SG2 Recruiting

Cyber Vulnerability Researcher

SG2 Recruiting  •  California (Onsite)  •  4 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

THIS POSITION REQUIRES AN ACTIVE US GOVERNMENT SECURITY CLEARANCE. IF YOU DO NOT HAVE A CLEARANCE, PLEASE DO NOT APPLY.

Cyber Vulnerability Researcher

SG2 Recruiting has partnered with Lumbee Holdings to spearhead the search for a visionary Cyber Vulnerability Researcher This is a pivotal opportunity to join a dynamic team and directly influence the company’s next phase of growth. If you are a strategic thinker ready to make a tangible impact, we want to hear from you.

At Lumbee Holdings, we deliver mission-critical logistical, technical, and analytical support to empower strategic government and defense operations. Our culture is built on continuous improvement, operational integrity, and dedicated service to key defense stakeholders. When you join our team, you become part of a collaborative environment where your expertise directly supports military readiness and system efficiency.

Your Role: As a Cyber Vulnerability Researcher, you will deliver advanced vulnerability research and low-level exploit development capability in support of the MCTSSA Cyber Branch’s adversarial testing mission at Camp Pendleton, CA. Your core purpose is to extend the team’s offensive depth beyond tool-based penetration testing into original vulnerability discovery, binary analysis, and exploitation of embedded systems, real-time operating systems (RTOS), and custom platform architectures. Working in close coordination with vulnerability assessment analysts and penetration testers, you will translate research-derived findings into actionable assessment products and technically defensible remediation recommendations for Marine Corps Program Offices.

What You Will Be Doing

  • Conduct Original Vulnerability Research: Perform static and dynamic analysis using tools like Ghidra, IDA Pro, WinDbg, OllyDbg, and gdb to identify exploitable weaknesses in Marine Corps software, firmware, and embedded platforms.

  • Execute Fuzzing & Exploitation: Develop and execute fuzz testing campaigns to discover zero-day vulnerabilities, and create proof-of-concept (PoC) exploits in isolated research environments to validate mission impact.

  • Analyze Low-Level Assembly Code: Examine assembly architectures (x86, x64, ARM, MIPS, PowerPC) to identify memory corruption, logic flaws, and bypass strategies for DEP, ASLR, and stack canaries.

  • Assess Embedded & RTOS Platforms: Research weapons systems, C5ISR platforms, embedded systems, and real-time operating systems (VxWorks, RTOSs, Android, Linux, Windows) that commercial COTS scanners cannot evaluate.

  • Analyze Code & Write Reports: Conduct static/dynamic source code analysis to identify CWEs, produce Code Review Reports, and deliver summary Security Posture Assessments to guide program office decision-making.

  • Automate Research Workflows: Utilize Python, Perl, Ruby, or C/C++ to build custom scripts and tools that accelerate research discovery cycles and improve methodology repeatability.

  • Publish Research Findings: Synthesize research into Vulnerability Survey Reports, technical briefings, attack path analyses, and mitigation strategies compliant with Security Classification Guides.

What You Will Need

Must-Haves

  • Security Clearance: Active DoD Secret Security Clearance (ability to obtain and maintain Top Secret preferred).

  • Tooling Expertise: At least five (5) years of hands-on experience using Ghidra for vulnerability research, binary analysis, and reverse engineering.

  • Programming & Debugging: Proficiency in C or C++, scripting languages (Python, Perl, or Ruby), assembly languages (x86, x64, ARM, MIPS, PowerPC), and debuggers (gdb, WinDbg, OllyDbg).

  • System & Protocol Knowledge: Experience with PC/embedded system architectures, OS internals, network protocols, fuzzing techniques, and common mitigation techniques (DEP, ASLR, stack canaries).

  • Location/On-Site: Willingness and ability to work 100% on-site at Camp Pendleton, CA.

Nice-to-Haves

  • Certifications: Advanced software assurance credentials such as OSED, OSEE, GREM, or equivalent.

  • Advanced Research Skills: Experience developing IDA Pro plugins/scripts, hardware/FPGA debugging, or 10+ years of low-level reverse engineering and systems programming experience.

  • Competitions & Tradecraft: Active participation in Capture The Flag (CTF) or software hacking competitions.

Military & Veteran Equivalents: We strongly encourage transitioning service members and veterans to apply! Candidates with backgrounds in the following military occupational specialties (MOS), Air Force Specialty Codes (AFSC), and Navy Enlisted Classifications (NEC) are exceptionally well-suited for this role:

  • U.S. Army MOS/WO: 17C (Cyber Operations Specialist), 170D (Cyber Warfare Technician Warrant Officer).

  • U.S. Air Force AFSC: 1B4X1 (Cyber Warfare Operations).

  • U.S. Navy Rating/Designator: CWT (Cyber Warfare Technician) or CWE (Cyber Warfare Engineer).

Logistics

  • Work Location: MCTSSA Cyber Branch – Camp Pendleton, California (Standard business hours: Mon–Fri, 8:00 a.m. – 5:00 p.m.)

  • Position Type: On-site, full-time, Exempt

  • Travel Required: Less than 10% CONUS travel

  • Salary Range: $110,000.00 To $120,000.00 Annually

  • Benefits: Comprehensive benefits package (detailed terms and eligibility provided during onboarding)

Mental and Physical Demands: This position is primarily sedentary and performed in an office or laboratory setting, requiring extended periods of computer use, close visual attention to technical detail, and the ability to sit or stand for extended periods. The role requires the cognitive ability to perform complex technical analysis, review software architectures, and interpret low-level system instructions. Occasional lifting of computer or lab equipment up to 25 lbs. may be required.

Related Duties as Assigned: To support evolving mission priorities and organizational goals, the Program Manager or MCTSSA Cyber Branch Lead may assign you additional operational, technical, or research tasks.

Equal Employment Opportunity & Disability Accommodations: Lumbee Holdings is an Equal Opportunity Employer. We do not discriminate in employment opportunities or practices on the basis of race, color, religion, sex (including pregnancy, sexual orientation, or gender identity), national origin, age, disability, protected veteran status, genetic information, or any other characteristic protected by applicable federal, state, or local law.

We are committed to providing reasonable accommodations to qualified individuals with disabilities in all phases of the employment process, including the application and interview phase. If you require a reasonable accommodation to participate in the application or recruitment process, please inform your recruiter or contact our HR team.

SG2 Recruiting

About SG2 Recruiting

SG2 Recruiting is a recruiting process outsourcing (RPO) firm founded in 2013. Our team of experienced talent recruiters and sourcers delivers top talent to growing organizations in the Technology, Management Consulting, Defense and Intelligence sectors.

While most of our clients hire SG2 Recruiting for our network of cleared developers, systems (DevOps/Automation) engineers, and cybersecurity engineers, we enjoy working on a wide variety of skills to leverage our modern talent acquisition tech stack and continue to develop effective sourcing strategies!

Industry
HR & Recruiting
Company Size
1-10 employees
Headquarters
Fairfax, VA
Year Founded
2013
Social Media