Position Title
Cyber Vulnerability Researcher
Position Classification
Exempt
Position Type
On-site, full-time and scheduled to work standard business hours from 8:00 a.m. to 5:00 p.m.
Work Location
MCTSSA Cyber Branch – Camp Pendleton, California
Position Description
The Cyber Vulnerability Researcher delivers advanced vulnerability research and low-level exploit development capability in support of the MCTSSA Cyber Branch’s adversarial testing mission. This position extends the team’s offensive depth beyond tool-based penetration testing into original vulnerability discovery, binary analysis, and exploitation of embedded systems, real-time operating systems, and custom platform architectures that may not be assessable through commercial off-the-shelf testing frameworks alone.
The incumbent works in close coordination with the Vulnerability Assessment Analyst and Penetration Tester team, ensuring that research-derived findings are translated into actionable assessment products and technically defensible remediation recommendations for Program Offices.
Essential Position Functions
-
Conduct original vulnerability research using static and dynamic analysis tools including Ghidra, IDA Pro, WinDbg, OllyDbg, and gdb to identify exploitable weaknesses in Marine Corps system software, firmware, and embedded platforms.
-
Develop and execute fuzz testing campaigns against target systems and applications to discover previously unknown vulnerabilities; document findings with sufficient technical detail for replication and remediation.
-
Research and analyze CVEs, publicly known exploits, and adversary TTPs relevant to assessed Marine Corps systems; synthesize findings into Vulnerability Survey Reports for requesting Program Offices within one to two weeks of request.
-
Develop proof-of-concept exploits against discovered vulnerabilities in isolated research environments to validate exploitability and quantify mission impact for Program Office stakeholders.
-
Analyze assembly code across target architectures (x86, x64, ARM, MIPS, PowerPC) to identify logic flaws, memory corruption vulnerabilities, and bypass opportunities for common mitigation techniques including DEP, ASLR, and stack canaries.
-
Conduct vulnerability research against embedded systems, real-time operating systems (VxWorks, RTOSs), and custom operating systems found in Marine Corps weapons systems and C5ISR platforms that are not assessable through standard penetration testing tools.
-
Collaborate with the Vulnerability Assessment Analyst and Penetration Tester team to integrate research-derived exploits and findings into operational assessment events, validating discovered vulnerabilities against live system environments where approved.
-
Automate vulnerability research and analysis processes using Python, Perl, Ruby, or C/C++ to accelerate discovery cycles and improve repeatability of research methodologies.
-
Document and communicate technical research results to both technical and non-technical audiences, including Program Offices, system engineers, and DCO stakeholders.
-
Develop presentation material and written technical research reports documenting vulnerability research findings, exploit development methodology, attack path analysis, and recommended mitigations, in compliance with applicable Security Classification Guides.
-
Stay current with emerging vulnerability research techniques, reverse engineering methodologies, exploit development frameworks, and adversary tradecraft; apply this knowledge to advance the Cyber Branch’s research capability.
-
Conduct static and dynamic analysis of software source code repositories and executables; identify CWEs, insecure coding patterns, and logic flaws exploitable by an adversary.
-
Produce Code Review Reports identifying specific vulnerabilities by location and severity, assessing potential mission impact, and providing remediation recommendations and secure coding best practices.
-
Deliver a summary Security Posture Assessment of each reviewed software component suitable for program management decision-making and inclusion in test and evaluation documentation.
-
Provide representation at technical working groups, program meetings, and coordination events as directed by the Government.
-
Perform additional duties as assigned by the Program Manager.
Competencies for the role
Ability to code in C or C++, and use a scripting language such as Python, Perl, or Ruby.
Experience with PC and embedded systems architecture, including boot processes and OS internals, and five (5) or more years of experience with Ghidra for vulnerability research.
Advanced understanding of network protocols, and experience with one or more assembly languages (x86, x64, ARM, MIPS, PowerPC, etc.) and debuggers (WinDbg, OllyDbg, gdb, etc.).
Experience with vulnerability research on one or more operating systems: Android, Windows, Linux, VxWorks, RTOSs, or other custom operating systems.
Knowledge of common mitigation techniques (DEP, ASLR, stack canaries, etc.) and fuzzing techniques, with the ability to engineer and execute fuzz tests.
Desired: experience with IDA Pro plugin and script development; knowledge of wired and wireless network protocol structures; active participation in CTF or software hacking competitions.
Desired: experience developing on and debugging embedded systems, real-time operating systems, and FPGAs; ten (10) or more years of low-level systems programming, analysis, and reverse engineering experience.
Desired: experience leading and tasking teams of engineers through technical design and delivery; advanced certifications such as OSED, OSEE, GREM, or equivalent.
Physical Requirements for the role
This position is primarily sedentary and performed in an office or laboratory setting, requiring extended periods of computer use, close visual attention to technical detail, and the ability to sit or stand for extended periods. Occasional lifting of computer or lab equipment up to 25 lbs. may be required.
Reports To
MCTSSA Cyber Branch Lead / Assigned Program Manager
Supervisory responsibilities
None; may provide technical mentorship and guidance to junior researchers and engineers as directed.
Work Environment
The work environment is a standard office and secured laboratory setting, which may include access to classified systems and materials in accordance with applicable Security Classification Guides.
Security Clearance Requirements
Active DoD Secret clearance required; ability to obtain and maintain Top Secret is preferred.
Travel Requirements
Travel is anticipated to be less than 10% within the Continental United States.
Compensation
Commensurate with experience and qualifications.
Lumbee Holdings is an Equal Opportunity Employer. We do not discriminate in employment based on race, color, religion, sex (including pregnancy, sexual orientation, or gender identity), national origin, age, disability, protected veteran status, or any other status protected by applicable federal, state, or local law.
Note: This summary is not intended to be a complete description of all benefits. Employees will receive detailed information about benefit plan terms, conditions, and eligibility during onboarding. These statements are intended to describe the general nature and level of work involved for this job. It is not an exhaustive list of all responsibilities, duties, and skills required of this job.