Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Principal Embedded Vulnerability Researcher

$95k - $237.5k

Draper Labs

Overview:

Draper is an independent, nonprofit research and development company headquartered in Cambridge, MA. The 2,000+ employees of Draper tackle important national challenges with a promise of delivering successful and usable solutions. From military defense and space exploration to biomedical engineering, lives often depend on the solutions we provide. Our multidisciplinary teams of engineers and scientists work in a collaborative environment that inspires the cross-fertilization of ideas necessary for true innovation. For more information about Draper, visit

Job Description Summary:

Draper's Offensive Cyber Security Group is looking for dedicated individuals to develop tailored solutions to meet our DoD and IC Sponsor directives. Our organization's not-for-profit status ensures a capability-driven focus on the United States of America's national interests that allows us to address some of our Nation's most pressing challenges. Due to the variety of USG organizational needs, our technical efforts and opportunities vary from conventional cyber operations enablement tooling to embedded vulnerability research and exploit development on a wide range of devices and systems.

Job Description:

Duties/Responsibilities
* Assess hardware and software for security vulnerabilities using a breadth of technologies and techniques.
* Develop software that meets behavior and security requirements for tailored applications.
* Integrate software capabilities with other tasks or groups to improve performance or behavior requirements.
* Create new tools and systems to detect and exploit vulnerabilities and system weaknesses.
* Document nominal application and system functionality, in addition to implemented changes.
* Independently drive solutions to complex problems - develop requirements, propose ways forward when customer requirements are unclear or incomplete, and adapt appropriately to changes in requirements.
* Subject Matter Expert (SME) in cyber security, able to plan, design, and execute large scale technical software and hardware solutions.
* Able to provide insight and suggest design modifications based on analysis outcomes, and to apply analysis techniques across a range of technical disciplines.
* Identify program/system-level technical risks and develop and execute mitigation strategies.
* Develop, document, and teach best practices to less experienced engineers; Demonstrate strong organization, planning, and time management skills to achieve program goals.
* Performs other related duties as assigned.

Skills/Abilities
* Curiosity-driven approach to solving complex, customer-driven problems as part of a multi-disciplinary team.
* Collaborate and communicate effectively and openly with multi-disciplinary program team members, program leadership, and non-technical personnel.
* Be a team player able to work in a fast-paced environment with the ability to balance multiple competing tasks and demands.

Education
Requires a bachelor's in computer science, computer engineering, or related field.

Experience
10-15 years experience in Cybersecurity or related field is required.

Additional Job Description:

Program Analysis, Reverse Engineering, and Vulnerability Research:

  • Proficiency with modern program analysis methodologies and techniques
  • Reverse-engineering assessment techniques for firmware or embedded systems
  • Familiarity with binary file and filesystem structures and formats
  • Hands-on proficiency with reverse engineering tooling such as: Ghidra, IDA, GDB, RR
  • Hands-on proficiency with physical instrumentation or hardware modification, soldering
  • Experience with JTAG/SWD/BDM, and eMMC/NAND/SPI flash data extraction
  • Exploitation techniques for embedded devices across platforms and architectures
  • Familiarity of network stack and internals
  • Familiarity of operating system internals throughout user mode, kernel mode, and during boot processes for at least one of the following: GNU/Linux, RTOS
  • Familiarity with architectures and assembly: x86, ARM, Hexagon, PowerPC

Languages and Development:

  • Proficiency with programming languages such as: C, C++, Python, Java
  • Familiarity with scripting languages such as: Bash, Powershell
  • Familiarity in development environments for GNU/Linux or Windows

Leadership and Business Development:

  • Successful history in authoring of technical proposals and documents
  • Leadership in advanced R&D initiatives, including government-funded projects
  • Leadership of critical programs with more than two full time staff members
  • Proficient in teamwork and communication with diverse audiences

Preferred Qualifications:

  • Experience with side channel attacks (glitching) to place components and/or devices into altered states to bypass protections.
  • Familiarity with custom filesystem extraction and modification, removal and/or regeneration of OOB/CRC data.
  • Familiarity with bus and protocol analysis.

Applicants selected for this position must be required to obtain and maintain a government TS/SCI security clearance.

Connect With Draper for Future Opportunities! If you don't find the right posting in our Career Opportunities, you may submit your resume for future consideration.

Job Location - City:

Cambridge

Job Location - State:

Massachusetts

Job Location - Postal Code:

02139-3563

The US base salary range for this full-time position is

$95,000.00 - $237,500.00

Our salary ranges are determined by role, level, and location. The range displayed on each job posting reflects the minimum and maximum target salaries for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Union ranges will be in compliance with the collective bargaining agreement's approved rates by location and role. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.Please note that the compensation details listed in US role postings reflect the base salary only, and does not include bonuses or benefits.

Our work is very important to us, but so is our life outside of work. Draper supports many programs to improve work-life balance including workplace flexibility, employee clubs ranging from photography to yoga, health and finance workshops, off site social events and discounts to local museums and cultural activities. If this specific job opportunity and the chance to work at a nationally renowned R&D innovation company appeals to you, apply now

Draper is committed to creating an inclusive environment. We understand the value of inclusivity and its impact on a high-performance culture. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, national origin, veteran status, or genetic information. Draper is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation, please contact View email address on click.appcast.io.

Required
Preferred
Job Industries
  • Other
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Principal Embedded Vulnerability Researcher in Reston, VA vacancy
  •  ...Vulnerability Researcher (Android) / Software Engineer (VR), Senior-Level Location: Chantilly VA. At REDLattice, we are a global leader...  ...with hardware components Understanding of moble/embedded systems concepts Exposure to C/C++ in low-level systems... 
    Suggested

    REDLattice

    Sterling, VA
    1 day ago
  •  ...Principal Embedded SWE - Image Signal Processing Location: Dever, CO Duration: Long term 1. Principal embedded SWE - DSP / EM Navigation Key Responsibilities: Analyze and understand existing Python code for electromagnetic field computations.... 
    Principal

    Kasmo Global

    Herndon, VA
    1 day ago
  • $75k - $156k

     ...Overview: Draper is an independent, nonprofit research and development company headquartered in Cambridge, MA. The 2,000+...  ...vary from conventional cyber operations enablement tooling to embedded vulnerability research and exploit development on a wide range of devices... 
    Suggested
    Full time
    Local area

    Draper Labs

    Reston, VA
    1 day ago
  • $170k - $200k

     ...Current Job Openings Principal Embedded Linux Engineer Principal Embedded Linux Engineer Summary Title: Principal Embedded Linux Engineer ID: SPA-25-04-ISR Team: Space & Ground Systems Location: Herndon, VA More about this job Description HawkEye 360... 
    Principal
    Work experience placement
    Worldwide

    HawkEye 360

    Herndon, VA
    1 day ago
  • Trase Systems is looking for a Principal AI Researcher to define the long-term research direction for their AI operating system. This hands-on leadership role requires extensive experience in AI and machine learning, focusing on research, systems, and production deployment... 
    Principal
    Remote job

    Trase Systems

    Mc Lean, VA
    2 days ago
  • $43.27 - $108.17 per hour

     ...could be a multi-year process. Location: Vienna, VA Description: The candidate will be working independently as a Vulnerability Researcher to identify flaws in software. The candidate must be familiar with the latest techniques in vulnerability research and... 
    Hourly pay
    Contract work
    For contractors
    Local area
    Remote work
    Relocation package

    Cipher Tech Solutions

    Vienna, VA
    27 days ago
  •  ...Role Redhorse is transforming how the government utilizes data and technology. We are seeking a self-motivated Senior Vulnerability Researcher who is ready to solve some of the most challenging technical problems in a fast-paced environment supporting national security... 
    Contract work

    Redhorse Corporation

    Herndon, VA
    a month ago
  •  ...Role:** We need Linux VRers to conduct reverse engineering, vulnerability research, and exploitation on Linux applications. Focus on native...  ...experience developing and testing applications on Windows, Mac, Linux, Mobile, or Embedded platforms. TS/SCI w POLY Required... 

    Falls Technology

    McLean, VA
    a month ago
  • $250k - $300k

    Principal AI Researcher (Agentic Systems & AI Infrastructure) Seattle, WA or McLean, VA or Remote About Us Red Cell Partners is an incubation firm building and investing in rapidly scalable technology-led companies that are bringing revolutionary advancements to market... 
    Principal
    Remote work
    Shift work

    Red Cell Partners

    Mc Lean, VA
    2 days ago
  •  ...Principal Software Test Engineer-Embedded- Defense Solutions As our Principal Test Engineer-Embedded , you will serve as the senior technical authority for test strategy, test system development and complex troubleshooting across products, materials and manufacturing... 
    Principal

    Curtiss-Wright

    Ashburn, VA
    4 days ago
  • $95k - $245k

     ...Draper is an independent, nonprofit research and development company headquartered...  ...Summary: Draper is actively seeking a Principal Cyber Software Engineer that will...  ...cyber operations enablement tooling to embedded vulnerability research and exploit development on a... 
    Principal
    Full time
    Local area

    Draper Labs

    Reston, VA
    1 day ago
  •  ...in national security. Role Clarity is seeking a Senior Principal, HR Business Partner (HRBP) to join a dynamic Human Resources...  ...Deep experience in handling complex Employee Relations cases, embedding employment law principles and risk mitigation General knowledge... 
    Principal
    Work at office
    Remote work

    Clarity Innovations

    Herndon, VA
    4 days ago
  •  ...A leading federal contracting firm is seeking a Contracts Senior Principal to manage contract activities with U.S. Government agencies. This role requires over 15 years of experience in federal contracts management, with responsibilities including proposal preparation,... 
    Principal
    Contract work
    Remote work

    SAIC

    Reston, VA
    4 days ago
  • $87.1k - $157.45k

     ...build,validate, and scale next-generation cyber and artificial intelligence (AI) capabilities. We are seeking a Senior AI Security Researcher who works at the intersection of cybersecurity, AI and agentic AI, and mission-aligned engineering, with a focus on developing... 
    Local area
    Immediate start
    Remote work

    Leidos

    Reston, VA
    1 day ago
  • EDI Technical Analyst Job Description: ~15+ Years Experience ~ Strong demonstrated analytical skills applied to business software solutions maintenance and/or development. ~ Knowledge of the software development standards and practices. ~ Demonstrated ability...
    Principal

    Samprasoft

    Reston, VA
    2 days ago
  • $156.4k - $234.6k

     ...applications to include code reviews, vulnerability assessments, and application security testing...  ...Qualifications: Education: Sr. Principal Cyber Systems Engineer ~ Bachelor's...  ...Management (EVM) ~ Experience with Embedded (C/C++), Scripting (Python) and Object-... 
    Principal
    Relocation package
    Shift work

    Northrop Grumman

    Sterling, VA
    3 days ago
  • $217.4k - $326k

     ...better company outcomes. Key Job Responsibilities As the principal Technical Program Manager for business-critical initiatives,...  ..., and configuration concepts Container image management, vulnerability scanning, runtime security, and secure deployment practices... 
    Principal
    Work at office
    Remote work
    Home office
    Flexible hours

    Workday

    Reston, VA
    2 days ago
  •  ...Principal Threat Analysis Engineer Information Technology - Computer Software Job...  ...Responsibilities Conduct project-based research into cyber attacks, working with...  ...Knowledge of both Windows and Unix vulnerabilities. Familiarity with network-based attack... 
    Principal

    Direct Staffing Inc

    Herndon, VA
    1 day ago
  • Core Full Stack JAVA Developer This is a core full stack JAVA developer. Candidates must absolutely have JAVA, Springboot, Microservices, Redis and for the front end Angular or React, either will work, but hands on experience with front end Angular or React is a must...
    Principal

    Samprasoft

    Reston, VA
    2 days ago
  • $262.5k - $299.6k

    Applied Researcher II Overview: At Capital One, we are creating trustworthy and reliable AI systems, changing banking for good. For...  ...AI Safety discourse, with the ability to document technical vulnerabilities and their direct impact on model privacy, alignment, and... 
    Full time
    Part time
    Immediate start
    Flexible hours

    Capital One

    McLean, VA
    13 hours ago
  •  ...Principal Artificial Intelligence/Machine Learning Scientist AEEC is seeking a Principal Artificial Intelligence/Machine Learning...  ...solving AI problems and advancing AI techniques, science and research agendas of AI in one or more areas. The candidate will be responsible... 
    Principal
    Full time
    Temporary work
    Work experience placement

    AEEC

    Reston, VA
    21 hours ago
  • $95k - $245k

     ...Draper is an independent, nonprofit research and development company headquartered in...  ...visit Job Description Summary: The Principal Guidance and Control Engineer develops software...  ...and proven techniques. * Develops embedded software based on prototype algorithms.... 
    Principal
    Full time
    Local area

    Draper Labs

    Reston, VA
    1 day ago
  •  ...Herndon, Virginia Type: Contract Job #3187 Principal Systems Engineer, Linux McLean, VA The Program is...  ...environments; C2S/UC2S policies and procedures; familiarity with creation of S3/GLACIERS instances and with Rapid7 vulnerability scans and reports.
    Principal
    Contract work
    Work experience placement

    Cornerstone Defense

    Herndon, VA
    4 days ago
  •  ...HIGH LEVEL Iron Bow is seeking a Principal Cybersecurity Solutions Architect with...  ...WHAT YOU'LL BE DOING Actively research, evaluate and drive next gen Enterprise...  ...Extensive field experience conducting security vulnerability assessments based on regulatory... 
    Principal
    Remote work

    Iron Bow Technologies

    Herndon, VA
    3 days ago
  •  ...Job Description Description The Senior Contracts Principal will lead the preparation, negotiation, and administration of large‑scale Firm Fixed Price (FFP) and defined‑delivery federal government contracts. This role not only ensures compliance with company policies... 
    Principal
    Contract work

    SAIC (Science Applications Int.)

    Reston, VA
    1 day ago
  •  ...Senior Principal Cyber Software Test Engineer : The selected Software Test Engineer will have a background in maintaining and enhancing automated test scripts and creating and executing test procedures to support development, integration, regression and user acceptance... 
    Principal

    IC-CAP, LLC

    Herndon, VA
    17 hours ago
  •  ...Description Join SAIC as a Contracts Senior Principal - Shaping the Future of Federal Contracting (Remote) SAIC is on the search for an experienced Contracts Senior Principal to lead end-to-end contract management for various U.S. Government agencies, primarily supporting... 
    Principal
    Contract work
    Remote work

    SAIC

    Reston, VA
    4 days ago
  •  ...and operationalizing capabilities; support the implementation of continuous security monitoring practices along with threat and vulnerability prevention, detection, and response capabilities. Collaborate with engineers, internal teams, and vendors to support all phases... 
    Principal
    Internship
    Monday to Friday

    Navy Federal Credit Union

    Vienna, VA
    3 days ago
  • $184.8k - $277.2k

     ...the systems that protect the Workday product. Operating entirely within AWS, you will treat "Security as Code," ensuring our Vulnerability Management, SIEM, and SOAR tools are robust, scalable, and automated. You are the primary engineering partner to our SOC, building... 
    Principal
    Work at office
    Remote work
    Home office
    Flexible hours

    Workday

    Reston, VA
    2 days ago
  • $262.5k - $299.6k

    Applied Researcher II Overview At Capital One, we are creating trustworthy and reliable AI systems, changing banking for good. For...  ...AI Safety discourse, with the ability to document technical vulnerabilities and their direct impact on model privacy, alignment, and organizational... 
    Full time
    Part time
    Local area
    Flexible hours

    Capital One National Association

    Mc Lean, VA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Principal Embedded Vulnerability Researcher. Be the first to apply!