Senior Vulnerability Researcher

February 24, 2017 - Austin, TX or Columbia, MD

If you enjoy vulnerability research, crash analysis, reverse engineering, and researching new techniques and writing tools to automate these tasks, this job is for you. This Senior Research Developer position with Cisco Talos VulnDev Team (formerly Sourcefire VRT) is available to remote and international workers.

Position Overview

Security research including development of tools for vulnerability discovery, analysis, and mitigation. Development of fuzzers and static analysis tools to identify new vulnerabilities in software. Development of static and run-time analysis tools to determine the root cause and input conditions related to a vulnerability. Vulnerability triage and proof of concept exploit development to support the creation of detection content. Additional responsibilities include helping users and other analysts with setup, installation, and usage of the vulnerability research tools and demonstrating leadership in the security community through publishing open source tools, papers, presentations, and blog posts.

Essential Duties and Responsibilities

  • Perform software security analysis to discover new vulnerabilities.
  • Create tools for the discovery and triage of vulnerabilities.
  • Write detailed technical advisories on new vulnerabilities.
  • Develop proof of concept exploits for testing IPS and IDS effectiveness.
  • Perform patch analysis to find and trigger vulnerabilities.
  • Reverse engineer binary applications, protocols and formats.
  • Demonstrate leadership with the security community.

Education and Work Experience

  • Bachelor’s degree in CS, CE, or Mathematics preferred.
  • Demonstrable experience with vulnerability research required.

Specialized Knowledge and Skills

  • Proficient in C/C++, python and x86 assembler.
  • Knowledge of Windows and Linux System API and ABI.
  • Knowledge of common file format and network protocol structures.
  • Experience binary auditing and reverse engineering.
  • Experience with IDA Pro and plugin development.
  • Experience with compiler plugins or program analysis algorithms.
  • Experience with runtime binary instrumentation tools such as PIN, DynamoRIO, etc
  • Exceptional analytical skills and problem solving skills.
  • Good organization, decision making, and verbal and written communication skills.
  • Ability to work independently with minimum supervision and to take on additional tasks as required.
  • Ability to work with small teams to solve complex problems.
  • A drive to succeed and a passion to solve difficult problems.

Work Conditions

  • Employee will telecommute from home office or work from Columbia, MD or Austin, TX
  • Works closely with software reverse engineers and research analysts to understand their needs and develop tools to assist with the creation of detection content.
  • Moderate to high levels of stress may occur at times.
  • Fast paced and rapidly changing environment.
  • Extremely talented and experienced team members and mentors.