We securely connect everything to make anything possible.
Security Research Engineer
Location
United States
Posted
25 days ago
Salary
$146.7K - $277.6K / year
Seniority
Mid Level
Job Description
Security Research Engineer
Cisco
Role Description This is a fully remote role based in the United States. As a member of Talos, you will support cutting edge detection and mitigation technologies. You will work towards keeping yourself abreast of the latest industry threat creation and defense techniques, and you will develop proof-of-concept solutions, provide domain expertise, and guide implementation to facilitate successful security posture in Cisco’s products. If you enjoy vulnerability research, crash analysis, reverse engineering, and researching new techniques and writing tools to automate these tasks, this job is for you! Your Impact - Security research including development of tools for vulnerability analysis and mitigation. - Development of static and run-time analysis tools to figure out root cause and input conditions related to a vulnerability. - Vulnerability triage and proof of concept exploit development to support the creation of detection content. - Write detailed technical reports, summaries, and testing methodologies. - Research emerging technologies, protocols, and testing methodologies. - Develop proof of concept exploits for testing vulnerability mitigations. - Perform patch analysis to find and trigger vulnerabilities. - Reverse engineer binary applications, protocols, and formats. - Analyze vulnerabilities and emerging security threats and technologies. - Provide critical security focused expertise to engineering organizations. Qualifications - 3+ years of experience in vulnerability research or a closely related area such as exploit or mitigation development on Linux Systems. - 3+ years’ experience with C/C++, and a scripting language (e.g., Python), and assembly (e.g., x86/x64, ARM, etc.). Requirements - Bachelor’s degree or equivalent in Computer Science, Electrical Engineering, Cyber Security, or other tech-related degree. - Experience with Linux internals. - Experience with binary auditing and reverse engineering, and with related tools such as IDA Pro, Binary Ninja, Ghidra, etc. and with plugin development. - Experience with common vulnerabilities and methods of exploitation, such as memory corruption, web application exploitation, file format vulnerabilities, protocol-based weaknesses, etc. - Knowledge of common file formats, network protocol structures, and enterprise networking architecture. - Ability to work independently with minimum supervision and to tackle additional tasks as the need arises. Benefits - Medical, dental and vision insurance. - 401(k) plan with a Cisco matching contribution. - Paid parental leave. - Short and long-term disability coverage. - Basic life insurance. - 10 paid holidays per full calendar year, plus 1 floating holiday for non-exempt employees. - 1 paid day off for employee’s birthday, paid year-end holiday shutdown, and 4 paid days off for personal wellness determined by Cisco. - Non-exempt employees receive 16 days of paid vacation time per full calendar year. - Exempt employees participate in Cisco’s flexible vacation time off program. - 80 hours of sick time off provided on hire date and each January 1st thereafter. - Optional 10 paid days per full calendar year to volunteer.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Cybersecurity Engineer – Clearance Required
LMILMI is a nonprofit business that was established in 1961 to address complex issues throughout the federal government of the United States. LMI is headquartered in McLean, Virginia
• Lead Risk Management Framework (RMF) activities for the LIGER deployment at CBP, including system categorization, control selection and tailoring, implementation, assessment, and continuous monitoring • Own and maintain authorization artifacts: System Security Plan (SSP), Security Assessment Plan (SAP), Security Assessment Report (SAR), Plan of Action and Milestones (POA&M), and supporting documentation aligned to CBP and DHS requirements • Coordinate directly with CBP ISSOs, Authorizing Officials, and cyber working groups to advance ATO and continuous authorization activities • Interpret NIST 800-53 controls in the context of the LIGER platform and translate them into actionable engineering requirements • Run and review vulnerability scans across CI/CD pipelines and runtime environments, triage findings, and drive remediation through the engineering team • Validate secure configurations and hardening baselines (e.g., CIS Benchmarks, DISA STIGs) on containers, hosts, and cloud resources • Partner with platform engineers on cloud and container security in AWS GovCloud, including IAM, network controls, secrets management, logging, and runtime protection • Develop and maintain security policies, procedures, and standard operating procedures (SOPs) specific to LIGER on CBP infrastructure • Track audit findings, remediation actions, and POA&M items to closure • Support FedRAMP-aligned control implementation and inheritance where applicable • Advise senior LIGER and CBP leadership on system risk levels, control effectiveness, and emerging compliance considerations for AI/LLM systems in federal environments.
Role Description This Protection Advisor opportunity is ideal for experienced individuals near South Coast seeking a proposition with leads provided. You will be joining a business based along the South Coast, who are producing a high number of leads, which they can share with you. As such, little need for self-generation. This is a home based role with occasional meetings with the Principal to discuss business, cases etc, as such you should be within 1 – 2 hours of the Southampton / Bournemouth area. Qualifications - You should have experience as a Protection Advisor. - Ideally, you should have R05 or equivalent. - You should have a desire to be self-employed. Benefits - Self-employed role with OTE of £50,000 - £85,000+. - Healthy commission splits with tiered rates on self-generation and company leads. - Fully home based role with occasional get-togethers. - Ability to earn additional income through various referral schemes. Company Description
Especialista em Segurança da Informação
Unimed Grande FlorianópolisConheça todos os benefícios de ser Unimed em: https://linktr.ee/unimedflorianopolis
• Participar ativamente do ciclo de melhoria contínua em segurança da informação, identificando gaps, oportunidades de melhorias, propondo e executando planos de ação, bem como definir políticas de segurança da informação e indicadores de segurança.
• Build & Harden Secure Pipelines • Design, build, and maintain secure CI/CD pipelines with security gates that catch issues before they reach production. • Systematically, consistently and automatically capture the risk exposure of Chainguards products. • Implement and enforce software supply chain security controls: signed artifacts, SBOMs, provenance attestation (SLSA, Sigstore / Cosign). • Proactively identify emerging customer security needs, and build solutions to meet these. • Cloud-Native Product Hardening • Lead security architecture reviews and threat models for Kubernetes-based workloads running on GCP and AWS. • Harden container images, Kubernetes cluster configurations, and cloud IAM postures — minimising attack surface across our product stack. • Define and drive adoption of baseline security standards: pod security standards, network policies, workload identity, secrets management. • Evaluate and operationalise CNAPP / CSPM tooling to maintain continuous visibility into cloud-native risk.


