1

Hardware Vulnerability Research Jobs (NOW HIRING)

Lead Vulnerability Researcher

Herndon, VA · On-site

$175K - $220K/yr

... lead vulnerability research across hardware, software, and operational systems. Working side by side with engineers and security researchers, you'll guide investigations, identify critical ...

Perform vulnerability research / reverse engineering (VR/RE) against a variety of hardware and software targets * Allocate tasking to support larger-scale cyber tool development * Perform testing and ...

Perform vulnerability research / reverse engineering (VR/RE) against a variety of hardware and software targets * Allocate tasking to support larger-scale cyber tool development * Perform testing and ...

Lead Vulnerability Researcher

MD · Remote

$175K - $220K/yr

Join us at GrammaTech where you'll lead vulnerability research across hardware, software, and operational systems. Working side by side with engineers and security researchers, you'll guide ...

Hardware Reverse Engingeer

Herndon, VA · On-site

$127K - $167K/yr

Conduct vulnerability research on hardened systems and architectures. * Draft technical reports related to the function, characteristics, and any potential vulnerabilities of the assessed hardware ...

Hardware Reverse Engingeer

Herndon, VA · On-site

$127K - $167K/yr

Conduct vulnerability research on hardened systems and architectures. * Draft technical reports related to the function, characteristics, and any potential vulnerabilities of the assessed hardware ...

Showing results 41-60

Hardware Vulnerability Research information

See salary details

$51K

$146.2K

$196.5K

How much do hardware vulnerability research jobs pay per year?

As of Sep 9, 2026, the average yearly pay for hardware vulnerability research in the United States is $146,230.00, according to ZipRecruiter salary data. Most workers in this role earn between $123,500.00 and $163,000.00 per year, depending on experience, location, and employer.

What is hardware vulnerability research?

Hardware vulnerability research involves identifying, analyzing, and addressing security weaknesses in physical computer components such as CPUs, memory chips, and embedded devices. Researchers in this field use a combination of reverse engineering, side-channel analysis, and testing methodologies to discover flaws that could be exploited by attackers. The goal is to uncover vulnerabilities before malicious actors do and to work with manufacturers to develop patches or mitigations. This research is critical for ensuring the security of devices ranging from servers to IoT products.

What are the key skills and qualifications needed to thrive as a hardware vulnerability researcher?

To thrive as a Hardware Vulnerability Researcher, you need a strong background in computer engineering, embedded systems, and cybersecurity, often supported by degrees in electrical engineering or computer science. Familiarity with hardware description languages (HDL), reverse engineering tools, logic analyzers, and certifications like CISSP or OSCP are commonly required. Analytical thinking, problem-solving, and clear communication are essential soft skills for effectively identifying vulnerabilities and collaborating with cross-functional teams. These competencies are crucial for detecting and mitigating security threats in hardware, ensuring device integrity and protecting sensitive data.

What are some of the common challenges faced by professionals in hardware vulnerability research roles?

Professionals in hardware vulnerability research often encounter challenges such as staying ahead of rapidly evolving attack techniques and understanding complex, proprietary hardware architectures. The role requires regularly reverse-engineering hardware components and firmware, which can be time-consuming and demand a high level of technical expertise. Collaborating with cross-disciplinary teams, such as software security analysts and hardware engineers, is essential to ensure thorough threat assessments and effective mitigation. Researchers must also keep up with the latest academic findings and industry trends to stay effective in identifying and addressing new vulnerabilities.

What is the difference between Hardware Vulnerability Research vs Hardware Security Engineer?

AspectHardware Vulnerability ResearchHardware Security Engineer
CredentialsKnowledge of hardware design, security protocols, certifications like CISSP or CEH beneficialSimilar credentials, often with security certifications and hardware expertise
Work EnvironmentResearch labs, cybersecurity firms, academiaCorporate security teams, product development, hardware manufacturing companies
Industry UsageIdentifying vulnerabilities, analyzing hardware flaws, developing exploitsImplementing security measures, designing secure hardware, mitigating vulnerabilities

Hardware Vulnerability Research focuses on discovering and analyzing hardware flaws, while Hardware Security Engineers work on securing hardware systems and fixing vulnerabilities. Both roles require hardware knowledge and security certifications but differ in their primary objectives and work environments.

Infographic showing various Hardware Vulnerability Research job openings in the United States as of September 2026, with employment types broken down into 1% Internship, 1% As Needed, 88% Full Time, 9% Part Time, and 1% Contract. Highlights an 79% Physical, 3% Hybrid, and 18% Remote job distribution, with an average salary of $146,230 per year, or $70.3 per hour.

Lead Vulnerability Researcher

Herndon, VA • On-site

GrammaTech
Software Development • 51 - 200 employees

$175K - $220K/yr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 5 days ago


Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Lead Vulnerability Researcher

Herndon, VA, US

7 days ago Requisition ID: 1015

Join us at GrammaTech where you’ll lead vulnerability research across hardware, software, and operational systems. Working side by side with engineers and security researchers, you’ll guide investigations, identify critical vulnerabilities, and develop countermeasures with operational impact. Our fast-growing roster of government customers relies on us to deliver advanced security solutions, and we’re looking for a Lead Vulnerability Researcher to provide technical leadership and mentorship.

This role requires regular on-site support at the Linthicum, Maryland customer site or our headquarters in Herndon VA

What you will do:

  • Lead the identification of vulnerabilities and attacks across hardware, software, personnel, logistics, procedures, and physical security.
  • Develop proof of concept (PoC) code for identified vulnerabilities
  • Reverse-engineer targeted embedded systems to identify vulnerabilities
  • Review source code looking for risks and vulnerabilities
  • Analyze the effects of vulnerabilities on mission outcomes and operational effectiveness.
  • Compare system attack techniques and propose operationally effective countermeasures
  • Produce reports, briefings, and perspectives on actual and potential attacks
  • Provide technical leadership on research efforts, prioritizing investigations, reviewing methodologies, and overseeing proof-of-concepts.
  • Mentor and guide junior engineers and researchers, reviewing technical approaches and fostering skill development.

What you will need (Basic Qualifications):

  • Doctorate in Computer Science, Computer/Electrical Engineering, or a related field and 4 years of relevant experience, OR Master’s degree and 6 years of relevant experience, OR Bachelor’s degree and 8 years of relevant experience, OR Associate’s degree and 10 years of relevant experience.
    • Relevant experience: computer/information systems design/development, programming, information/cyber/network security, reverse-engineering, vulnerability analysis, penetration testing, computer forensics, information assurance, or systems engineering
  • Proficiency in C/C++, Python, and at least one ISA (e.g. x86/ARM/MIPS)
  • Proficiency in Linux command-line environments
  • Experience using a decompiler such as IDA Pro, Binary Ninja, or Ghidra
  • Experience using vulnerability research tools such as emulators or fuzzers
  • Experience using a software debugger such as GDB or WinDbg

Nice If You Have (Preferred):

  • Experience translating vulnerabilities into operationally relevant impact assessments and countermeasures.
  • Experience producing client-facing technical briefings for operational stakeholders
  • Experience using a hardware debugger
  • Experience with UART, SPI, I2C
  • Experience with common secure communications such as TLS or SSH
  • Familiarity with embedded firmware, RTOS, or networked systems
  • Familiarity with high-side environments

Security Clearance:

  • Active TS/SCI clearance ( Herndon) with Polygraph required at customer site in Maryland

The anticipated base salary range for this position is $175,000–$220,000 annually. This range reflects the Company's good-faith estimate at the time of posting. Final compensation will be determined based on a variety of factors, including the scope and level of the role, relevant experience, technical expertise, education, and other job-related qualifications.

GrammaTech offers a comprehensive total rewards package designed to support the health, well-being, and financial security of our employees. Benefits include medical, dental, and vision insurance; short- and long-term disability coverage; life insurance; and a 401(k) retirement plan with company contributions. Employees are also eligible for paid holidays, paid time off (PTO), sick and personal leave, annual merit increases, and performance-based bonus opportunities.

GrammaTech, Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status. GrammaTech is committed to providing reasonable accommodations to qualified individuals with disabilities throughout the application and hiring process. Applicants requiring accommodation should contact Human Resources.

#J-18808-Ljbffr