Principal Vulnerability Researcher ($300k+/year + Sign-On Bonus)

Linthicum, Maryland

At Two Six Technologies, we build, deploy, and implement innovative products that solve the world’s most complex challenges today. Through unrivaled collaboration and unwavering trust, we push the boundaries of what’s possible to empower our team and support our customers in building a safer global future.

Compensation & Incentive Highlights

  • Target Base Salary: $300,000+ (Final salary is determined based on candidate qualifications and experience alignment with open roles)

  • Sign-On Bonus: Starting at $25,000 for qualified FSP hires.

  • Benefits & Flexible PTO: Comprehensive health, dental, and vision coverage, 401(k) matching, paid professional development, educational assistance, and flexible PTO with rollover options and annual payout opportunities.

Overview of Opportunity 

Join the Trusted Electronics & Effects business unit of Two Six Technologies, where you’ll provide strategic technical leadership in vulnerability research across hardware, software, and operational domains. Working alongside engineers, researchers, and clients, you’ll identify vulnerabilities, assess operational impacts, and develop effective countermeasures. Our fast-growing roster of government customers relies on us to deliver advanced security solutions, and we’re looking for a Principal Vulnerability Researcher to drive research programs and mentor technical teams.

This role requires regular on-site support at the Linthicum, Maryland customer site.

What you will do:

  • Lead the identification of vulnerabilities and attacks across hardware, software, personnel, logistics, procedures, and physical security, linking them to operational and mission impacts.
  • Identify vulnerabilities and potential attacks across hardware, software, procedures, logistics, and physical security of systems
  • Develop proof of concept (PoC) code for identified vulnerabilities
  • Reverse-engineer targeted embedded systems to identify vulnerabilities
  • Review source code looking for risks and vulnerabilities
  • Analyze the effects of vulnerabilities on mission outcomes and operational effectiveness.
  • Compare system attack techniques and propose operationally effective countermeasures
  • Produce reports, briefings, and perspectives on actual and potential attacks
  • Provide technical leadership on research efforts, prioritizing investigations, reviewing methodologies, and overseeing proof-of-concepts.
  • Mentor and guide junior engineers and researchers, reviewing technical approaches and fostering skill development.

What you will need (Basic Qualifications):

  • Doctorate in Computer Science, Computer/Electrical Engineering, or a related field and 7 years of relevant experience, OR Master’s degree and 9 years of relevant experience, OR Bachelor’s degree and 11 years of relevant experience, OR Associate’s degree and 13 years of relevant experience.
    • Relevant experience: computer/information systems design/development, programming, information/cyber/network security, reverse-engineering, vulnerability analysis, penetration testing, computer forensics, information assurance, or systems engineering
  • Proficiency in C/C++, Python, and at least one ISA (e.g. x86/ARM/MIPS)
  • Proficiency in Linux command-line environments
  • Experience using a decompiler such as IDA Pro, Binary Ninja, or Ghidra
  • Experience using vulnerability research tools such as emulators or fuzzers
  • Experience using a software debugger such as GDB or WinDbg
  • Ability to work on-site at Linthicum, Maryland customer site regularly.

Nice If You Have (Preferred):

  • Experience translating vulnerabilities into operationally relevant impact assessments and countermeasures.
  • Experience producing technical briefings for operational stakeholders
  • Experience using a hardware debugger
  • Experience with UART, SPI, I2C
  • Experience with common secure communications such as TLS or SSH 
  • Familiarity with embedded firmware, RTOS, or networked systems
  • Familiarity with high-side environments

Security Clearance:

  • Active TS/SCI clearance with Polygraph required

#LI-ZS1

#LI-ONSITE

 

Two Six Technologies is committed to providing competitive and comprehensive compensation packages that reflect the value we place on our employees and their contributions. We believe in rewarding skills, experience, and performance. Our offerings include but are not limited to, medical, dental, and vision insurance, life and disability insurance, retirement benefits, paid leave, tuition assistance and professional development.

The projected salary range listed for this position is annualized. This is a general guideline and not a guarantee of salary. Salary is one component of our total compensation package and the specific salary offered is determined by various factors, including, but not limited to education, experience, knowledge, skills, geographic location, as well as contract specific affordability and organizational requirements.

Salary Range

$300,000 - $325,000 USD

Create a Job Alert

Interested in building your career at Two Six Technologies? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...
Select...

Select...
Select...

For more information on clearances, review this document

Select...
Select...
Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Two Six Technologies’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...