Clarity Logo

Clarity

Sr. Principal Reverse Engineering/Vulnerability Research Engineer

Posted 21 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in USA
Senior level
Remote
Hiring Remotely in USA
Senior level
Conduct vulnerability research and reverse engineering across diverse systems. Perform static and dynamic analysis using disassemblers, debuggers, and fuzzers; develop exploits; document and communicate findings; and mentor security researchers. The role requires expertise in C and assembly, Linux internals, exploitation techniques, Android and Chrome vulnerability research, and the ability to obtain and maintain a TS/SCI clearance.
The summary above was generated by AI

Clarity Innovations is a trusted national security partner, dedicated to safeguarding our nation’s interests and delivering innovative solutions that empower the Intelligence Community (IC) and Department of Defense (DoD) to transform data into actionable intelligence, ensuring mission success in an evolving world.

Our mission-first software and data engineering platform modernizes data operations, utilizing advanced workflows, CI/CD, and secure DevSecOps practices. We focus on challenges in Information Warfare, Cyber Operations, Operational Security, and Data Structuring, enabling end-to-end solutions that drive operational impact.

We are committed to delivering cutting-edge tools and capabilities that address the most complex national security challenges, empowering our partners to stay ahead of emerging threats and ensuring the success of their critical missions. At Clarity, we are people-focused and set on being a destination employer for top talent, offering an environment where innovation thrives, careers grow, and individuals are valued. Join us as we continue to lead innovation and tackle the most pressing challenges in national security.

Position Summary

As a member of the Security Research team, you will imagine weaknesses in multiple types of systems and then find, demonstrate/document, and exploit those weaknesses. You will be joining a team of mature and extremely competent Security Researchers to breakdown and fully understand how a host of different systems function. You will need to leverage extensive experience performing static and dynamic analysis and must be familiar with multiple classes of vulnerabilities. Additionally, you must be extremely comfortable communicating with team members, technical partners, and non-technical partners alike. The ideal candidate will be comfortable and confident operating at the early phases of a vulnerability research project and have the mettle to see the project through to multiple phases and iterations.

Responsibilities

  • Perform vulnerability research and reverse engineering for customer tasks
  • Perform static and dynamic analysis by applying research tools such as disassemblers, debuggers, and fuzzers
  • Perform exploit development leveraging discovered vulnerabilities
  • Communicate security research findings internally and, when and where appropriate, externally Mentor fellow security researchers

Minimum Qualifications

  • Must be able to obtain and maintain a TS/SCI security clearance (note, only US Citizens are eligible for security clearances)
  • Bachelor's degree in Computer Engineering, Computer Science, Software Engineering, or a related technical discipline and 11  years of professional experience
  • Experience participating in CTFs, hackathons, or other cyber competitions
  • Experience with Ghidra, Binary Ninja, IDA or other reverse engineering/disassembler tools
  • Experience working in Linux fundamentals (understanding sockets, file descriptors, networking, iptables, file systems, kernel, etc.)
  • Ability to read and write C and assembly languages as needed (ARM, MIPS, x86_64)
  • Programming fundamentals; particularly with networking, data structures, and data models
  • Understanding of exploitation techniques such as leveraging arbitrary read-write primitives, shellcoding, and return-oriented programming / jump-oriented programming
  • Proven track record of exploit creation targeting Android operating systems and Chrome web browsers

Preferred Experience

  • Currently possess a Top Secret security clearance
  • OS and kernel reverse engineering
  • Understanding of fuzzers such as AFL++ or libfuzzer
  • Understanding of common exploit mitigation mechanisms such as SELinux, Seccomp, ASLR, and CFI.
  • Strong understanding of dynamic analysis with gdb/gdbserver and similar tools
  • Basic understanding of processor tool chains and the Android NDK
  • Understanding of emulation using Qemu or Unicorn for running code in a non-native environment
  • Experience identifying 0-days and vulnerabilities

Salary Range: $133,000 - $315,000

We are an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.

Similar Jobs

30 Seconds Ago
In-Office or Remote
Maryland, USA
43K-78K Annually
Junior
43K-78K Annually
Junior
Other • Utilities
Acquire new small-business customers through prospecting, cold calling, networking, lead generation, and referrals. Sell wireless products and services using solution-based selling, analyze customer needs, negotiate and close deals, manage sales funnels, and report forecasts. The role requires strong communication, customer service, multitasking, negotiation, and relationship-management skills, with opportunities for training and advancement.
Top Skills: Sales Force AutomationWireless Communications
6 Minutes Ago
Remote or Hybrid
USA
85K-120K Annually
Entry level
85K-120K Annually
Entry level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Monitor, triage, investigate, and respond to security incidents across endpoint, identity, email, network, and cloud environments. Analyze EDR telemetry, logs, forensic artifacts, malware, Microsoft 365 threats, and network activity to determine compromise scope and recommend remediation. Communicate findings and guidance to customers, improve detection and response processes, and use scripting and AI technologies to streamline investigations. The role requires independent technical work and a 4x10 schedule including one weekend day.
Top Skills: Active DirectoryAi TechnologiesBashCrowdstrike Falcon CompleteEndpoint Detection And Response (Edr)Forensic Analysis ToolsLinuxmacOSMalware Analysis ToolsMicrosoft 365Microsoft Entra IdMitre Att&CkNetwork ProtocolsOktaPowershellPythonSIEMWindows
7 Minutes Ago
In-Office or Remote
43K-78K Annually
Junior
43K-78K Annually
Junior
Other • Utilities
Acquire new small and medium-sized business accounts through prospecting, cold calling, networking, and referrals. Analyze customer needs, recommend wireless products and solutions, negotiate terms, and close sales. Manage sales funnels, forecasts, and activity reporting using sales automation tools. Participate in training and sales meetings while developing prospecting, call execution, and relationship-management skills.
Top Skills: Sales Force AutomationWireless Products And Services

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account