Vulnerability Researcher

2 weeks ago


Meade, United States ARSIEM Corporation Full time

About ARSIEM Corporation

At ARSIEM Corporation we are committed to fostering a proven and trusted partnership with our government clients. We provide support to multiple agencies across the United States Government. ARSIEM has an experienced workforce of qualified professionals committed to providing the best possible support.

As demand increases, ARSIEM continues to provide reliable and cutting-edge technical solutions at the best value to our clients. That means a career packed with opportunities to grow and the ability to have an impact on every client you work with.

ARSIEM is looking for Vulnerability Researchers, Levels Candidates must have experience conduction r everse engineering of hardware, software applications, and operating systems to determine functionality, code structure, and circuit design for use in the discovery of initial access capabilities. Candidates will develop proof-of-concept exploits against research targets, prototypes, and hands-on demonstrations of vulnerability analysis results. This position will support one of our Government clients in Ft. Meade, MD.

Level 1 Vulnerability Researcher Responsibilities

+ Provide engineering and vulnerability research results related to hardware components, software applications, and operating systems to determine functionality, code structure, and system design for use in the discovery of initial access capabilities.

+ Actively debug software and troubleshoot issues with software crashes and programmatic flow

+ Provide written reports, proof-of-concept code, prototypes, and hands-on demonstrations of reverse engineering and vulnerability analysis results, and

+ Provide/author and participate in technical presentations on assigned projects

Level 1 Vulnerability Researcher Qualifications

+ Bachelor's Degree in Computer Science or related field, or minimum two (2) years experience in computer science, information systems, or network engineering

+ Minimum two (2) years experience programming in Assembly, C, C#, C++, Perl, or Python.

+ Minimum two (2) years of demonstrated experience in either hardware or software reverse engineering.

Level 2 Vulnerability Researcher Responsibilities

+ Provide engineering and vulnerability research results related to hardware components, software applications, and operating systems to determine functionality, code structure, and system design for use in the discovery of initial access capabilities.

+ Actively debug software and troubleshoot issues with software crashes and programmatic flow

+ Ability to perform source code analysis in an effort to discover software flaws, and

+ provide/author documentation on the impact and severity of the flaw

+ Ability to develop proof-of-concept exploits against research targets, prototypes, and hands-on demonstrations of vulnerability analysis results

+ Provide/author and participate in technical presentations on assigned projects

+ Lead reverse engineering and vulnerability research of hardware components, software applications, and operating systems to determine functionality, code structure, and circuit design for the use in the discovery of initial access capabilities

Level 2 Vulnerability Researcher Qualifications

+ Meets all qualifications of a CNO Vulnerability Researcher/Analyst I, but has the following increased experience and skill levels

+ Minimum four (4) years experience programming in Assembly, C, C#, C++, Perl, or Python for a production environment

+ Minimum of five (5) years contiguous experience in computer science, information systems, or network engineering; or Bachelor's Degree in Computer Science or related field plus minimum three (3) years contiguous experience

+ Minimum four (4) years demonstrated experience in either hardware or software reverse engineering

Level 3 Vulnerability Researcher Responsibilities

+ Provide engineering and vulnerability research results related to hardware components, software applications, and operating systems to determine functionality, code structure, and system design for use in the discovery of initial access capabilities.

+ Lead efforts to debug software and troubleshoot issues with software crashes and programmatic flow

+ Ability to perform source code analysis in an effort to discover software flaws, and provide/author documentation on the impact and severity of the flaw

+ Ability to develop robust exploits (advancements beyond initial proof-of-concept such as version coverage, decreased failure rate, handling edge cases, etc.) against research targets, prototypes, and hands-on demonstrations of vulnerability analysis results

+ Edit/Approve and participate in technical presentations on assigned projects

+ Subject Matter Expert and Leader of at least one technology area responsible for reverse engineering and vulnerability analysis of hardware components, software applications, and operating systems to determine functionality, code structure, and circuit design for the use in the discovery of initial access capabilities

Level 3 Vulnerability Researcher Qualifications

+ Meets all qualifications of a CNO Vulnerability Researcher/Analyst II, but has the following increased experience and skill levels

+ Proven results from participation in vulnerability discovery efforts within the last twelve (12) months

+ Demonstrated ability to discover multiple previously unknown vulnerabilities (0-day) across multiple versions of similar technologies.

+ Demonstrated ability to discover multiple previously unknown vulnerabilities (0-day) that achieve reliable remote code execution and/or reliable privilege escalation.

Desired Skills for All Levels

+ Experience programming in Assembly, C, C#, C++, Perl, or Python with a focus on an understanding of system interactions with these libraries vs. production-style environments

+ Use of Unix/Windows system APIs

+ Understanding of virtual function tables in C++

+ Heap allocation strategies and protections

+ Experience with very large software projects a plus

+ Kernel programming experience (WDK / Unix||Linux) a significant plus

+ Hardware/Software reverse engineering, which often includes the use of tools (e.g., IDA Pro, Ghidra, Binary Ninja) to identify abstract concepts about the code flow of an application.

+ For Hardware reverse engineering, candidates are expected to have performed analysis of embedded devices, focusing primarily on identifying the software stack and points of entry to the hardware (e.g., not interested in FPGA reverse engineering, or other circuit reverse engineering).

+ Candidates who can merge low-level knowledge about the compilation of C/C++ code with a nuanced understanding of system design to identify and exploit common vulnerability patterns. Candidates should be comfortable with, at a minimum, user-mode stack-based buffer overflows, and heap-based exploitation strategies.

Clearance Requirement: This position requires an active TS/SCI with a polygraph. You must be a US Citizen for consideration.

Candidate Referral: Do you know someone who would be GREAT at this role? If you do, ARSIEM has a way for you to earn a bonus through our referral program for persons presenting NEW (not in our resume database) candidates who are successfully placed on one of our projects. The bonus for this position is $10,000, and the referrer is eligible to receive the sum for any applicant we are able to place within 12 months of referral. The bonus is paid after the referred employee reaches 6 months of employment.

ARSIEM is proud to be an Equal Opportunity and Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age, or any other federally protected class.



  • Meade, United States National Security Agency (NSA) Full time

    ResponsibilitiesAre you an emerging or seasoned network professional who wants to work our nation's tough cybersecurity problems? Do you enjoy deeply technical, hands-on work? Do you want to identify vulnerabilities in network infrastructure devices and then figure out how to deal with them? Are you looking to make an impact in cybersecurity and advance your...


  • Fort Meade, United States National Security Agency Full time

    Are you an emerging or seasoned network professional who wants to work our nation's tough cybersecurity problems? Do you enjoy deeply technical, hands-on work? Do you want to identify vulnerabilities in network infrastructure devices and then figure out how to deal with them? Are you looking to make an impact in cybersecurity and advance your career while...

  • Research Scientist

    1 month ago


    Meade, United States National Security Agency (NSA) Full time

    ResponsibilitiesNSA Research Scientists are actively expanding the boundaries of what can be accomplished with artificial intelligence, machine learning, human-machine teaming, software reverse engineering, data science, novel architectures, cyber security, high performance computing, and computational linguistics. Our experts generalize mission problems,...


  • Fort Meade, United States MIT Lincoln Laboratory Full time

    Located onsite in Fort Meade, MD From the MIT Lincoln Laboratory field office in Annapolis Junction, MD, you will be immersed in the missions of key government sponsors.The Cyber System Assessments Group performs software and hardware reverse engineering, vulnerability research and discovery, and system exploitation. We develop and prototype...


  • Ft Meade, United States MIT Lincoln Laboratory Full time

    Located onsite in Fort Meade, MDFrom the MIT Lincoln Laboratory field office in Annapolis Junction, MD, you will be immersed in the missions of key government sponsors.The Cyber System Assessments Group performs software and hardware reverse engineering, vulnerability research and discovery, and system exploitation. We develop and prototype cutting-edge...


  • Meade, United States National Security Agency (NSA) Full time

    ResponsibilitiesAre you driven by a passion to work at the cutting edge of technology? Do you dream to make the impossible possible? The National Security Agency is seeking highly motivated Computer Science and Computer/Electrical Engineering professionals to drive its mission to develop new capabilities, design new approaches, help solve complex problems,...


  • Meade, United States National Security Agency (NSA) Full time

    ResponsibilitiesAre you an emerging or seasoned network professional who wants to work our nation's tough cybersecurity problems? Do you enjoy deeply technical, hands-on work? Do you want to identify vulnerabilities in network infrastructure devices and then figure out how to deal with them? Are you looking to make an impact in cybersecurity and advance your...

  • Intel Analyst

    3 weeks ago


    Fort Meade, United States Dhara Consulting Group Full time

    Today - Top Secret/SCI - Mid Level Career (5+ yrs experience) - $100,000 - $125,000 - No Traveling - Intelligence - Fort Meade, MD** (ON-SITE/OFFICE)** Night shift (Mon-Thu: 9pm - 7am) Primary Responsibilities Collect intelligence on events occurring both internal and external community of interest Enhance Situational Awareness (SA), Situational...

  • Intel Analyst

    2 weeks ago


    Fort Meade, United States Dhara Consulting Group Full time

    Today - Top Secret/SCI - Early Career (2+ yrs experience) - $125,000 - $150,000 - IT - Security - Fort Meade, MD** (ON/OFF-SITE)** Collect intelligence on events occurring both internal and external community of interest Enhance Situational Awareness (SA), Situational Understanding (SU), and identify possible relationships, trends, and adversary TTPs based...


  • Fort Meade, United States Jacobs Full time

    Your Impact:Jacobs is seeking experienced CI Specialists to identify, monitor, and assess foreign intelligence efforts attempting collection of sensitive national security information on U.S. persons, activities and interests, including threats posed by emerging technologies to U.S. operations and interests. The CI Specialist applies understanding of foreign...


  • Fort Meade, United States National Security Agency Full time

    Are you an emerging or seasoned network professional who wants to work our nation's tough cybersecurity problems? Do you enjoy deeply technical, hands-on work? Do you want to identify vulnerabilities in network infrastructure devices and then figure out how to deal with them? Are you looking to make an impact in cybersecurity and advance your career while...


  • Fort Meade, United States National Security Agency Full time

    Job Summary Are you a cyber professional with the drive and expertise to be on the forefront of the cyber fight; tackling NSA's complex mission to defend against cyber threats of today and tomorrow? NSA, the nation's leading cyber agency, has exciting and challenging positions in Cyber Security Engineering and Cyber and TEMPEST vulnerability...


  • Fort Meade, United States IC Defense Full time

    Job DescriptionJob DescriptionDescription:Perform as a CNO analyst leveraging Python and Data Science skills executing on a broad range of mission critical tasks touching every aspect of the development life cycle for new CNO tools or plugins.Conduct research to identify opportunities, conduct vulnerability research and working closely with other analysts...


  • Fort Meade, United States IC Defense Full time

    Job DescriptionJob DescriptionDescription:Perform as a CNO analyst leveraging Python and Data Science skills executing on a broad range of mission critical tasks touching every aspect of the development life cycle for new CNO tools or plugins.Conduct research to identify opportunities, conduct vulnerability research and working closely with other analysts...


  • Fort Meade, United States US National Security AgencyCentral Security Service Full time

    **Duties**: Are you an emerging or seasoned network professional who wants to work our nation's tough cybersecurity problems? Do you enjoy deeply technical, hands-on work? Do you want to identify vulnerabilities in network infrastructure devices and then figure out how to deal with them? Are you looking to make an impact in cybersecurity and advance your...


  • Fort Meade, United States ARSIEM Full time

    ARSIEM is currently looking for a **Firmware-Savvy CNO Developer**. This position will support one of our Government clients in Ft. Meade, MD. **Responsibilities**: - Work as a SAS member for Firmware development. - Support the development of new and existing capabilities. **Minimum Qualifications**: - 5+ years of software development experience with a...


  • Meade, United States National Security Agency (NSA) Full time

    ResponsibilitiesThe professionals at the National Security Agency (NSA) have one common goal: to protect our nation. The mission requires a strong offense and a steadfast defense. The offense collects, processes and disseminates intelligence information derived from foreign signals for intelligence and counterintelligence purposes. The defense prevents...


  • Fort Meade, United States Belay Technologies Full time

    Belay Technologies has been voted Baltimore Business Journal's (BBJ) Best Places to Work 2019, runner up in 2020 and a finalist in 2021! Belay Technologies is seeking a Computer Network Exploitation Analyst (CNEA3) to join our intel team. You will be supporting ATPG-SI performing as a CNEA3 analyst executing on a broad range of mission critical tasks that...


  • Fort Meade, United States Lockheed Martin Full time

    Description:Lockheed Martin is seeking a Classified Cyber Solutions Developer in the in the Fort Meade, MD area. Essential duties include leading advanced research projects in highly specialized areas of computer network operations (CNO); planning, coordinating, and executing the development of multiple projects that impact the organization’s portfolio and...


  • Fort Meade, United States Belay Technologies Full time

    Job DescriptionJob DescriptionBelay Technologies has been voted Baltimore Business Journal's (BBJ) Best Places to Work 2019, runner up in 2020 and a finalist in 2021! Belay Technologies is seeking a Computer Network Exploitation Analyst (CNEA3) to join our intel team. You will be supporting ATPG-SI performing as a CNEA3 analyst executing on a broad...