Join our GrammaTech team and immerse yourself in reverse engineering and vulnerability research on a wide range of embedded systems, software, and operational processes. Working alongside reverse engineers and security researchers, you’ll identify vulnerabilities, analyze attack vectors, and assess operational impacts on some of the most critical systems for our customers. Our fast-growing roster of government customers relies on us to deliver advanced security solutions, and we’re looking for a Senior Vulnerability Researcher to help us continue pushing boundaries. If you’re passionate about vulnerability research that can make a tangible impact on national security, we want you on our team.
This role requires regular on-site support at the Linthicum, Maryland customer site or our headquarters in Herndon VA
What you will do:
- Identify vulnerabilities and potential attacks across hardware, software, procedures, logistics, and physical security of systems
- Develop proof of concept (PoC) code for identified vulnerabilities
- Reverse-engineer targeted embedded systems to identify vulnerabilities
- Review source code looking for risks and vulnerabilities
- Analyze the effects of vulnerabilities on mission outcomes and operational effectiveness.
- Compare system attack techniques and propose operationally effective countermeasures
- Produce reports, briefings, and perspectives on actual and potential attacks
- Mentor junior engineers and analysts, reviewing technical approaches and guiding research methodology
What you will need (Basic Qualifications):
- Bachelor’s degree and 5 years of relevant experience, OR Associate’s degree and 7 years of relevant experience.
- Relevant experience: computer/information systems design/development, programming, information/cyber/network security, reverse-engineering, vulnerability analysis, penetration testing, computer forensics, information assurance, or systems engineering
- Proficiency in C/C++, Python, and at least one ISA (e.g. x86/ARM/MIPS)
- Proficiency in Linux command-line environments
- Experience using a decompiler such as IDA Pro, Binary Ninja, or Ghidra
- Experience using vulnerability research tools such as emulators or fuzzers
- Experience using a software debugger such as GDB or WinDbg
Nice If You Have (Preferred):
- Experience producing technical briefings for operational stakeholders
- Experience using a hardware debugger
- Experience with UART, SPI, I2C
- Experience with common secure communications such as TLS or SSHÂ
- Familiarity with embedded firmware, RTOS, or networked systems
- Familiarity with high-side environments
Security Clearance:
- Active TS/SCI clearance required (Polygraph preferred)
The anticipated base salary range for this position is $165,000–$200,000 annually. This range reflects the Company's good-faith estimate at the time of posting. Final compensation will be determined based on a variety of factors, including the scope and level of the role, relevant experience, technical expertise, education, and other job-related qualifications.
GrammaTech offers a comprehensive total rewards package designed to support the health, well-being, and financial security of our employees. Benefits include medical, dental, and vision insurance; short- and long-term disability coverage; life insurance; and a 401(k) retirement plan with company contributions. Employees are also eligible for paid holidays, paid time off (PTO), sick and personal leave, annual merit increases, and performance-based bonus opportunities.
GrammaTech, Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status. GrammaTech is committed to providing reasonable accommodations to qualified individuals with disabilities throughout the application and hiring process. Applicants requiring accommodation should contact Human Resources.
Learn more about this Employer on their Career Site
