Vulnerability Researcher

Location

Worldwide

Posted

57 days ago

Salary

0

Seniority

Mid Level

Job Description

Vulnerability Researcher

The Josef Group

Role Description We are seeking a talented Vulnerability Researcher or Exploit Engineer to join our security research team. This role focuses on discovering, analyzing, and demonstrating vulnerabilities in mobile platforms (Android, iOS) and desktop operating systems (Windows). You will contribute to the development of advanced security capabilities while working with cutting-edge tools and techniques in vulnerability research, reverse engineering, and exploitation. Successful candidates will have demonstrable expertise in at least one of our target platforms and a strong foundation in security principles. - Conduct security research on mobile (Android, iOS) and desktop (Windows) platforms to identify novel vulnerabilities and attack surfaces - Develop proof-of-concept exploits and technical demonstrations of discovered vulnerabilities - Perform reverse engineering and binary analysis on platform code and third-party applications - Analyze platform architecture, system libraries, and kernel components to understand security mechanisms - Document findings with technical depth, including vulnerability chain analysis and impact assessment - Contribute to the development of automated tools and frameworks for vulnerability discovery and exploitation - Collaborate with cross-functional teams to understand customer requirements and technical constraints - Stay current with platform updates, security patches, and emerging vulnerability classes Qualifications - Hands-on experience with at least one of the following platforms: Android, iOS, or Windows - Strong understanding of operating system internals (kernel architecture, process management, memory management, IPC mechanisms) - Proficiency in reverse engineering tools and techniques (debuggers, disassemblers, binary instrumentation) - Experience with one or more programming/scripting languages (C, C++, Python, JavaScript, Java, or assembly) - Familiarity with common vulnerability classes and exploitation techniques (memory corruption, logic flaws, permission bypass, etc.) - Ability to communicate technical findings clearly in writing and through presentations - Experience working in a security-conscious environment with proper handling of sensitive vulnerability information - US citizen with ability to obtain government security clearance Requirements - Published security research, public vulnerability disclosures, or relevant conference presentations - Experience with mobile platform instrumentation and debugging (Frida, lldb, Android Studio debugger) - Expertise in wireless communications, messaging protocols (SMS, RCS, IMS), or network-level attack vectors - Proficiency with firmware analysis and hardware security concepts - Experience with malware analysis and threat research - Background in threat modeling and security architecture assessment - Experience developing automation tools for security research (test harnesses, instrumentation frameworks) - Current TS/SCI security clearance Benefits - Comfort in chaos — you do your best work when requirements are incomplete, the environment is unfamiliar, and the answer is not obvious - Customer obsession with an engineering backbone — you care deeply about outcomes, and you have the technical depth to deliver them - Intellectual honesty — you tell customers and colleagues what is true, including when the honest answer is uncomfortable or inconvenient - Bias toward action — you make informed decisions quickly, execute, and adjust; paralysis under ambiguity is not in your vocabulary - Extreme ownership — you follow problems all the way to resolution, never stopping at the handoff - Builder instinct — when something does not exist that should exist, you build it; when something is broken, you fix it rather than file a ticket about it - Restless curiosity — you go deep on customer domains, not just your own product, because you understand that credibility is built on comprehension - Clear, confident communication — you can hold your own in a boardroom and equally in a terminal window; you adjust register without losing substance

Related Categories

Related Job Pages

More Security Engineer Jobs

Oportun logo

Data Security Engineer

Oportun

Oportun is an A.I.-powered digital banking platform that seeks to make financial health effortless for anyone.

Full TimeRemoteTeam 1,001-5,000Since 2006H1B Sponsor

• Design, implement, and maintain scalable data pipelines and data processing systems aligned with Oportun’s data architecture standards. • Collaborate with data scientists, analysts, and engineering teams to integrate data solutions into applications, analytics platforms, and workflows. • Develop and optimize ETL/ELT processes using modern data platforms such as Databricks. • Write efficient and scalable code using Python and SQL for data transformation, validation, and ingestion. • Ensure data quality, consistency, and reliability through validation, monitoring, and testing practices. • Support data platform monitoring and troubleshooting by investigating pipeline failures and contributing to root cause analysis. • Automate repetitive data workflows to improve efficiency and scalability across data operations. • Contribute to the documentation of data pipelines, data models, and system architecture. • Partner with governance and compliance teams to ensure alignment between data practices and organizational standards. • Perform other engineering-related tasks and initiatives as assigned within the Data Engineering function.

India
Job Closed
Zensar logo

Help Desk Engineer - Infra & IT Security Services

Zensar

At Zensar, we’re “experience-led everything”. We are committed to conceptualizing, designing, engineering, marketing, and managing digital solutions and experiences for over 130 leading enterprises. We are a company driven by a bold purpose: Together, we shape experiences for better futures. Whether for our clients, our people, or the world around us, this belief powers everything we do. At the heart of our culture is ONE with Client - a set of four core values that reflect who we are and how we work: One Zensar, Nurturing, Empowering, and Client Focus. Part of the $4.8 billion RPG Group, we’re a community of 10,000+ innovators across 30+ global locations, including Milpitas, Seattle, Princeton, Cape Town, London, Zurich, Singapore, and Mexico City. We believe the best work happens when individuality is celebrated, growth is encouraged, and well-being is prioritized. We are an equal employment opportunity (EEO) and affirmative action employer, committed to creating an inclusive workplace. All qualified applicants will be considered without regard to race, creed, color, ancestry, religion, sex, national origin, citizenship, age, sexual orientation, gender identity, disability, marital status, family medical leave status, or protected veteran status.

Full TimeRemoteTeam 10,001

What's this role about? H Description - Provide input to service delivery roadmap to ensure business continuity (present and future) as they relate to the endpoint space. - Develop and enforce engineering standards and models. - Design, maintain, and troubleshoot operating system images and task sequences in for a variety of physical platforms. - Package and execute application deployments, Microsoft’s standard installer technology (.MSI) and transforms (.MST), using industry standard tools such as Flexera Admi Studio, PSAppDeployToolkit, Advanced Installer, and Orca. - Perform advanced troubleshooting on desktop/laptop related issues using industry standard tools such as ProcMon and Process Explorer. - Write and maintain scripts using industry standard scripting languages including PowerShell. - Manage and troubleshoot Group Policy through the enterprise with a focus on workstation management and end user experience. - Recommend and implement improvements to desktop architecture and design. - Partner and collaborate with multiple technical teams (Architecture, Networking, Information Security, Support, etc.) to develop and support endpoint solutions. - Investigating alternative methods to expedite the problem resolution by evaluating future technologies or process improvement. - Triage and troubleshoot issues as escalated from Endpoint Support and Endpoint Administration. - Participate in the identification of vulnerabilities and mitigation plan. Experience and Educational Requirements - Bachelor’s Degree, preferably in Computer Science, Management Information Systems or technology related field, or equivalent combination of education and experience. - At least 7 years of experience in IT field, 3 of which would be Infrastructure endpoint engineering related experience. - Successful deployment of thoughtful, effective, and timely solutions that address complex business solutions and enhance the user experience. - Windows 10 Enterprise Operating system features, settings, and installation. - Active Directory, Group Policy, and their use for managing user and computer objects. - Ability to write scripts in PowerShell. - Familiarity with Defender, BitLocker, etc. - BIOS functions and configurations. - Wire and wireless networking technologies, topologies, and basic networking concepts such as DHCP, DNS, IP Addressing, Subnets, and VLANS. How we’d like you to lead: Advantage Zensar We are a technology consulting and services company with 11, 800+ associates in 33 global locations. More than 130 leading enterprises depend on our expertise to be more disruptive, agile and competitive. We focus on conceptualizing, designing, engineering, marketing, and managing digital products and experiences for high-growth companies looking to disrupt through innovation and velocity. Zensar Technologies is an Equal Employment Opportunity (EEO) and Affirmative Action Employer, encouraging diversity in the workplace. Please be assured that we will consider all qualified applicants fairly, regardless of race, creed, color, ancestry, religion, sex, national origin, citizen status, age, sexual orientation, gender identity, disability, marital status, family medical leave status, or protected veterans’ status. Zensar is a place where you are free to express yourself in an environment that values individuality, nurtures development and is mindful of wellbeing. We put our people and customers at the center of everything that we do. Our core values include: - Putting people first - Client-centricity - Collaboration Grow. Own. Achieve. Learn. with Zensar: www.youtube.com/watch?v=i2NZsiQqVnU

India
Motive logo

Product Security Architect

Motive

Motive combines IoT hardware with AI-powered applications to connect and automate physical operations.

Full TimeRemoteTeam 1,001-5,000Since 2013H1B Sponsor

Who we are: Motive empowers the people who run physical operations with tools to make their work safer, more productive, and more profitable. For the first time ever, safety, operations and finance teams can manage their drivers, vehicles, equipment, and fleet related spend in a single system. Combined with industry leading AI, the Motive platform gives you complete visibility and control, and significantly reduces manual workloads by automating and simplifying tasks. Motive serves nearly 100,000 customers – from Fortune 500 enterprises to small businesses – across a wide range of industries, including transportation and logistics, construction, energy, field service, manufacturing, agriculture, food and beverage, retail, and the public sector. Visit gomotive.com to learn more. Motive is looking for a Product Security Architect to join our Security Engineering team. You will be the primary security partner for product and engineering teams, focusing on design reviews, threat modeling, and building scalable "secure-by-default" components (libraries, services, frameworks) that empower engineers to ship securely and quickly. You will work across teams, influencing architecture and driving enablement programs. This is a highly strategic and technical role for architects who want to scale security through programs, influence, and engineering excellence, focusing on design, automation, and enablement. What you’ll do: Lead security design reviews and threat modeling for critical new products and features.Partner directly with Product and Engineering teams to define security requirements and architecture.Design, develop, and advocate for secure-by-default libraries and frameworks that eliminate entire classes of vulnerabilities.Develop and lead a Security Champions program to embed security expertise within product engineering teams.Provide expert guidance on architecture patterns (cloud, container, API, identity, data) to ensure security is built-in, not bolted on.Review 100s of features being shipped every quarter, identifying high-risk areas and prioritizing engagement.Drive measurable security outcomes by scaling engagement with dev/eng teams while keeping the security team lean.Own key domains such as API security, authentication/authorization patterns, and data-in-transit/at-rest security.Contribute to documentation, playbooks, and reusable patterns. What we’re looking for: Strong background in Product Security principles, architecture, and design patterns (API security, modern auth/auth, data security).Proven ability to lead security design reviews and threat modeling for large-scale distributed systems.Experience designing and developing secure-by-default libraries, frameworks, or security services for internal consumption.Deep hands-on experience with cloud security fundamentals (identity, networks, encryption, isolation, boundary design).Ability to design, write, and maintain automations using Python or Go is a plus, but architecture skills are paramount.Excellent cross-functional collaboration and communication skills, with a track record of influencing engineering and product decisions.Experience establishing or running a Security Champions program or similar security enablement initiatives is a strong plus.Ability to self-manage, think strategically about security program scaling, and drive projects from design to deployment. Bonus skills: Experience with Kubernetes/EKS, ArgoCD, or Terraform. Experience with multi-account AWS Org design. Experience with CI/CD security and software supply chain controls. Experience with IoT or edge device security. Experience building identity automation or least privilege workflows. Creating a diverse and inclusive workplace is one of Motive's core values. We are an equal opportunity employer and welcome people of different backgrounds, experiences, abilities and perspectives. Please review our Candidate Privacy Notice here. UK Candidate Privacy Notice here. The applicant must be authorized to receive and access those commodities and technologies controlled under U.S. Export Administration Regulations. It is Motive's policy to require that employees be authorized to receive access to Motive products and technology.

India
Job Closed
Full TimeRemoteTeam 1-10H1B No Sponsor

• Develop high-level C# Desktop Applications for user interaction; • Build low-level, hardened C/C++ code for Linux (Yocto) and RTOS; • Design and maintain secure C/C++ applications across Windows (Visual Studio), Linux (Eclipse), and RTOS; • Develop robust C#/.NET desktop applications (WPF/WinForms); • Build and secure Yocto-based Linux distributions; • Design firmware for RTOS with a focus on memory protection; • Integrate security controls such as encryption (AES, RSA); • Ensure seamless and secure communication between C# high-level applications and low-level embedded targets.

Portugal