skills and ability to work... 
    Work at office

    Genmo

    San Francisco, CA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cleared Vulnerability Research Engineer. Be the first to apply!