430,009open jobs
14,850companies
61,589added this week
Browse all
Salary
$142k – $250k per year (Estimated)
Location
Remote (United States)
Seniority
Senior
Overview
Company
Impact
Profile match
2026 1H State of Exploitation Report is live Learn More Company Check out our blog, press release, and more. Blog All the latest VulnCheck news, straight from the team News and Awards VulnCheck press coverage and awards.

Sr. Vulnerability Researcher (US)

About VulnCheck

Exploitation prevention is only as strong as the intelligence driving those efforts, and most of the industry is still running on intelligence that lacks exploit context. VulnCheck, The Exploit Intelligence Company, delivers structured exploit intelligence on what is actively weaponized in the wild, purpose-built for the data lakes, ETL pipelines, automation, and AI and LLM workflows your infrastructure already runs on, raising the capability of everything it powers.

About the Role

We’re looking for a Senior Vulnerability Researcher to join our agentic vulnerability discovery team. This role sits within our Initial Access Intelligence group, which delivers exploits, detections, and other artifacts designed for active cyber defense. You'll work with a seasoned team of hackers and threat researchers to find and weaponize new vulnerabilities across a range of operating systems, platforms, and devices - before adversaries do. 

You'll drive original research from exposure analysis and reverse engineering through vulnerability discovery and weaponized exploit development. You'll also help push the state of the art in how VulnCheck finds bugs by applying novel agentic approaches to vulnerability discovery and exploit creation. This is a 100% remote role based in the United States. 

Why Join VulnCheck?

VulnCheck stands behind its mission to influence how organizations worldwide understand, assess, and remediate security vulnerabilities - and to deliver intelligence-based solutions that change the world.

You'll be joining a collaborative, supportive environment that values intellectual curiosity, technical mastery, and personal growth. (And more, below!)

  • Leverage your expertise: Work on cutting-edge threat intelligence initiatives that matter, alongside the top domain experts in the field.
  • Shape the industry: Influence how vulnerabilities are classified, scored, mapped, and remediated at scale for enterprise customers and for the entire cybersecurity industry.
  • Grow your impact: Collaborate with global partners, lead high-visibility research, and drive standards across the security community.
  • Innovate and explore: Conduct original research and develop tooling - including agentic and automated approaches - for finding and understanding new vulnerabilities.

What You'll Do

  • Conduct vulnerability research to identify net-new vulnerabilities across a range of operating systems, platforms, and devices
  • Reverse engineer a variety of firmware and software
  • Author original exploits, network rules (Suricata / Snort), and other artifacts (e.g., Docker containers, version scanners, ASM queries) to accompany new vulnerability finds
  • Apply and expand agentic approaches to scale vulnerability discovery and exploit development

What You'll Bring

  • 5+ years of full-time vulnerability research experience, including experience targeting networking device firmware, embedded Linux/RTOS-based systems, and/or network protocols
  • Demonstrable experience with agentic approaches to vulnerability discovery and exploit development
  • Experience developing original (weaponized) exploit code 
  • Comfort acquiring, unpacking, and analyzing target firmware and appliances, including reasoning about network protocols and unauthenticated attack surface
  • Familiarity with embedded architectures (MIPS, ARM) and firmware extraction/unpacking (e.g., binwalk).
  • Experience with dynamic analysis and debugging on embedded/emulated targets (e.g., QEMU)
  • Working knowledge of common networking protocols (TCP/IP, routing protocols, VPN protocols such as IPsec/SSL-VPN, SNMP, etc.).
  • Strong reverse engineering skills, including static and dynamic analysis of compiled binaries and firmware (VulnCheck uses Ghidra for reversing)
  • Strong command of memory corruption and other vulnerability classes (e.g., stack and heap overflows, use-after-free, type confusion, integer errors, command and path injection, authentication and logic flaws)
  • Solid working knowledge of C/C++ and at least one scripting language (e.g., Python)
  • Experience working on technical projects remotely, alone, and on small teams.

Preferred Qualifications

  • Prior cybersecurity work experience (at a vendor or in government)
  • A track record of discovering new vulnerabilities (e.g., CVEs, advisories, exploits, or published research)
  • Able to share example research or exploit code written

IMPORTANT NOTE: This position may involve access to technology subject to U.S. export control regulations. Employment is contingent upon the company's ability to authorize access under applicable export control, sanctions, and any other applicable legal or contractual requirements. The company does not guarantee and is under no obligation to seek such authorization if it would be necessary.

What We Offer

We believe people do their best work when they feel supported, trusted, and valued. VulnCheck offers benefits designed to meet a wide range of needs and lifestyles, tailored to your country of employment:

  • Generous, flexible time off
  • Retirement/pension plan contributions (e.g., 401k with match in the US; local pension schemes elsewhere)
  • Comprehensive healthcare coverage
  • Generous paid parental leave
  • Remote-friendly environment with flexibility
  • Support for home office costs (phone & internet)

Specific benefit details vary by country and are confirmed during the offer process.

Why Join Us

Built on over two decades of cybersecurity experience, our team of experts understands the intricacies of vulnerabilities, their exploitation in the wild, and how to leverage this data to build more effective cybersecurity products that produce better outcomes for organizations.

VulnCheck gives organizations a tactical advantage by providing best-in-class exploit & vulnerability intelligence information. We have a sense of duty to protect the critical infrastructure we rely on including medical devices, power grids and telecommunication networks. We were founded in 2021 in Lexington, Massachusetts.

VulnCheck has a transparent, collaborative, and supportive culture - we are looking for people who have a growth mindset, are curious and innovative. Our team is smart, but humble, hardworking, and supportive.

VulnCheck is proud to be an Equal Employer Opportunity employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. VulnCheck is committed to working with and providing reasonable accommodations to applicants with physical and mental disabilities. Even if your experience doesn't perfectly align with the job description, we encourage you to apply-we value potential just as much as a perfect resume.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
430,009 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$19k – $54k per year (Estimated) • Remote/Hybrid • Full-Time • Bachelor's Degree • Budapest
Python
JavaScript
C#
DevOps
Azure DevOps
GitHub Actions
Azure
CI/CD
Jenkins
Git
GitHub
QA
Selenium
Cypress
Playwright
Postman
Apply
$31k – $74k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Bengaluru
Python
JavaScript
SQL
Python
Flask
Django
Databases
PostgreSQL
Snowflake
MS SQL
AI/ML
Copilot
LangChain
Airflow
AWS Bedrock
NumPy
LLM
RAG
Frontend
AG Grid
DevOps
CI/CD
Git
AWS
AWS Lambda
Amazon EC2
GitHub
Amazon S3
Analytics
Power BI
Plotly
ETL/ELT
Management
Confluence
Jira
Microsoft Teams
Apply
$52k – $129k per year (Estimated) • Equity • Remote/Hybrid • Full-Time • London • Leeds
Python
SQL
Apply
In office • 8+ years exp • Bachelor's Degree
Python
SQL
Databases
Snowflake
Analytics
Power BI
Apply
$56k – $120k per year • In office • Full-Time • 3+ years exp • Toronto
Python
DevOps
Rest API
Apply
$145k – $252k per year (Estimated) • Remote • Full-Time • 8+ years exp • Boston
AI/ML
LLM
Analytics
ETL/ELT
Apply
$112k – $230k per year (Estimated) • Remote • Full-Time • 5+ years exp • Boston
Python
AI/ML
LLM
Analytics
ETL/ELT
Apply
$106k – $214k per year (Estimated) • Remote • Full-Time • 5+ years exp • Tel Aviv
Python
Assembly
AI/ML
LLM
Analytics
ETL/ELT
Apply
$122k – $294k per year (Estimated) • Remote • Full-Time • 5+ years exp • Tel Aviv
Assembly
AI/ML
LLM
Analytics
ETL/ELT
Marketing
Salesforce
Apply
$121k – $214k per year (Estimated) • Remote • Full-Time • 5+ years exp • Austin
Python
AI/ML
LLM
DevOps
Terraform
CloudFormation
Datadog
Prometheus
CI/CD
AWS
Docker
Kubernetes
Grafana
Cybersecurity
CVE
KEV
Analytics
ETL/ELT
Apply
See all jobs
This is one of many
430,009 more open roles from verified company boards, updated every day.