Find Jobs
Find Jobs Near You – Available Work in Your Location
Junior Vulnerability Researcher (Cloud & Containers)
Career Insights for Vulnerability Analyst / Penetration Tester
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on New Jersey data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.
$124,644 / year median in New Jersey
+3% projected growth
Job Description
Job Title:
Junior Vulnerability Researcher (Cloud & Containers)Job Category:
Engineering Time Type:
Full time Minimum Clearance Required toStart:
None Employee Type:
Regular Percentage of Travel Required:
None Type of Travel:
None •The Opportunity:
We are seeking a Vulnerability Researcher with a strong background in systems-level engineering and a passion for cloud security. This role is for a practitioner who has moved beyond the basics and is ready to take ownership of research tasks within the "DNA of the cloud." You will apply your knowledge of container internals and binary analysis to hunt for escapes and logic flaws in Kubernetes environments. You will work as part of a high-performing team, executing complex vulnerability research and developing automated tools to secure national cybersecurity infrastructure.Responsibilities:
- Execute research into OCI runtimes (runc, crun) and Linux kernel primitives (namespaces, cgroups) to identify breakout and privilege escalation paths.
- Perform static and dynamic analysis on compiled binaries (Go, Rust, or C++) to map logic and identify potential security vulnerabilities.
- Develop and maintain custom fuzzing harnesses (e.g., AFL++, libFuzzer) to stress-test gRPC interfaces and microservice components.
- Use symbolic and concolic execution tools (e.g., Angr, Manticore) to automate the discovery of complex execution paths.
- Analyze containerized environments and system initialization logic to identify and document potential attack surfaces.
- Write custom Python3 scripts to automate research workflows, including firmware unpacking and memory analysis.
- Generate detailed technical reports and documentation for discovered vulnerabilities and research methodology.
Qualifications:
Required:
- 3-5 years of professional experience in vulnerability research, reverse engineering, or systems-level software development.
- Familiarity with container orchestration (Kubernetes) and the OCI runtime specification.
- Working knowledge of Linux kernel internals, specifically regarding container isolation (namespaces/cgroups).
- Proficiency in software development and strong scripting skills.
- Hands-on experience with debugging tools like GDB and packet analysis tools like Wireshark.
- Demonstrated ability to conduct independent technical research and document complex findings.
- Must be a US Citizen and able to obtain/maintain a security clearance
Desired:
- An active TS SCI clearance.
- Experience with disassembly and decompilation tools such as IDA Pro, Ghidra, or Binary Ninja.
- Previous experience with fuzzing frameworks and vulnerability discovery in distributed systems.
- Understanding of x86 or ARM assembly language.
- Experience with cloud provider security (AWS, Azure, or GCP).
- Relevant security certifications or a history of participation in advanced CTF competitions.