
Vulnerability Research and Exploit Developer
CACI International1 day ago
Base Salary
$94k - $198k/yr
Responsibilities
- Conduct in-depth vulnerability research and exploit development for mobile and network devices.
- Identify and analyze security weaknesses in complex systems and provide actionable insights and solutions.
- Apply AI models and AI-assisted workflows, including LLM-assisted code analysis, reverse engineering, and triage, to accelerate vulnerability discovery and exploit development.
- Collaborate with interagency partners and Joint Cyber Operations Group personnel to support mission objectives.
- Develop and maintain tools and scripts for automated vulnerability detection and exploitation.
- Integrate developed solutions into existing systems without disrupting ongoing operations.
- Provide technical guidance and support to team members.
- Document research findings, exploit development processes, and solution implementations.
- Stay current with cybersecurity, vulnerability research, and exploit development techniques.
Requirements
- Current Top Secret/SCI security clearance with polygraph is required.
- Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or a related field, with at least five years of relevant experience, or an equivalent combination of education and experience.
- Proven experience identifying and exploiting security weaknesses in mobile and network devices.
- Strong proficiency in C/C++, Python, and assembly for ARM/x86.
- Experience with exploit development, reverse engineering, and vulnerability assessment tools and frameworks.
- Excellent written and verbal communication skills and the ability to work independently and collaboratively.
- A related master’s degree is preferred.
- Preferred certifications include OSCP, OSED, OSEE, GXPN, and GREM.
- Preferred experience includes fuzzing harness development, crash triage, memory-corruption vulnerabilities, exploit mitigation bypass, closed-source binary and embedded firmware reverse engineering, iOS and Android internals, kernel-mode and low-level exploitation, and operating system internals.
- Preferred additional programming experience includes Java, Kotlin, Rust, or similar memory-safe systems languages.
- Published CVEs, Pwn2Own results, DEFCON or Black Hat talks, and competitive CTF placements are valued.
Benefits
- Flexible time off, learning and development resources, healthcare, wellness, financial, retirement, family support, continuing education, and other time-off benefits are offered.
- The role is full time, regular employment, requires TS/SCI with polygraph clearance, involves up to 10% local travel, and is contingent on funding.
About CACI International
CACI International is a public government contractor that delivers enterprise IT, cybersecurity, electronic warfare, space, and intelligence solutions to U.S. defense, intelligence, and federal civilian customers. It provides systems engineering, software and data services, and mission support across C4ISR and business systems, primarily through long-term government contracts. Founded in 1962 and headquartered in Reston, Virginia, CACI trades on the NYSE under the ticker CACI.