Senior Vulnerability EngineerPosted today$253K

The opportunity

Anduril Cyber is hiring a Vulnerability Engineer to discover novel vulnerabilities in hardware and software systems and turn that research into rigorous technical artifacts. The role is focused on original vulnerability discovery across embedded systems, firmware, applications,…

What you'll do

  • Find novel vulnerabilities in software, firmware, embedded systems,: protocols, update paths, device interfaces, and hardware/software integration boundaries.

  • Design and execute vulnerability research plans that combine code review,: reverse engineering, fuzzing, emulation, dynamic instrumentation, hardware analysis, and adversarial testing.

  • Build custom fuzzers, harnesses, emulators, instrumentation, triage: workflows, and proof-of-concept tooling to turn research hypotheses into reproducible findings.

  • Analyze root cause, exploitability, operational impact, and mitigation options for discovered vulnerabilities.

  • Partner with reverse engineers, product security engineers, embedded software: engineers, hardware engineers, and systems teams to validate findings and drive practical remediation.

  • Write clear technical reports that include evidence, reproduction steps,: exploitability assessment, impact, mitigations, and follow-on research opportunities.

What they're looking for

  • Experience finding vulnerabilities in boot chains, firmware update: mechanisms, device identity systems, cryptographic integrations, anti-tamper mechanisms, or programmable-logic-backed systems.
  • Experience with advanced vulnerability research techniques such as: coverage-guided fuzzing, symbolic execution, differential testing, fault injection, protocol state modeling, or hardware-in-the-loop testing.
  • Familiarity with reverse-engineering tools such as Ghidra, IDA Pro, Binary: Ninja, QEMU, Frida, gdb/lldb, or comparable frameworks.
  • Background in embedded, aerospace, robotic, RF, or cyber-physical systems and: the ways their threat models differ from conventional enterprise software.
  • Track record of producing high-quality vulnerability research artifacts,: internal tooling, conference-quality writeups, CVEs, or comparable technical outputs.
  • Experience applying side-channel analysis, fault injection, black-box: testing, or hardware-assisted fuzzing to embedded systems.
  • Experience with RF protocols, cryptographic protocol analysis, FPGA/SoC: security, signal processing, or board-level vulnerability assessment.
  • Demonstrated technical leadership, mentorship, or ownership of complex: vulnerability research efforts from hypothesis through reproducible technical artifact.