CF CloudFrame Job Scanner Open Dashboard →
Verified Active Opening

Senior Vulnerability Engineer

Andurilindustries • Boston, Massachusetts, United States; Costa Mesa, California, United States; Washington, District of Columbia, United States

Job Description

<div class="content-intro"><p>Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril’s family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years.</p></div><section class="job-description"> <h2>ABOUT THE TEAM</h2> <p>Anduril Cyber is hiring a Vulnerability Engineer to discover novel vulnerabilities in hardware and software systems and turn that research into rigorous technical artifacts. The role is focused on original vulnerability discovery across embedded systems, firmware, applications, protocols, hardware/software boundaries, and system integrations.</p> <h2>ABOUT THE JOB</h2> <ul> <li>Find novel vulnerabilities in software, firmware, embedded systems, protocols, update paths, device interfaces, and hardware/software integration boundaries.</li> <li>Design and execute vulnerability research plans that combine code review, reverse engineering, fuzzing, emulation, dynamic instrumentation, hardware analysis, and adversarial testing.</li> <li>Build custom fuzzers, harnesses, emulators, instrumentation, triage workflows, and proof-of-concept tooling to turn research hypotheses into reproducible findings.</li> <li>Analyze root cause, exploitability, operational impact, and mitigation options for discovered vulnerabilities.</li> <li>Partner with reverse engineers, product security engineers, embedded software engineers, hardware engineers, and systems teams to validate findings and drive practical remediation.</li> <li>Write clear technical reports that include evidence, reproduction steps, exploitability assessment, impact, mitigations, and follow-on research opportunities.</li> <li>Design hardware-in-the-loop vulnerability experiments that combine software exploitation, protocol analysis, physical interfaces, and lab instrumentation.</li> <li>Develop tooling to automate experiment orchestration, device interaction, data collection, crash triage, and vulnerability reproduction.</li> </ul> <h2>REQUIRED QUALIFICATIONS</h2> <ul> <li>Strong experience discovering vulnerabilities in firmware, applications, network services, embedded Linux systems, drivers, protocols, IoT devices, or hardware-adjacent systems.</li> <li>Proficiency with one or more programming languages used for vulnerability research and tooling, such as Python, C, C++, Rust, or Go.</li> <li>Experience with fuzzing, harness development, crash triage, exploitability analysis, source-code review, binary analysis, or dynamic instrumentation.</li> <li>Ability to reason about memory corruption, logic flaws, authentication and authorization failures, unsafe parsing, concurrency issues, insecure update flows, and trust-boundary failures.</li> <li>Hands-on familiarity with Linux, embedded systems, networking, debugging, and common security research tooling.</li> <li>Ability to communicate vulnerability impact, reproduction steps, and mitigation options clearly to both research and engineering audiences.</li> <li>Demonstrated bias toward practical, mission-enabling security outcomes rather than purely theoretical findings.</li> <li>Must be eligible to obtain and maintain a U.S. security clearance.</li

Job Reference ID: CF-152898 • Posted on CloudFrame Job Scanner