远程工作雷达

高级漏洞研究员(美国)

Sr. Vulnerability Researcher (US)

开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差
公司VulnCheck
薪资未公开
工作地点United States
地域资格限定地区(需当地身份)
时区要求与中国几乎无重叠,需长期倒时差
用工类型permanent
发布时间7 天前
数据来源4dayweek.io
前往 4dayweek.io 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:与中国几乎无重叠,需长期倒时差。

## 高级漏洞研究人员(美国)

**关于VulnCheck**

防御攻击的强度取决于驱动这些努力的情报,而大多数行业仍使用缺乏利用上下文的情报。VulnCheck,一家专注于漏洞情报的公司,提供结构化的漏洞情报,展示当前在野外被武器化的漏洞,专为您的基础设施已运行的数据湖、ETL流水线、自动化以及AI和LLM工作流而设计,提升其支持的所有系统的功能。

**职位描述**

我们正在寻找一位高级漏洞研究人员加入我们的智能漏洞发现团队。该职位属于我们的初始访问情报小组,负责提供用于主动网络防御的漏洞、检测和其他工件。您将与经验丰富的黑客和威胁研究人员合作,在对手之前发现并利用各种操作系统、平台和设备上的新漏洞。

您将从暴露分析和逆向工程开始,推动原创研究,完成漏洞发现和武器化漏洞开发。您还将通过应用新颖的智能方法来推动VulnCheck发现漏洞和创建漏洞的技术前沿。这是一份100%远程的工作,位于美国。

**为什么加入VulnCheck?**

VulnCheck致力于影响全球组织对安全漏洞的理解、评估和修复方式,并提供基于情报的解决方案,改变世界。

您将加入一个协作、支持的环境,重视求知欲、技术精湛和个人成长。(更多内容如下!)

- **发挥您的专长:** 与领域内的顶级专家一起,参与具有重要意义的前沿威胁情报项目。
- **塑造行业:** 影响企业客户和整个网络安全行业对漏洞的分类、评分、映射和修复方式。
- **扩大影响力:** 与全球合作伙伴合作,领导高可见度的研究,并推动安全社区的标准。
- **创新与探索:** 进行原创研究并开发工具——包括智能和自动化方法——用于发现和理解新的漏洞。

**您将从事的工作**

- 开展漏洞研究,识别各种操作系统的全新漏洞

查看英文原文

## Sr. Vulnerability Researcher (US)

**About VulnCheck**

Exploitation prevention is only as strong as the intelligence driving those efforts, and most of the industry is still running on intelligence that lacks exploit context. VulnCheck, The Exploit Intelligence Company, delivers structured exploit intelligence on what is actively weaponized in the wild, purpose-built for the data lakes, ETL pipelines, automation, and AI and LLM workflows your infrastructure already runs on, raising the capability of everything it powers.

**About the Role**

We’re looking for a Senior Vulnerability Researcher to join our agentic vulnerability discovery team. This role sits within our Initial Access Intelligence group, which delivers exploits, detections, and other artifacts designed for active cyber defense. You'll work with a seasoned team of hackers and threat researchers to find and weaponize new vulnerabilities across a range of operating systems, platforms, and devices — before adversaries do.

You'll drive original research from exposure analysis and reverse engineering through vulnerability discovery and weaponized exploit development. You'll also help push the state of the art in how VulnCheck finds bugs by applying novel agentic approaches to vulnerability discovery and exploit creation. This is a 100% remote role based in the United States.

**Why Join VulnCheck?**

VulnCheck stands behind its mission to influence how organizations worldwide understand, assess, and remediate security vulnerabilities — and to deliver intelligence-based solutions that change the world.

You'll be joining a collaborative, supportive environment that values intellectual curiosity, technical mastery, and personal growth. (And more, below!)

- **Leverage your expertise:** Work on cutting-edge threat intelligence initiatives that matter, alongside the top domain experts in the field.
- **Shape the industry:** Influence how vulnerabilities are classified, scored, mapped, and remediated at scale for enterprise customers and for the entire cybersecurity industry.
- **Grow your impact:** Collaborate with global partners, lead high-visibility research, and drive standards across the security community.
- **Innovate and explore:** Conduct original research and develop tooling — including agentic and automated approaches — for finding and understanding new vulnerabilities.

**What You'll Do**

- Conduct vulnerability research to identify net-new vulnerabilities across a range of operating systems, platforms, and devices
- Reverse engineer a variety of firmware and software
- Author original exploits, network rules (Suricata / Snort), and other artifacts (e.g., Docker containers, version scanners, ASM queries) to accompany new vulnerability finds
- Apply and expand agentic approaches to scale vulnerability discovery and exploit development

**What You'll Bring**

- 5+ years of full-time vulnerability research experience, including experience targeting networking device firmware, embedded Linux/RTOS-based systems, and/or network protocols
- Demonstrable experience with agentic approaches to vulnerability discovery and exploit development
- Experience developing original (weaponized) exploit code
- Comfort acquiring, unpacking, and analyzing target firmware and appliances, including reasoning about network protocols and unauthenticated attack surface
- Familiarity with embedded architectures (MIPS, ARM) and firmware extraction/unpacking (e.g., binwalk).
- Experience with dynamic analysis and debugging on embedded/emulated targets (e.g., QEMU)
- Working knowledge of common networking protocols (TCP/IP, routing protocols, VPN protocols such as IPsec/SSL-VPN, SNMP, etc.).
- Strong reverse engineering skills, including static and dynamic analysis of compiled binaries and firmware (VulnCheck uses Ghidra for reversing)
- Strong command of memory corruption and other vulnerability classes (e.g., stack and heap overflows, use-after-free, type confusion, integer errors, command and path injection, authentication and logic flaws)
- Solid working knowledge of C/C++ and at least one scripting language (e.g., Python)
- Experience working on technical projects remotely, alone, and on small teams.

**Preferred Qualifications**

- Prior cybersecurity work experience (at a vendor or in government)
- A track record of discovering new vulnerabilities (e.g., CVEs, advisories, exploits, or published research)
- Able to share example research or exploit code written

**IMPORTANT NOTE:** This position may involve access to technology subject to U.S. export control regulations. Employment is contingent upon the company's ability to authorize access under applicable export control, sanctions, and any other applicable legal or contractual requirements. The company does not guarantee and is under no obligation to seek such authorization if it would be necessary.

### **What We Offer**

We believe people do their best work when they feel supported, trusted, and valued. VulnCheck offers benefits designed to meet a wide range of needs and lifestyles, tailored to your country of employment:

- Generous, flexible time off
- Retirement/pension plan contributions (e.g., 401k with match in the US; local pension schemes elsewhere)
- Comprehensive healthcare coverage
- Generous paid parental leave
- Remote-friendly environment with flexibility
- Support for home office costs (phone & internet)

_Specific benefit details vary by country and are confirmed during the offer process._

**Why Join Us**

Built on over two decades of cybersecurity experience, our team of experts understands the intricacies of vulnerabilities, their exploitation in the wild, and how to leverage this data to build more effective cybersecurity products that produce better outcomes for organizations.

VulnCheck gives organizations a tactical advantage by providing best-in-class exploit & vulnerability intelligence information. We have a sense of duty to protect the critical infrastructure we rely on including medical devices, power grids and telecommunication networks. We were founded in 2021 in Lexington, Massachusetts.

VulnCheck has a transparent, collaborative, and supportive culture — we are looking for people who have a growth mindset, are curious and innovative. Our team is smart, but humble, hardworking, and supportive.

VulnCheck is proud to be an Equal Employer Opportunity employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. VulnCheck is committed to working with and providing reasonable accommodations to applicants with physical and mental disabilities. Even if your experience doesn't perfectly align with the job description, we encourage you to apply—we value potential just as much as a perfect resume.

本页面信息整理自 4dayweek.io,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

销售赋能经理

VulnCheckUnited Statespermanent今天
市场运营限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

销售工程师

VulnCheckIsraelpermanent2026-08-04
开发工程市场运营限定地区(需当地身份)

销售总监

VulnCheckIsraelpermanent2026-08-04
市场运营限定地区(需当地身份)

← 返回全部职位