Senior CNO / Exploit Developer

Industry:
R&D
Category:
Cybersecurity
Location:
Greater Boston (Hybrid)
Job Description

The Senior CNO Developer will drive the engineering of cybersecurity exploitation tools & techniques. As an OffSec expert, you will reverse engineer and exploit software and hardware systems important to U.S. government (USG) operations and critical to the defense of our nation. Your main areas of research will include cyber tool prototyping and technical analysis of offensive or defensive cyber tools and systems, automated vulnerability discovery, reversing, fuzzing, emulation, software protection mechanisms, static analysis and dynamic instrumentation. Once you’re on this elite team, you will communicate your research to non-domain experts through your writing, public presentations, and hand-on training sessions.

Scope:

  • Conduct cyber tool prototyping and technical analysis of offensive or defensive cyber tools and systems and automated vulnerability discovery to drive exploit development capabilities.
  • Daily research will include reversing, fuzzing, emulation, protocol and binary analysis.
  • Collaborate effectively with a wide range of technical experts to meet customer objectives.
  • Develop research concepts from proposal through implementation and transition, delivering high-quality software in a team environment.
  • Communicate technical ideas and practical applications through reports, white papers and presentations.
  • The selected candidate will be subject to a pre-employment background check (“CBI”) and must be able to obtain and maintain a Secret-level DoD security clearance (Top Secret preferred).

Quals:

  • Active security clearance, and ability to obtain Top Secret (TS) preferred
  • MS or PhD in Computer Science or a related field
  • Version Control Systems (Git)
  • Dissassemblers/Decompilers (Ghidra, IDAPro, BinJa)
  • Debuggers (WinDbg, GDB)
  • Programming languages (C/C++, Python)
  • Container provisioning/orchestration systems (Ansible, Kubernetes, Docker)
  • Network protocol analysis (Wireshark, Tcpdump)
  • Emulation/Virtualization technologies (QEMU, VMWare)
  • Operating System internals, e.g. Linux, RTOS
  • Reverse Engineering of Embedded Systems Firmware, Malicious Code, Mobile Applications, etc.
  • Vulnerability Assessments, Statistics and Metrics
  • SAT/SMT Solvers, Symbolic Execution
  • Dataflow analysis for compiled binaries
  • Binary intermediate representations, translations
  • Compiler construction
  • Anti-debugging/anti-instrumentation techniques
  • Network and host security products

Comp:

  • $125-165K base salary depending on mutual fit and depth of engineering skills
  • Pension plan, 401(k) match program (5%)
  • Rich, comprehensive employee benefits
  • Relocation service fully arranged and paid for by the hiring employer
  • Employer-paid continuous training, e.g. prestigious academic classes, DEFCON attendance/participation, symposiums, etc.

Rogue Talent and all of its hiring partners/clients are equal employment opportunity (EEO) employers who may provide reasonable accommodation to enable individuals with disabilities to perform the essential functions of the job. We champion and continue to work toward a harmoniously diverse and inclusive workforce built upon a foundation of equity and goodwill. All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, veteran status, disability status, or genetic information; US citizenship is required.