Senior Vulnerability Engineer
Anduril Industries · Boston, Massachusetts, United States; Costa Mesa, California, United States; Washington, District of Columbia, United States
About this role
## Senior Vulnerability Engineer **About the Team** Anduril Cyber is hiring a Vulnerability Engineer to discover novel vulnerabilities in hardware and software systems and turn that research into rigorous technical artifacts. The role is focused on original vulnerability discovery across embedded systems, firmware, applications, protocols, hardware/software boundaries, and system integrations. **About the Job** • Find novel vulnerabilities in software, firmware, embedded systems, protocols, update paths, device interfaces, and hardware/software integration boundaries • Design and execute vulnerability research plans combining code review, reverse engineering, fuzzing, emulation, dynamic instrumentation, hardware analysis, and adversarial testing • Build custom fuzzers, harnesses, emulators, instrumentation, triage workflows, and proof-of-concept tooling • Analyze root cause, exploitability, operational impact, and mitigation options for discovered vulnerabilities • Partner with reverse engineers, product security engineers, embedded software engineers, hardware engineers, and systems teams • Write clear technical reports with evidence, reproduction steps, exploitability assessment, impact, and mitigations • Design hardware-in-the-loop vulnerability experiments combining software exploitation, protocol analysis, and lab instrumentation • Develop tooling to automate experiment orchestration, device interaction, data collection, and vulnerability reproduction **Required Qualifications** • Strong experience discovering vulnerabilities in firmware, applications, network services, embedded Linux systems, drivers, protocols, or IoT devices • Proficiency with Python, C, C++, Rust, or Go for vulnerability research and tooling • Experience with fuzzing, harness development, crash triage, exploitability analysis, source-code review, binary analysis, or dynamic instrumentation • Ability to reason about memory corruption, logic flaws, authentication failures, unsafe parsing, concurrency issues, and trust-boundary failures • Hands-on familiarity with Linux, embedded systems, networking, debugging, and security research tooling • Clear communication of vulnerability impact, reproduction steps, and mitigation options • Demonstrated bias toward practical, mission-enabling security outcomes • Eligible to obtain and maintain a U.S. security clearance • Experience evaluating vulnerabilities across embedded protection mechanisms (secure boot, firmware updates, key storage, memory protection) • Comfort with lab-based vulnerability validation using hardware interfaces, protocol analyzers, and instrumented test setups **Preferred Qualifications** • Experience with boot chains, firmware update mechanisms, device identity systems, cryptographic integrations, or anti-tamper mechanisms • Advanced vulnerability research techniques (coverage-guided fuzzing, symbolic execution, differential testing, fault injection, hardware-in-the-loop testing) • Familiarity with Ghidra, IDA Pro, Binary Ninja, QEMU, Frida, gdb/lldb, or comparable tools • Background in embedded, aerospace, robotic, RF, or cyber-physical systems • Track record of high-quality vulnerability research artifacts, tooling, writeups, or CVEs • Experience with side-channel analysis, fault injection, or hardware-assisted fuzzing • Experience with RF protocols, cryptographic protocol analysis, FPGA/SoC security, or board-level assessment • Demonstrated technical leadership or mentorship of complex vulnerab
Listing freshness
CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.