Lead, Security Research Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 10,001+H1B SponsorCompany SiteLinkedIn

Location

Florida

Posted

7 days ago

Salary

$135K - $250.5K / year

Seniority

Senior

Bachelor Degree9 yrs expExperience acceptedEnglishLinuxPythonUnix

Job Description

Lead, Security Research Engineer

L3Harris Technologies

• Perform vulnerability research on embedded systems and software applications to identify previously undisclosed security risks • Reverse engineer multiple architectures and platforms as needed, including ARM, x86, x64, and MIPS • Leverage both static and dynamic analysis tools for firmware/software evaluation • Bypass modern security controls (such as ASLR, NX, canaries) in order to develop a working proof-of-concept (PoC) • Apply knowledge of offensive and defensive reverse engineering techniques, including countering and developing advanced security measures • Design, develop, or analyze low-level system components, including kernel modules and other system foundational firmware services • Develop tools and software solutions using python scripts, C, or other programming languages as needed • Work proficiently within a Unix/Linux operating system environments

Job Requirements

  • Active Top Secret/SCI security clearance required
  • Bachelor’s Degree and minimum 9 years of prior relevant experience
  • Graduate Degree and a minimum of 7 years of prior related experience
  • In lieu of a degree, minimum of 13 years of prior related experience
  • 5+ years’ experience working with reverse engineering frameworks such as Ghidra or IDA Pro
  • 5+ years’ experience performing vulnerability research on embedded systems and/or software applications to identify potential security risks
  • Professional hands-on experience with diagnostic tools such as oscilloscopes, multi-meters, power supplies, and logic analyzers
  • Experience in firmware emulation and debugging
  • Experience with embedded hardware and software design, development, and testing processes
  • Background in developing hardware platforms
  • Competence in one or more low-level programming languages
  • Knowledge and expertise in RF systems and technologies
  • Familiarity with wired and wireless protocols including USB, SPI/I2C/1-Wire, Ethernet, PCI-Express, 802.11, Bluetooth, Cellular, and others
  • Experience developing custom emulation solutions to enable dynamic analysis using tools such as QEMU
  • Experience writing plugins for decompilers such as IDA and Ghidra
  • Skill in soldering, prototyping, and analyzing electronic circuits
  • Ability to lead and manage engineering teams effectively

Benefits

  • health and disability insurance
  • 401(k) match
  • flexible spending accounts
  • EAP
  • education assistance
  • parental leave
  • paid time off
  • company-paid holidays

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 10,001+H1B Sponsor

• Managing and maintaining all site cleared employee required training • Performing internal audits as required • Working with Cyber Engineering to develop a System Security Plan (SSP) from entrance to exit of sensitive materials and hardware • Application of site security policy(s) • Performing security surveys identifying requirements to enable business growth • Being directly accessible to senior members of the organization and able to influence an organization's internal policies and procedures • Complying with contract security requirements: Maintaining your organization security clearance, Screening your personnel, and Securing information and assets • Working with Sales/Contracts at bid proposal through contract award. • Sponsoring subcontractors as required, requesting approval for visits to secure sites • Working on sensitive contracts, conducting annual audits and inspections of these sites, and keeping records of these inspections • Ensuring employees, officers, and directors are properly assessed and authorized before they can examine, possess, or transfer controlled goods. • Verifying personal information for temporary workers, international students and visitors for the purpose of applications for exemption • Maintaining all site registrations with the Controlled Goods Program

Canada

Senior Cyber Security Specialist Location Strada Regina 40 6934 Bioggio Switzerland Work arrangement Full-time A bit about the role We are looking for an individual with a passion for cyber security to work alongside a talented team to Improve and operate a cyber security Center. The role requires a strong background and understanding of all cyber security domains. In this position, you will be part of the global cyber security operations team with focus on identification, analysis and response to cyber security threats and events. You will support the Head of our Cyber Security Operations Center in improving the effectiveness of the team and Leads the planning, implementation, documentation. You can expect a demanding and complex international environment, which is highly stimulating and encouraging. The growth of the company demands your structured and innovative approach, as well as flexibility to a high degree. As a committed team player, you will support developing the maturity of the cyber security operation center, its controls and processes. Your key tasks - Handle daily incidents/threats - Assist correlating alerts, implementing monitoring Use Cases - Recommend Cyber Security changes or enhancements and drive implementation - Manage and cultivate the defined security services and the relationship to our service providers - Participate in organizational Security projects, as required - Support in development processes, and procedures for the team - Provide implementations, recommendations for protecting and resolving threats and incidents - Participate in the selection and evaluation of security solutions, or enhancements to existing cyber security solutions, to improve overall enterprise security - Manage and support in major Cyber Security Incidents - Support in on-call rotation - Act as a technical Lead role model in the team on driving initiatives and projects A bit about you - 4-6 years of working experience in a SOC / CDC or similar roles - Working experience in the creation of playbooks and the tuning of SIEM use cases - Deep knowledge and expertise in SIEM and EDR solutions - Solid knowledge about Cloud like (AWS, Azure, Oracle etc) - Working experience in Threat Intelligence Management - Fluent in English (both written and verbal) - Knowledge of German is considered a strong asset It would be a real bonus if you have - Information and Cyber Security certificates like CISSP, SANS or similar - Working experience with Splunk Apps, especially Enterprise Security and knowledge of the Splunk “search”-language - Working experience with automation and SOAR solutions - Working experience in Digital Forensics and Cyber Security Incident Response Additional information We realize that managing work life balance is a challenge we all face in our daily lives and in order to support with this we are pleased to offer hybrid and flexible working for most of our Avaloqers to maintain work life balance and still continue our fantastic Avaloq culture in our global offices. #LI-Hybrid Benefits - Annual bonus or sales reward At Avaloq we work hard to remain an industry leading provider and we love to reward our colleagues with a share of that success with an annual bonus, you will even remain eligible for annual bonus while you do the hardest job of your life – taking care of your children during parental leave. - Flexible working We understand that fitting your life around your job can be challenging which is why in most roles we offer flexible working to allow you to thrive both in and out of work. - Kudos instant recognition scheme We love to see people thriving in their roles and we have an instant recognition scheme at Avaloq to help managers reward the great work our colleagues deliver with a gift to say thanks. - Access to Udemy for professional and personal learning We think it is important to learn and grow professionally, but if you are someone who likes to learn outside of work we give you access to online learning for both professional and personal learning, with over 210,000 courses to choose from.

Switzerland
Simeio logo

Security Engineer, Purview

Simeio

We simplify IAM complexities for global organizations to ensure security goals are met, backed with right tech & people!

Full TimeRemoteTeam 501-1,000H1B Sponsor

• Assess the current state of the client’s Active Directory and Azure/Entra ID deployment, including forest design, site design, domain design, security group topology, deployment architecture, organizational unit (“OU”) design, authentication, and group policy design. • Manage the migration of enterprise data governance and compliance frameworks to Microsoft Purview, ensuring secure data management and regulatory compliance. • Run PowerShell queries against the client AD to determine relevant statistics of current AD and Azure objects, including users, accounts, groups, organizational units (OUs), computer objects, and related identity objects. • Run SailPoint out-of-the-box reports against AD connectivity to provide group and account ownership and membership information. • Review AD configurations, processes, and documentation to understand the client’s current deployment and operating model. • Identify configuration and operational gaps in the client’s AD domains, infrastructure, architecture, and deployment. • Prioritize identified gaps based on criticality and risk. • Provide recommendations to address critical gaps and risks across AD and Entra ID environments. • Discover and assess current processes for AD group management, AD group policy management, and AD account management. • Suggest modifications and refinements to existing processes and create new processes if required. • Determine the resources and skills necessary to complete remediation activities and achieve defined milestones. • Provide an estimated budget to accomplish remediation as outlined during the assessment phases. • Leverage client tools such as ADUC (Active Directory Users & Computers), ManageEngine, StealthAUDIT, or other AD scanning utilities as needed to accomplish data-gathering activities.

Texas
OpenAI logo

Offensive Security Engineer

OpenAI

Creating safe AGI that benefits all of humanity.

Full TimeRemoteTeam 201-500Since 2015H1B Sponsor

• Serve as the technical owner of OpenAI’s offensive security agents, establishing its architecture, technical direction, operating model, and evaluation strategy. • Design and build a portfolio of specialized agents that continuously test OpenAI’s infrastructure and applications from a variety of authenticated and unauthenticated perspectives. • Translate expert offensive security workflows and intuition into tools, skills, harnesses, policies, and internal knowledge bases. • Build agents that deeply understand OpenAI’s environment by integrating internal context. • Develop capabilities for testing cloud and Kubernetes environments, modern web applications, external attack surface, endpoints, and other high-value systems. • Build complete vulnerability-management loops that move beyond discovery to impact validation, ownership identification, prioritization, remediation support, progress tracking, and fix verification. • Design human-in-the-loop systems that allow offensive security engineers to approve or reject potentially dangerous actions, provide missing context, redirect investigations, and steer agents away from unproductive paths. • Create feedback mechanisms that allow agents to learn from the decisions, corrections, and domain expertise of experienced offensive security practitioners. • Develop rigorous evaluations that measure meaningful security outcomes and improvements in agent capability over time. • Build production-quality infrastructure that allows the system to run continuously, recover from failures, remain observable and debuggable, and operate safely against production systems. • Investigate failures in agent reasoning and behavior, identify where models are capable or unreliable, and improve the surrounding tools, context, workflows, and guardrails accordingly. • Partner closely with offensive security, infrastructure security, product security, codex security, and engineering teams to ensure findings are high signal, understandable, and actionable. • Help define the future of offensive security at OpenAI, with the goal of enabling agents to perform most repeatable security testing while human experts focus on automation and high leverage agent-assisted manual review.

California + 3 moreAll locations: California | District Of Columbia | New York | Washington
$347K - $490K / year