Senior Embedded Vulnerability Researcher

Draper
Cambridge, MA

Overview:

Draper is an independent, nonprofit research and development company headquartered in Cambridge, MA. The 2,000+ employees of Draper tackle important national challenges with a promise of delivering successful and usable solutions. From military defense and space exploration to biomedical engineering, lives often depend on the solutions we provide. Our multidisciplinary teams of engineers and scientists work in a collaborative environment that inspires the cross-fertilization of ideas necessary for true innovation. For more information about Draper, visit

Job Description Summary:

Draper’s Offensive Cyber Security Group is looking for dedicated individuals to develop tailored solutions to meet our DoD and IC Sponsor directives. Our organization's not-for-profit status ensures a capability-driven focus on the United States of America's national interests that allows us to address some of our Nation's most pressing challenges. Due to the variety of USG organizational needs, our technical efforts and opportunities vary from conventional cyber operations enablement tooling to embedded vulnerability research and exploit development on a wide range of devices and systems.

Job Description:

  • Duties/Responsibilities

    • Assess hardware and software for security vulnerabilities using a breadth of technologies and techniques.
    • Develop software that meets behavior and security requirements for tailored applications.
    • Integrate software capabilities with other tasks or groups to improve performance or behavior requirements.
    • Create new tools and systems to detect and exploit vulnerabilities and system weaknesses.
    • Document nominal application and system functionality, in addition to implemented changes.
    • Drive solutions to complex problems with limited direction – contribute to requirements. development, propose ways forward, and adapt appropriately to changes in requirements.
    • Provides insight and suggest design modifications based on analysis outcomes, and to apply analysis techniques across a range of technical disciplines.
    • Identifies program/system-level technical risks and develop and execute mitigation strategies.
    • Actively mentor less experienced engineers and provide thoughtful, constructive feedback.
    • Performs other related duties as assigned.

    Skills/Abilities

    • Curiosity-driven approach to solving complex, customer-driven problems as part of a multi-disciplinary team.
    • Collaborate and communicate effectively and openly with multi-disciplinary program team members, program leadership, and non-technical personnel.
    • Be a team player able to work in a fast-paced environment with the ability to balance multiple competing tasks and demands.


    Education

    Requires a bachelor's in computer science, computer engineering, or related field.



    Experience
    5-10 years experience in Cybersecurity or related field is required.


Additional Job Description:

Program Analysis, Reverse Engineering, and Vulnerability Research:

  • Proficiency with modern program analysis methodologies and techniques
  • Reverse-engineering assessment techniques for firmware or embedded systems
  • Familiarity with binary file and filesystem structures and formats
  • Hands-on proficiency with reverse engineering tooling such as: Ghidra, IDA, GDB, RR
  • Hands-on proficiency with physical instrumentation or hardware modification, soldering
  • Experience with JTAG/SWD/BDM, and eMMC/NAND/SPI flash data extraction
  • Exploitation techniques for embedded devices across platforms and architectures
  • Familiarity of network stack and internals
  • Familiarity of operating system internals throughout user mode, kernel mode, and during boot processes for at least one of the following: GNU/Linux, RTOS
  • Familiarity with architectures and assembly: x86, ARM, Hexagon, PowerPC

Languages and Development:

  • Proficiency with programming languages such as: C, C++, Python, Java
  • Familiarity with scripting languages such as: Bash, Powershell
  • Familiarity in development environments for GNU/Linux or Windows

Leadership and Business Development:

  • Successful history in authoring of technical proposals and documents
  • Leadership in advanced R&D initiatives, including government-funded projects
  • Leadership of critical programs with more than two full time staff members
  • Proficient in teamwork and communication with diverse audiences

Preferred Qualifications:

  • Experience with side channel attacks (glitching) to place components and/or devices into altered states to bypass protections.
  • Familiarity with custom filesystem extraction and modification, removal and/or regeneration of OOB/CRC data.
  • Familiarity with bus and protocol analysis.

Applicants selected for this position must be required to obtain and maintain a government TS/SCI security clearance.

Connect With Draper for Future Opportunities! If you don't find the right posting in our Career Opportunities, you may submit your resume for future consideration.

Job Location - City:

Cambridge

Job Location - State:

Massachusetts

Job Location - Postal Code:

02139-3563

The US base salary range for this full-time position is

$82,300.00 - $205,750.00

Our salary ranges are determined by role, level, and location. The range displayed on each job posting reflects the minimum and maximum target salaries for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Union ranges will be in compliance with the collective bargaining agreement's approved rates by location and role. Your recruiter can share more about the specific salary range for your preferred location during the hiring process. Please note that the compensation details listed in US role postings reflect the base salary only, and does not include bonuses or benefits.

Our work is very important to us, but so is our life outside of work. Draper supports many programs to improve work-life balance including workplace flexibility, employee clubs ranging from photography to yoga, health and finance workshops, off site social events and discounts to local museums and cultural activities. If this specific job opportunity and the chance to work at a nationally renowned R&D innovation company appeals to you, apply now

Draper is committed to creating an inclusive environment. We understand the value of inclusivity and its impact on a high-performance culture. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, national origin, veteran status, or genetic information. Draper is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation, please contact [email protected].

Posted 2025-12-15

Recommended Jobs

English teacher in Boston, MA

Global LT
Boston, MA

Join the Global LT community and help provide language lessons to business professionals and their families worldwide. We are hiring an English Language Teacher to provide in-person lessons to ou…

View Details
Posted 2025-11-21

Blow Molding Technician

Amcor
Somerville, MA

**Overview** **Accelerate the possible by joining a winning Amcor team that's transforming the packaging industry and improving lives around the world.** At Amcor, we unpack possibility through our in…

View Details
Posted 2025-11-26

Full Time Hospitalist Job FALL RIVER, MA

Curare Group, Inc. Curare Group, Inc.
Fall River, MA

Explore this stellar opportunity in southeastern Massachusetts within a large, physician-owned and managed multi-specialty group. The area has excellent schooling options and every type of housing sit…

View Details
Posted 2025-11-07

NetSuite Implementation Senior Consultant (Financials)

Deloitte
Boston, MA

Technical Accounting and Reporting - Senior Consultant Are you a detail-oriented, inquisitive individual who enjoys coming up with innovative solutions? We are in the process of expanding Deloitte's A…

View Details
Posted 2025-11-13

Senior EHS Specialist

ProAmpac
West Chesterfield, MA

ProAmpac is a leading global flexible packaging company with a strong safety culture. Our Westfield, MA Production Site, is currently seeking an experienced EHS Specialist that excels in a fast-pac…

View Details
Posted 2025-12-15

Enterprise Account Executive, Life Sciences

Neon
Massachusetts

SLSQ426R845 As an Enterprise Account Executive at Databricks, you are a strategic sales professional experienced in selling into large Medical Device or Pharmaceutical accounts. You know how to sel…

View Details
Posted 2025-11-20

Building Automation and Mechanical Service Sales Consultant

Brazed Mechanical
Canton, MA

Building Automation and Mechanical Service Sales Consultant Let’s Start with You Do you cultivate executive relationships, navigate complex facilities, and close tailored Preventative Maintenan…

View Details
Posted 2025-12-16

NPI DFM Process Development Engineer (Teradyne, North Reading, MA)

Teradyne
North Reading, MA

We are the global test and automation specialists, powering next-generation technologies through sophisticated solutions. Behind every electronic device you use, Teradyne's test technology ensures y…

View Details
Posted 2025-11-27

Prep Supply

Dessert Holdings Inc.
Newburyport, MA

We are searching for two2nd ShiftWarehouse Prep Supply Associates to join our Warehouse team in Newburyport, MA at Diannes Fine Desserts, a subsidiary of Dessert Holdings. Monday Thursday 3:00 pm - 1:…

View Details
Posted 2025-10-17

Vice President, Human Resources Business Partner

Lensa
Burlington, MA

Lensa is a career site that helps job seekers find great jobs in the US. We are not a staffing firm or agency. Lensa does not hire directly for these jobs, but promotes jobs on LinkedIn on behalf of …

View Details
Posted 2025-12-15