Principal Embedded Vulnerability Researcher
$95k - $237.5kDraper Labs
Overview:
Draper is an independent, nonprofit research and development company headquartered in Cambridge, MA. The 2,000+ employees of Draper tackle important national challenges with a promise of delivering successful and usable solutions. From military defense and space exploration to biomedical engineering, lives often depend on the solutions we provide. Our multidisciplinary teams of engineers and scientists work in a collaborative environment that inspires the cross-fertilization of ideas necessary for true innovation. For more information about Draper, visit
Job Description Summary:
Draper's Offensive Cyber Security Group is looking for dedicated individuals to develop tailored solutions to meet our DoD and IC Sponsor directives. Our organization's not-for-profit status ensures a capability-driven focus on the United States of America's national interests that allows us to address some of our Nation's most pressing challenges. Due to the variety of USG organizational needs, our technical efforts and opportunities vary from conventional cyber operations enablement tooling to embedded vulnerability research and exploit development on a wide range of devices and systems.Job Description:
Duties/Responsibilities
* Assess hardware and software for security vulnerabilities using a breadth of technologies and techniques.
* Develop software that meets behavior and security requirements for tailored applications.
* Integrate software capabilities with other tasks or groups to improve performance or behavior requirements.
* Create new tools and systems to detect and exploit vulnerabilities and system weaknesses.
* Document nominal application and system functionality, in addition to implemented changes.
* Independently drive solutions to complex problems - develop requirements, propose ways forward when customer requirements are unclear or incomplete, and adapt appropriately to changes in requirements.
* Subject Matter Expert (SME) in cyber security, able to plan, design, and execute large scale technical software and hardware solutions.
* Able to provide insight and suggest design modifications based on analysis outcomes, and to apply analysis techniques across a range of technical disciplines.
* Identify program/system-level technical risks and develop and execute mitigation strategies.
* Develop, document, and teach best practices to less experienced engineers; Demonstrate strong organization, planning, and time management skills to achieve program goals.
* Performs other related duties as assigned.
* Curiosity-driven approach to solving complex, customer-driven problems as part of a multi-disciplinary team.
* Collaborate and communicate effectively and openly with multi-disciplinary program team members, program leadership, and non-technical personnel.
* Be a team player able to work in a fast-paced environment with the ability to balance multiple competing tasks and demands. Education
Requires a bachelor's in computer science, computer engineering, or related field. Experience
10-15 years experience in Cybersecurity or related field is required.
Additional Job Description:
Program Analysis, Reverse Engineering, and Vulnerability Research:
- Proficiency with modern program analysis methodologies and techniques
- Reverse-engineering assessment techniques for firmware or embedded systems
- Familiarity with binary file and filesystem structures and formats
- Hands-on proficiency with reverse engineering tooling such as: Ghidra, IDA, GDB, RR
- Hands-on proficiency with physical instrumentation or hardware modification, soldering
- Experience with JTAG/SWD/BDM, and eMMC/NAND/SPI flash data extraction
- Exploitation techniques for embedded devices across platforms and architectures
- Familiarity of network stack and internals
- Familiarity of operating system internals throughout user mode, kernel mode, and during boot processes for at least one of the following: GNU/Linux, RTOS
- Familiarity with architectures and assembly: x86, ARM, Hexagon, PowerPC
Languages and Development:
- Proficiency with programming languages such as: C, C++, Python, Java
- Familiarity with scripting languages such as: Bash, Powershell
- Familiarity in development environments for GNU/Linux or Windows
Leadership and Business Development:
- Successful history in authoring of technical proposals and documents
- Leadership in advanced R&D initiatives, including government-funded projects
- Leadership of critical programs with more than two full time staff members
- Proficient in teamwork and communication with diverse audiences
Preferred Qualifications:
- Experience with side channel attacks (glitching) to place components and/or devices into altered states to bypass protections.
- Familiarity with custom filesystem extraction and modification, removal and/or regeneration of OOB/CRC data.
- Familiarity with bus and protocol analysis.
Applicants selected for this position must be required to obtain and maintain a government TS/SCI security clearance.
Connect With Draper for Future Opportunities! If you don't find the right posting in our Career Opportunities, you may submit your resume for future consideration.
Job Location - City:
CambridgeJob Location - State:
MassachusettsJob Location - Postal Code:
02139-3563The US base salary range for this full-time position is
$95,000.00 - $237,500.00Our salary ranges are determined by role, level, and location. The range displayed on each job posting reflects the minimum and maximum target salaries for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Union ranges will be in compliance with the collective bargaining agreement's approved rates by location and role. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.Please note that the compensation details listed in US role postings reflect the base salary only, and does not include bonuses or benefits.
Our work is very important to us, but so is our life outside of work. Draper supports many programs to improve work-life balance including workplace flexibility, employee clubs ranging from photography to yoga, health and finance workshops, off site social events and discounts to local museums and cultural activities. If this specific job opportunity and the chance to work at a nationally renowned R&D innovation company appeals to you, apply now
Draper is committed to creating an inclusive environment. We understand the value of inclusivity and its impact on a high-performance culture. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, national origin, veteran status, or genetic information. Draper is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation, please contact View email address on click.appcast.io.
Required
Preferred
Job Industries
- Other
- ...Vulnerability Researcher (Android) / Software Engineer (VR), Senior-Level Location: Chantilly VA. At REDLattice, we are a global leader... ...with hardware components Understanding of moble/embedded systems concepts Exposure to C/C++ in low-level systems...Suggested
- ...Principal Embedded SWE - Image Signal Processing Location: Dever, CO Duration: Long term 1. Principal embedded SWE - DSP / EM Navigation Key Responsibilities: Analyze and understand existing Python code for electromagnetic field computations....Principal
$75k - $156k
...Overview: Draper is an independent, nonprofit research and development company headquartered in Cambridge, MA. The 2,000+... ...vary from conventional cyber operations enablement tooling to embedded vulnerability research and exploit development on a wide range of devices...SuggestedFull timeLocal area$170k - $200k
...Current Job Openings Principal Embedded Linux Engineer Principal Embedded Linux Engineer Summary Title: Principal Embedded Linux Engineer ID: SPA-25-04-ISR Team: Space & Ground Systems Location: Herndon, VA More about this job Description HawkEye 360...PrincipalWork experience placementWorldwide- Trase Systems is looking for a Principal AI Researcher to define the long-term research direction for their AI operating system. This hands-on leadership role requires extensive experience in AI and machine learning, focusing on research, systems, and production deployment...PrincipalRemote job
$43.27 - $108.17 per hour
...could be a multi-year process. Location: Vienna, VA Description: The candidate will be working independently as a Vulnerability Researcher to identify flaws in software. The candidate must be familiar with the latest techniques in vulnerability research and...Hourly payContract workFor contractorsLocal areaRemote workRelocation package- ...Role Redhorse is transforming how the government utilizes data and technology. We are seeking a self-motivated Senior Vulnerability Researcher who is ready to solve some of the most challenging technical problems in a fast-paced environment supporting national security...Contract work
- ...Role:** We need Linux VRers to conduct reverse engineering, vulnerability research, and exploitation on Linux applications. Focus on native... ...experience developing and testing applications on Windows, Mac, Linux, Mobile, or Embedded platforms. TS/SCI w POLY Required...
$250k - $300k
Principal AI Researcher (Agentic Systems & AI Infrastructure) Seattle, WA or McLean, VA or Remote About Us Red Cell Partners is an incubation firm building and investing in rapidly scalable technology-led companies that are bringing revolutionary advancements to market...PrincipalRemote workShift work- ...Principal Software Test Engineer-Embedded- Defense Solutions As our Principal Test Engineer-Embedded , you will serve as the senior technical authority for test strategy, test system development and complex troubleshooting across products, materials and manufacturing...Principal
$95k - $245k
...Draper is an independent, nonprofit research and development company headquartered... ...Summary: Draper is actively seeking a Principal Cyber Software Engineer that will... ...cyber operations enablement tooling to embedded vulnerability research and exploit development on a...PrincipalFull timeLocal area- ...in national security. Role Clarity is seeking a Senior Principal, HR Business Partner (HRBP) to join a dynamic Human Resources... ...Deep experience in handling complex Employee Relations cases, embedding employment law principles and risk mitigation General knowledge...PrincipalWork at officeRemote work
- ...A leading federal contracting firm is seeking a Contracts Senior Principal to manage contract activities with U.S. Government agencies. This role requires over 15 years of experience in federal contracts management, with responsibilities including proposal preparation,...PrincipalContract workRemote work
$87.1k - $157.45k
...build,validate, and scale next-generation cyber and artificial intelligence (AI) capabilities. We are seeking a Senior AI Security Researcher who works at the intersection of cybersecurity, AI and agentic AI, and mission-aligned engineering, with a focus on developing...Local areaImmediate startRemote work- EDI Technical Analyst Job Description: ~15+ Years Experience ~ Strong demonstrated analytical skills applied to business software solutions maintenance and/or development. ~ Knowledge of the software development standards and practices. ~ Demonstrated ability...Principal
$156.4k - $234.6k
...applications to include code reviews, vulnerability assessments, and application security testing... ...Qualifications: Education: Sr. Principal Cyber Systems Engineer ~ Bachelor's... ...Management (EVM) ~ Experience with Embedded (C/C++), Scripting (Python) and Object-...PrincipalRelocation packageShift work$217.4k - $326k
...better company outcomes. Key Job Responsibilities As the principal Technical Program Manager for business-critical initiatives,... ..., and configuration concepts Container image management, vulnerability scanning, runtime security, and secure deployment practices...PrincipalWork at officeRemote workHome officeFlexible hours- ...Principal Threat Analysis Engineer Information Technology - Computer Software Job... ...Responsibilities Conduct project-based research into cyber attacks, working with... ...Knowledge of both Windows and Unix vulnerabilities. Familiarity with network-based attack...Principal
- Core Full Stack JAVA Developer This is a core full stack JAVA developer. Candidates must absolutely have JAVA, Springboot, Microservices, Redis and for the front end Angular or React, either will work, but hands on experience with front end Angular or React is a must...Principal
$262.5k - $299.6k
Applied Researcher II Overview: At Capital One, we are creating trustworthy and reliable AI systems, changing banking for good. For... ...AI Safety discourse, with the ability to document technical vulnerabilities and their direct impact on model privacy, alignment, and...Full timePart timeImmediate startFlexible hours- ...Principal Artificial Intelligence/Machine Learning Scientist AEEC is seeking a Principal Artificial Intelligence/Machine Learning... ...solving AI problems and advancing AI techniques, science and research agendas of AI in one or more areas. The candidate will be responsible...PrincipalFull timeTemporary workWork experience placement
$95k - $245k
...Draper is an independent, nonprofit research and development company headquartered in... ...visit Job Description Summary: The Principal Guidance and Control Engineer develops software... ...and proven techniques. * Develops embedded software based on prototype algorithms....PrincipalFull timeLocal area- ...Herndon, Virginia Type: Contract Job #3187 Principal Systems Engineer, Linux McLean, VA The Program is... ...environments; C2S/UC2S policies and procedures; familiarity with creation of S3/GLACIERS instances and with Rapid7 vulnerability scans and reports.PrincipalContract workWork experience placement
- ...HIGH LEVEL Iron Bow is seeking a Principal Cybersecurity Solutions Architect with... ...WHAT YOU'LL BE DOING Actively research, evaluate and drive next gen Enterprise... ...Extensive field experience conducting security vulnerability assessments based on regulatory...PrincipalRemote work
- ...Job Description Description The Senior Contracts Principal will lead the preparation, negotiation, and administration of large‑scale Firm Fixed Price (FFP) and defined‑delivery federal government contracts. This role not only ensures compliance with company policies...PrincipalContract work
- ...Senior Principal Cyber Software Test Engineer : The selected Software Test Engineer will have a background in maintaining and enhancing automated test scripts and creating and executing test procedures to support development, integration, regression and user acceptance...Principal
- ...Description Join SAIC as a Contracts Senior Principal - Shaping the Future of Federal Contracting (Remote) SAIC is on the search for an experienced Contracts Senior Principal to lead end-to-end contract management for various U.S. Government agencies, primarily supporting...PrincipalContract workRemote work
- ...and operationalizing capabilities; support the implementation of continuous security monitoring practices along with threat and vulnerability prevention, detection, and response capabilities. Collaborate with engineers, internal teams, and vendors to support all phases...PrincipalInternshipMonday to Friday
$184.8k - $277.2k
...the systems that protect the Workday product. Operating entirely within AWS, you will treat "Security as Code," ensuring our Vulnerability Management, SIEM, and SOAR tools are robust, scalable, and automated. You are the primary engineering partner to our SOC, building...PrincipalWork at officeRemote workHome officeFlexible hours$262.5k - $299.6k
Applied Researcher II Overview At Capital One, we are creating trustworthy and reliable AI systems, changing banking for good. For... ...AI Safety discourse, with the ability to document technical vulnerabilities and their direct impact on model privacy, alignment, and organizational...Full timePart timeLocal areaFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal Embedded Vulnerability Researcher. Be the first to apply!


