Why This Role Stands Out
Leverage your expertise in binary patch diffing and reverse engineering to contribute to critical national security missions, with the flexibility of a hybrid work environment and a highly competitive salary of $150,000 - $215,000. This mid-senior role is ideal for analytical thinkers passionate about software security validation, offering significant opportunities for growth and impact within a growing, intelligent team. Apply today to join GrammaTech and advance your career in a rewarding field.
Quick Overview
Job Description
GrammaTech is actively seeking a Software Vulnerability Analyst to join our team in Linthicum, Maryland. The team is composed of intelligent individuals, passionate about binary patch diffing, root-cause vulnerability analysis, and software security validation. The team is growing and looking for someone with a vulnerability analysis and reverse engineering background who has an understanding of how to analyze software patches, verify security fixes, and confirm vulnerability mitigation across target systems.
If you are actively using Ghidra, IDA Pro, BinDiff, and dynamic analysis tools, the team wants to talk to you!
What you will do: • Evaluate software and firmware patches to perform binary patch diffing and root-cause vulnerability analysis in support of national security research missions. • Work under minimal supervision with latitude for independent judgment to confirm patch integrity and ensure security fixes completely address target vulnerabilities. • Document detailed analytical findings, validate security fixes, and assist with integrating AI-assisted software verification tools into security analysis workflows.
What you will need (basic qualifications) • Demonstrated experience in static and dynamic reverse engineering, binary patch diffing (e.g., BinDiff, Diaphora), and software vulnerability analysis. • Hands-on proficiency with disassembly tools (Ghidra, IDA Pro, or Binary Ninja) and software debuggers (GDB, WinDbg). • Proven track record performing root-cause analysis on software vulnerabilities and validating patch mitigation effectiveness. • Strong programming and scripting skills in C, C++, and Python within Linux environments.
Nice to have (preferred) • Experience applying AI/ML models or LLM frameworks to software code analysis, vulnerability discovery, or patch verification. • Familiarity with dynamic instrumentation frameworks (Frida, DynamoRIO) or automated fuzzing engines. • Knowledge of operating system security mitigations (ASLR, DEP, CFI, Stack Canaries) and common vulnerability patterns (CWEs).
Security Clearance: • Active TS/SCI clearance with Polygraph required The anticipated base salary range for this position is $150,000–$215,000 annually. This range reflects the Company's good-faith estimate at the time of posting. Final compensation will be determined based on a variety of factors, including the scope and level of the role, relevant experience, technical expertise, education, and other job-related qualifications. GrammaTech offers a comprehensive total rewards package designed to support the health, well-being, and financial security of our employees.
Benefits include medical, dental, and vision insurance; short- and long-term disability coverage; life insurance; and a 401(k) retirement plan with company contributions. Employees are also eligible for paid holidays, paid time off (PTO), sick and personal leave, annual merit increases, and performance-based bonus opportunities. GrammaTech, Inc. is an
Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status. GrammaTech is committed to providing reasonable accommodations to qualified individuals with disabilities throughout the application and hiring process. Applicants requiring accommodation should contact Human Resources.
Similar jobs
- KA
AI Security Engineer
NewKaltechsoft
United States🇺🇸Remote22 hours agoAWSOWASPAzure+2Technology - PE
Mid All Source Analysis CI Cyber Analysis Support (Cyber Analyst with Security Clearance
NewPrescient Edge
Fort Meade, MD🇺🇸Hybrid22 hours agoTechnology - PE
Mid All Source Analyst - Cyber with Security Clearance
NewPrescient Edge
Huntsville, AL🇺🇸Hybrid22 hours agoAssemblyTechnology - IR
Cyber Security / Infrastructure Business Analyst
NewInformation Resource Group, Inc.
Spartanburg, SC🇺🇸On-site22 hours agoTechnology - WO
Principal Cyber Security Engineer US Federal with Security Clearance
NewWorkday
Reston, VA🇺🇸$184.8k/yrHybrid22 hours agoGCPAWSEncryption+3Technology - NE
SOC Analyst
NewNexiva Inc.
Washington, DC🇺🇸On-site22 hours agoTCP/IPPenetration TestingPerl+1Technology