VulnCheck

Outpace Adversaries

Senior Exploit Developer

Security EngineerSecurity EngineerFull TimeRemoteTeam 11-50Since 2021H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

3 days ago

Salary

Not specified

Reverse EngineeringExploit DevelopmentGoGitSuricataSnortYARAVulnerability ResearchRCE

Job Description

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more.

Role Description

VulnCheck is looking for a Senior Exploit Developer with a background in reverse engineering and exploit development. This role is on our Initial Access Intelligence team, which delivers exploits and related artifacts designed to give VulnCheck customers visibility into exploitation from exposure through execution and detection. You’ll work with a seasoned team of hackers and threat researchers to help global enterprises, governments, and intelligence firms defend against emerging threats and get ahead of the attacker curve.

This is a 100% remote role based in the United States, though we are primarily looking for candidates in Massachusetts, Maryland, and Texas.

What You’ll Do

  • Reverse engineering software to discover the root cause of both zero-day and n-day vulnerabilities
  • Writing original software exploits for initial access vulnerabilities using VulnCheck’s open-source go-exploit framework, including when there are no public PoCs or vulnerability details
  • Implementing detections (such as Suricata & Snort signatures, YARA rules, etc.) that accurately identify initial access vulnerabilities being exploited on the wire
  • Writing Attack Surface Management (ASM) queries (e.g., Shodan, Census, FOFA, & ZoomEye) to find vulnerable systems likely to be targeted
  • Contributing to technical blogs and/or conference talks (optional) on exploit development and attack trends

Qualifications

  • Prior experience with exploit development for RCE / initial access vulnerabilities (that do not require authentication to exploit)
  • Comfort with reverse engineering and patch diffing
  • Experience with Git-based project development
  • Experience working on technical projects remotely, alone, and on small teams

Preferred Qualifications

  • Prior cybersecurity work experience (at a vendor or in government)
  • Ability to share example exploit code written
  • Some experience with programming / software development is helpful
  • Experience writing technical blogs and/or giving conference talks is a big plus

Benefits

  • Competitive salary with employee equity program
  • Health, dental, and vision coverage
  • Unlimited PTO + All federal holidays observed
  • 401(k) program - 100% match on the first 3%, then 50% of the next 3-5% of compensation
  • Short and long-term disability coverage
  • Remote friendly environment with flexibility
  • Expense reimbursement for home internet and phone
  • Ongoing professional development, coaching, and learning resources
  • Opportunities for career advancement within a fast-growing team

Company Description

VulnCheck is transforming vulnerability intelligence by helping security teams act faster and with more confidence. Built on over two decades of cybersecurity experience, our team of experts understands the intricacies of vulnerabilities, their exploitation in the wild, and how to leverage this data to build more effective cybersecurity products that produce better outcomes for organizations.

VulnCheck gives organizations a tactical advantage by providing best-in-class exploit & vulnerability intelligence information. We have a sense of duty to protect the critical infrastructure we rely on including medical devices, power grids and telecommunication networks. We were founded in 2021 in Lexington, Massachusetts.

VulnCheck has a transparent, collaborative, and supportive culture - we are looking for people who have a growth mindset, are curious and innovative. Our team is smart, but humble, hardworking, and supportive.

VulnCheck is proud to be an Equal Employer Opportunity employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. VulnCheck is committed to working with and providing reasonable accommodations to applicants with physical and mental disabilities.

Job Requirements

  • Prior experience with exploit development for RCE / initial access vulnerabilities (that do not require authentication to exploit)
  • Comfort with reverse engineering and patch diffing
  • Experience with Git-based project development
  • Experience working on technical projects remotely, alone, and on small teams
  • Preferred Qualifications
  • Prior cybersecurity work experience (at a vendor or in government)
  • Ability to share example exploit code written
  • Some experience with programming / software development is helpful
  • Experience writing technical blogs and/or giving conference talks is a big plus

Benefits

  • Competitive salary with employee equity program
  • Health, dental, and vision coverage
  • Unlimited PTO + All federal holidays observed
  • 401(k) program - 100% match on the first 3%, then 50% of the next 3-5% of compensation
  • Short and long-term disability coverage
  • Remote friendly environment with flexibility
  • Expense reimbursement for home internet and phone
  • Ongoing professional development, coaching, and learning resources
  • Opportunities for career advancement within a fast-growing team

Related Categories

Related Job Pages

More Security Engineer Jobs

Principal Application Security Engineer – AI & Agentic Systems

CVS Health

Bringing our heart to every moment of your health.

Security Engineer3 days ago
Full TimeRemoteTeam 10,001+Since 1963H1B No Sponsor

This role involves leading the development and enforcement of application and AI security policies, establishing secure design patterns for AI agent frameworks, and serving as the principal subject matter expert for securing AI-enabled applications and agentic system architectures. Responsibilities also include influencing engineering teams, advising senior leadership on AI security strategy, and leading advanced security testing and risk assessments for AI systems.

PythonJavaJavaScriptC#GoAWSAzureGCPDockerKubernetesMicroservicesThreat ModelingVulnerability ManagementLLMRAGCI/CDHIPAANIST
United States
$144K - $288K / year

FedRAMP Information System Security Officer / GRC Manager

IFS

Be your best when it really matters. At the #MomentOfService

Security Engineer3 days ago
Full TimeRemoteTeam 5,001-10,000Since 1983H1B Sponsor

The role involves supporting ongoing FedRAMP authorization processes, including managing SSPs, POA&Ms, and coordinating with 3PAOs, while overseeing compliance with NIST SP 800-53. Responsibilities also include tracking and remediating findings within FedRAMP SLAs and developing security policies and procedures.

United States
$150K - $200K / year

FedRAMP Information System Security Officer / GRC Manager

IFS

Be your best when it really matters. At the #MomentOfService

Security Engineer3 days ago
Full TimeRemoteTeam 5,001-10,000Since 1983H1B Sponsor

The role involves supporting ongoing FedRAMP authorization processes, including managing SSPs, POA&Ms, evidence, and coordinating with 3PAOs, while overseeing compliance with NIST SP 800-53. Responsibilities also include managing continuous monitoring, vulnerabilities, incidents, and tracking findings remediation within FedRAMP SLAs.

United States
$150K - $200K / year

Microsoft Security Architect

Armor Defense Inc

Join Armor if you want to be part of a company that is redefining cybersecurity. Here, you will have the opportunity to shape the future, disrupt the status quo, and be a part of a team that celebrates energy, passion, and fresh thinking. We are not looking for someone who simply fills a role – we want talent who will help us write the next chapter of our growth story. Commitment to Growth: A growth mindset that encourages continuous learning and improvement with adaptability in the face of challenges. Integrity Always: Sustain trust through transparency and honesty in all actions and interactions regardless of circumstances. Empathy In Action: Active understanding, compassion, and support to the needs of others through genuine connection. Immediate Impact: Taking initiative with swift, informed actions to deliver positive outcomes. Follow-Through: Dedication to delivering finished results with attention to quality and detail to achieve the desired outcomes.

Security Engineer3 days ago
ContractRemote

Armor Defense Inc. is seeking a Microsoft Security Architect / Senior Consultant to lead and deliver advanced consulting engagements across the full Microsoft security ecosystem. This role goes beyond a single product area, requiring deep architectural expertise spanning: Microso...

Microsoft DefenderMicrosoft SentinelMicrosoft PurviewMicrosoft EntraConditional AccessAzure Information ProtectionZero Trust ArchitectureSIEMSOARIdentity GovernanceData Loss PreventionCloud SecurityEndpoint SecurityCybersecurity Risk ManagementComplianceGDPRCCPAHIPAAPCI DSS
United States