Senior Firmware Security Researcher
MITRE · McLean, VA · Yesterday
Information Technology$127k–$159k/yrFull-time
Roles & Responsibilities
- Develop and apply technical expertise in reverse engineering software binaries/embedded firmware.
- Prototype technical capabilities in hardware and software, including proof-of-concept software exploit development.
- Research emerging threats to embedded systems and countermeasures.
- Provide technical leadership within project teams and help define research approaches that deliver impactful solutions for our customers.
- Design, develop, and lead key efforts to build software infrastructure and tools that enable, accelerate, and scale reverse engineering, vulnerability research, and security capability development for embedded systems.
- Communicate technical approach, risks, and results to MITRE program leaders and customers.
- Mentor junior engineers in reverse engineering, vulnerability research, and capability development.
Basic Qualifications
- Bachelor’s degree in Electrical or Computer Engineering, Computer Science or similar field with 5 years of related experience; Master’s degree in the same with 3 years of related experience; or PhD in the same with 3 years of related experience.
- Expertise in reverse engineering software binaries/embedded firmware and practical experience with disassemblers, decompilers, firmware unpacking, common executable file formats, and debuggers.
- Expertise in reverse engineering for one or more embedded processor architectures, preferably ARM.
- Expertise in modern binary exploitation techniques and countermeasures with practical experience in software vulnerability analysis and exploitation development.
- Experience developing software with C/C++ and Python.
- Experience developing low-level software (e.g., embedded systems/microcontrollers, kernels, and/or device drivers).
- Effective oral and written communication skills.
- US citizen with active Secret security clearance.
- A minimum of 3 days on site each week.
Preferred Qualifications
- Bachelor’s degree in Electrical or Computer Engineering, Computer Science or similar field with 8 years of related experience; Master’s degree in the same with 6 years of related experience; or PhD in the same with 3 years of related experience.
- Possess an active Top Secret security clearance.
- Experience leading teams developing or evaluating secure embedded systems.
- Experience with one or more of the following technical areas:
- Fuzz testing software applications or embedded firmware.
- Instrumentation/debug of embedded software or firmware.
- Firmware rehosting and peripheral modeling.
- Symbolic analysis.
- Linux kernel, kernel derivators, or real-time operating systems.
- Commercial embedded and/or hardware security technologies such as ARM TrustZone, Trusted Platform Modules, Boot Guard, Secure Boot, etc.