Cyber Vulnerability Researcher
Job description
THIS POSITION REQUIRES AN ACTIVE US GOVERNMENT SECURITY CLEARANCE. IF YOU DO NOT HAVE A CLEARANCE, PLEASE DO NOT APPLY.
Cyber Vulnerability Researcher
SG2 Recruiting has partnered with Lumbee Holdings to spearhead the search for a visionary Cyber Vulnerability Researcher . This is a pivotal opportunity to join a dynamic team and directly influence the company’s next phase of growth. If you are a strategic thinker ready to make a tangible impact, we want to hear from you.
Company Overview: At Lumbee Holdings, we deliver mission-critical logistical, technical, and analytical support to empower strategic government and defense operations. Our culture is built on continuous improvement, operational integrity, and dedicated service to key defense stakeholders. When you join our team, you become part of a collaborative environment where your expertise directly supports military readiness and system efficiency.
Your Role: As a Cyber Vulnerability Researcher, you will deliver advanced vulnerability research and low-level exploit development capability in support of the MCTSSA Cyber Branch’s adversarial testing mission at Camp Pendleton, CA. Your core purpose is to extend the team’s offensive depth beyond tool-based penetration testing into original vulnerability discovery, binary analysis, and exploitation of embedded systems, real-time operating systems (RTOS), and custom platform architectures. Working in close coordination with vulnerability assessment analysts and penetration testers, you will translate research-derived findings into actionable assessment products and technically defensible remediation recommendations for Marine Corps Program Offices.
What You Will Be Doing
- Conduct Original Vulnerability Research: Perform static and dynamic analysis using tools like Ghidra, IDA Pro, WinDbg, OllyDbg, and gdb to identify exploitable weaknesses in Marine Corps software, firmware, and embedded platforms.
- Execute Fuzzing & Exploitation: Develop and execute fuzz testing campaigns to discover zero-day vulnerabilities, and create proof-of-concept (PoC) exploits in isolated research environments to validate mission impact.
- Analyze Low-Level Assembly Code: Examine assembly architectures (x86, x64, ARM, MIPS, PowerPC) to identify memory corruption, logic flaws, and bypass strategies for DEP, ASLR, and stack canaries.
- Assess Embedded & RTOS Platforms: Research weapons systems, C5ISR platforms, embedded systems, and real-time operating systems (VxWorks, RTOSs, Android, Linux, Windows) that commercial COTS scanners cannot evaluate.
- Analyze Code & Write Reports: Conduct static/dynamic source code analysis to identify CWEs, produce Code Review Reports, and deliver summary Security Posture Assessments to guide program office decision-making.
- Automate Research Workflows: Utilize Python, Perl, Ruby, or C/C++ to build custom scripts and tools that accelerate research discovery cycles and improve methodology repeatability.
- Publish Research Findings: Synthesize research into Vulnerability Survey Reports, technical briefings, attack path analyses, and mitigation strategies compliant with Security Classification Guides.
What You Will Need
Must-Haves
- Security Clearance: Active DoD Secret Security Clearance (ability to obtain and maintain Top Secret preferred).
- Tooling Expertise: At least five (5) years of hands-on experience using Ghidra for vulnerability research, binary analysis, and reverse engineering.
- Programming & Debugging: Proficiency in C or C++, scripting languages (Python, Perl, or Ruby), assembly languages (x86, x64, ARM, MIPS, PowerPC), and debuggers (gdb, WinDbg, OllyDbg).
- System & Protocol Knowledge: Experience with PC/embedded system architectures, OS internals, network protocols, fuzzing techniques, and common mitigation techniques (DEP, ASLR, stack canaries).
- Location/On-Site: Willingness and ability to work 100% on-site at Camp Pendleton, CA.
Nice-to-Haves
- Certifications: Advanced software assurance credentials such as OSED, OSEE, GREM, or equivalent.
- Advanced Research Skills: Experience developing IDA Pro plugins/scripts, hardware/FPGA debugging, or 10+ years of low-level reverse engineering and systems programming experience.
- Competitions & Tradecraft: Active participation in Capture The Flag (CTF) or software hacking competitions.
Military & Veteran Equivalents: We strongly encourage transitioning service members and veterans
first seen 2026-08-21 01:30:01 · last verified 2026-08-24 13:30:01
pentestcareers.com // breach the job market