Security Researcher
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
Position Summary
As a member of the Security Research team, you will imagine weaknesses in multiple types of systems and then find, demonstrate/document, and exploit those weaknesses. You will be joining a team of mature and extremely competent Security Researchers to breakdown and fully understand how a host of different systems function. You will need to leverage extensive experience performing static and dynamic analysis and must be familiar with multiple classes of vulnerabilities. Additionally, you must be extremely comfortable communicating with team members, technical partners, and non-technical partners alike. The ideal candidate will be comfortable and confident operating at the early phases of a vulnerability research project and have the mettle to see the project through to multiple phases and iterations.
Responsibilities
- Perform vulnerability research and reverse engineering for customer tasks
- Perform static and dynamic analysis by applying research tools such as disassemblers, debuggers, and fuzzers
- Perform exploit development leveraging discovered vulnerabilities
- Communicate security research findings internally and, when and where appropriate, externally Mentor fellow security researchers
Minimum Qualifications
- Must be able to obtain and maintain a TS/SCI security clearance (note, only US Citizens are eligible for security clearances)
- Bachelor's degree in Computer Engineering, Computer Science, Software Engineering, or a related technical discipline and 11 years of professional experience
- Experience participating in CTFs, hackathons, or other cyber competitions
- Experience with Ghidra, Binary Ninja, IDA or other reverse engineering/disassembler tools
- Experience working in Linux fundamentals (understanding sockets, file descriptors, networking, iptables, file systems, kernel, etc.)
- Ability to read and write C and assembly languages as needed (ARM, MIPS, x86_64)
- Programming fundamentals; particularly with networking, data structures, and data models
- Understanding of exploitation techniques such as leveraging arbitrary read-write primitives, shellcoding, and return-oriented programming / jump-oriented programming
- Proven track record of exploit creation targeting Android operating systems and Chrome web browsers
Preferred Experience
- Currently possess a Top Secret security clearance
- OS and kernel reverse engineering
- Understanding of fuzzers such as AFL++ or libfuzzer
- Understanding of common exploit mitigation mechanisms such as SELinux, Seccomp, ASLR, and CFI
- Strong understanding of dynamic analysis with gdb/gdbserver and similar tools
- Basic understanding of processor tool chains and the Android NDK
- Understanding of emulation using Qemu or Unicorn for running code in a non-native environment
- Experience identifying 0-days and vulnerabilities
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at Clarity Innovations
Explore Top Companies in this Space
Voyager
Aerospace & Defense / Space Tech
Continuity Global Solutions
Defense / Space / Security
Ursa Major
Aerospace & Defense / Space Technology / Advanced Manufacturing
MetroStar
Information Technology / Government Administration / Defense & Space
Clarity Innovations
View Company ProfileClarity Innovations is a mission-first software and data engineering powerhouse fundamentally dedicated to supporting the Department of Defense (DoD), the Intelligence Community (IC), and various Federal Agencies. Headquartered in Columbia, Maryland, the company serves as a vanguard partner in national security, aggressively modernizing defense infrastructure. Under the hood, Clarity specializes in transforming highly complex legacy ecosystems into secure, agile environments through advanced DevSecOps, CI/CD pipelines, and robust Big Data architecture. They actively pave the way for cyberspace operations and information warfare by ensuring critical data is consumable and actionable for both human operators and Non-Person Entities (NPEs). Their primary target audience spans federal defense organizations, military branches, and intelligence agencies that desperately need to achieve cyber dominance and turn massive data streams into real-time, mission-critical intelligence. What sets Clarity Innovations apart in the highly restricted GovTech and defense contracting sector is its unapologetic "badgeless" approach—prioritizing seamless collaboration, human-centered design, and rapid deployment of capabilities over corporate logos, thereby directly empowering the warfighter and ensuring national security in an evolving digital landscape.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.
