Clarity Logo

Clarity

Sr. Principal Reverse Engineering/Vulnerability Research Engineer

Posted 3 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in USA
Senior level
Remote
Hiring Remotely in USA
Senior level
Conduct vulnerability research and reverse engineering across diverse systems. Perform static and dynamic analysis using disassemblers, debuggers, and fuzzers; develop exploits; document and communicate findings; and mentor security researchers. The role requires expertise in C and assembly, Linux internals, exploitation techniques, Android and Chrome vulnerability research, and the ability to obtain and maintain a TS/SCI clearance.
The summary above was generated by AI

Clarity Innovations is a trusted national security partner, dedicated to safeguarding our nation’s interests and delivering innovative solutions that empower the Intelligence Community (IC) and Department of Defense (DoD) to transform data into actionable intelligence, ensuring mission success in an evolving world.

Our mission-first software and data engineering platform modernizes data operations, utilizing advanced workflows, CI/CD, and secure DevSecOps practices. We focus on challenges in Information Warfare, Cyber Operations, Operational Security, and Data Structuring, enabling end-to-end solutions that drive operational impact.

We are committed to delivering cutting-edge tools and capabilities that address the most complex national security challenges, empowering our partners to stay ahead of emerging threats and ensuring the success of their critical missions. At Clarity, we are people-focused and set on being a destination employer for top talent, offering an environment where innovation thrives, careers grow, and individuals are valued. Join us as we continue to lead innovation and tackle the most pressing challenges in national security.

Position Summary

As a member of the Security Research team, you will imagine weaknesses in multiple types of systems and then find, demonstrate/document, and exploit those weaknesses. You will be joining a team of mature and extremely competent Security Researchers to breakdown and fully understand how a host of different systems function. You will need to leverage extensive experience performing static and dynamic analysis and must be familiar with multiple classes of vulnerabilities. Additionally, you must be extremely comfortable communicating with team members, technical partners, and non-technical partners alike. The ideal candidate will be comfortable and confident operating at the early phases of a vulnerability research project and have the mettle to see the project through to multiple phases and iterations.

Responsibilities

  • Perform vulnerability research and reverse engineering for customer tasks
  • Perform static and dynamic analysis by applying research tools such as disassemblers, debuggers, and fuzzers
  • Perform exploit development leveraging discovered vulnerabilities
  • Communicate security research findings internally and, when and where appropriate, externally Mentor fellow security researchers

Minimum Qualifications

  • Must be able to obtain and maintain a TS/SCI security clearance (note, only US Citizens are eligible for security clearances)
  • Bachelor's degree in Computer Engineering, Computer Science, Software Engineering, or a related technical discipline and 11  years of professional experience
  • Experience participating in CTFs, hackathons, or other cyber competitions
  • Experience with Ghidra, Binary Ninja, IDA or other reverse engineering/disassembler tools
  • Experience working in Linux fundamentals (understanding sockets, file descriptors, networking, iptables, file systems, kernel, etc.)
  • Ability to read and write C and assembly languages as needed (ARM, MIPS, x86_64)
  • Programming fundamentals; particularly with networking, data structures, and data models
  • Understanding of exploitation techniques such as leveraging arbitrary read-write primitives, shellcoding, and return-oriented programming / jump-oriented programming
  • Proven track record of exploit creation targeting Android operating systems and Chrome web browsers

Preferred Experience

  • Currently possess a Top Secret security clearance
  • OS and kernel reverse engineering
  • Understanding of fuzzers such as AFL++ or libfuzzer
  • Understanding of common exploit mitigation mechanisms such as SELinux, Seccomp, ASLR, and CFI.
  • Strong understanding of dynamic analysis with gdb/gdbserver and similar tools
  • Basic understanding of processor tool chains and the Android NDK
  • Understanding of emulation using Qemu or Unicorn for running code in a non-native environment
  • Experience identifying 0-days and vulnerabilities
We are an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.

Similar Jobs

An Hour Ago
In-Office or Remote
Mid level
Mid level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Operates and maintains unmanned aircraft systems in remote and austere environments. Plans missions, briefs customers, monitors weather and airspace requirements, delivers flight and payload data, analyzes mission results, and completes reports. Performs system testing, troubleshooting, maintenance, inventory control, and customer support while coordinating with subject matter experts. Requires frequent deployment, physical outdoor work, an active Secret DoW clearance, and an FAA Class 2 medical certificate.
Top Skills: Faa Class 2 Medical CertificateIntegratorNetworkingNotamsRq-21ScaneagleSpinsUnmanned Aircraft Systems (Uas)
An Hour Ago
In-Office or Remote
Mid level
Mid level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Operate and maintain unmanned aircraft systems during customer missions, including preflight planning, mission execution, full-motion video and payload data delivery, post-mission reporting, troubleshooting, maintenance, inventory control, and customer coordination. The role requires frequent deployment to remote or austere environments for four-to-six-month assignments, extensive travel, physical work outdoors, and an active Secret Department of War clearance.
Top Skills: Faa Class 2 Medical CertificateIntegratorNotamsRq-21ScaneagleSpinsUas
2 Hours Ago
Remote or Hybrid
United States
85K-143K Annually
Expert/Leader
85K-143K Annually
Expert/Leader
Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Oversee operational risk management for MetLife’s Group Benefits business by implementing the non-financial risk framework, advising business leaders, monitoring risk events and indicators, managing remediation, strengthening controls, and partnering with technology, operations, compliance, and control functions. The role also develops risk mitigation strategies, supports governance and risk appetite compliance, and improves risk practices through training, stakeholder engagement, analytics, and emerging technologies.
Top Skills: AIAutomationDashboardsRisk Analytics

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account