1

Vulnerability Researcher Jobs in Washington (NOW HIRING)

Vulnerability Researcher: Use advanced systems to find zero-day (O-day) vulnerabilities. Responsible for analyzing, designing, and identifying programmatic behaviors. Have an opportunity to develop ...

We are seeking a Vulnerability Researcher to advance mission-critical cyber capabilities by uncovering vulnerabilities, analyzing complex systems, and developing innovative solutions that address our ...

As part of our elite team of security researchers, you'll work alongside CNO developers and hardware engineers, conducting cutting‑edge vulnerability research on complex, real‑world targets. Our ...

New

Showing results 41-60

Vulnerability Researcher information

See Washington salary details

$34K

$128.1K

$186.3K

How much do vulnerability researcher jobs pay per year?

As of Aug 20, 2026, the average yearly pay for vulnerability researcher in Washington is $128,099.00, according to ZipRecruiter salary data. Most workers in this role earn between $75,900.00 and $174,400.00 per year, depending on experience, location, and employer.

What is a vulnerability researcher?

A Vulnerability Researcher is a cybersecurity professional who identifies, analyzes, and reports security flaws in software, hardware, and networks. They use reverse engineering, fuzzing, and static analysis techniques to discover vulnerabilities before malicious actors can exploit them. Their work helps improve security by collaborating with developers and security teams to implement patches and mitigations. Often, they contribute to responsible disclosure programs or work for organizations focused on threat intelligence and cybersecurity defense.

What does a vulnerability researcher do?

A typical day for a Vulnerability Researcher involves researching the latest security vulnerabilities, analyzing software or hardware for potential weaknesses, and developing proof-of-concept exploits or mitigation techniques. You may spend time reviewing code, using reverse engineering or fuzzing tools, and documenting your findings for technical and non-technical stakeholders. Collaboration with security teams, software engineers, and sometimes external vendors is common to ensure vulnerabilities are addressed properly. The work is dynamic, often requiring you to stay updated on emerging threats and continuously refine your research skills.

What are the key skills and qualifications needed to thrive as a vulnerability researcher?

To thrive as a Vulnerability Researcher, you need a strong background in computer science, proficiency in programming languages like Python or C/C++, and an in-depth understanding of operating systems and networking. Familiarity with penetration testing tools (such as Metasploit or Burp Suite), reverse engineering software, and certifications like OSCP or CEH are commonly sought after. Analytical thinking, attention to detail, and strong problem-solving and communication skills distinguish top performers in this field. These abilities are crucial for identifying and analyzing security weaknesses, communicating findings effectively, and helping organizations proactively manage cybersecurity risks.

What are the most commonly searched types of Vulnerability Researcher jobs in Washington?

The most popular types of Vulnerability Researcher jobs in Washington are:

What are popular job titles related to Vulnerability Researcher jobs in Washington?

For Vulnerability Researcher jobs in Washington, the most frequently searched job titles are:

Infographic showing various Vulnerability Researcher job openings in Washington as of August 2026, with employment types broken down into 96% Full Time, and 4% Part Time. Highlights an 68% In-person, 8% Hybrid, and 24% Remote job distribution, with an average salary of $128,099 per year, or $61.6 per hour.

Senior Vulnerability Researcher

Two Six Technologies

Arlington, VA • On-site

Full-time

Re-posted 3 days ago


Job description

Overview of Opportunity 

Join the Communications Systems division at Two Six Technologies in Arlington, Virginia, where we push the boundaries of software and firmware reverse engineering to uncover vulnerabilities in wireless and embedded systems. As part of our elite team of security researchers, you'll work alongside CNO developers and hardware engineers, conducting cutting-edge vulnerability research on complex, real-world targets.

Our government customers rely on us to deliver mission-critical security solutions, and we're looking for a Senior Vulnerability Researcher who thrives on reverse engineering embedded systems, discovering security weaknesses, and developing innovative proof-of-concept exploits. If you're passionate about wireless security, embedded firmware analysis, and making an impact on national security, we want you on our team.

What you will do:

  • Take on complex technical problems for which there is often no known answer
  • Develop tools and techniques to assist/automate tasks that traditionally require significant manual reverse engineering effort, including binary patching, Vulnerability research, and Binary fingerprinting
  • Develop proof-of-concept exploits for discovered vulnerabilities following DevOps best practices for keeping code bases organized and maintainable.
  • Analyze firmware, software protections, and wireless protocols to uncover security flaws.
  • Follow-on development to productize results/PoCs or handoff to developers for productization
  • Collaborate closely with CNO developers, vulnerability researchers, and hardware engineers in a fast-paced, small-team environment.

What You'll Need (Basic Qualifications):

  • Bachelor's (or higher) degree in Computer Science, Computer/Electrical Engineering, or a related field (or equivalent practical experience).
  • Extensive experience with programming/scripting languages in C/C++, Python, and Linux command-line environments.
  • Experience with reverse engineering and vulnerability research, using tools such as IDA Pro, Binary Ninja, or Ghidra.
  • Expertise in one or more of the following:
    • Firmware analysis (ARM, MIPS, PowerPC, RTOS).
    • Firmware rehosting using emulation tools such as QEMU
    • Fuzzing and exploit development.
    • Binary obfuscation and anti-analysis techniques.
    • Wireless protocols and radio signal analysis.
    • File system forensics and fault injection frameworks.

Nice to Have (Preferred):

  • Experience scripting with Binary Ninja API or Ghidra.
  • Experience in embedded software development using C/C++ for RTOS or Linux environments.
  • Knowledge of cryptographic security and secure boot mechanisms.
  • Hands-on experience working with hardware debugging tools, JTAG/SWD, or software-defined radio (SDR) frameworks.
  • Familiarity with digital signal processing, wireless security protocols, RF signal processing, and side-channel analysis.
  • Client-facing experience in technical roles.
  • Active TS/SCI with Polygraph preferred.

Security Clearance:

  • Active Top Secret Clearance is required with the ability to obtain and maintain a TS/SCI security clearance 

#LI-ZS1

#LI-ONSITE