Capability Development Engineer

Bishop Fox Logo

Bishop Fox

πŸ“Remote - United States

Summary

Join Bishop Fox, a leader in continuous offensive security and penetration testing, as a Capability Development Engineer. You will leverage your expertise in offensive security to research emerging vulnerabilities and develop automated, scalable exploitation tools. This role involves researching N-day and 0-day vulnerabilities, prototyping fingerprinting capabilities, developing reliable exploits, and publishing cutting-edge research. You will work remotely anywhere in the United States and be part of a team trusted by top global organizations. Bishop Fox offers a comprehensive benefits program and embraces diversity and inclusion. The position requires extensive experience in various technology stacks, vulnerability discovery techniques, and advanced exploitation methods. You will contribute to the development of the Cosmos platform, a leading security technology.

Requirements

  • Experience with a wide variety of technology stacks including: Instruction sets (Intel, ARM, MIPS)
  • Native programming languages (C, C++) and related compiler toolchains
  • Managed programming languages (C#, Java) and related virtual machines
  • Operating systems (Windows, *nix)
  • Strong background with vulnerability discovery including: Static analysis (source code auditing, symbolic execution)
  • Dynamic analysis (debugging, fuzzing)
  • Reverse engineering tools (disassemblers, decompilers)
  • Experience applying AI/ML to vulnerability research
  • Detailed knowledge and hands on experience with advanced exploitation techniques including: Stack and heap exploitation
  • 32-bit and 64-bit architectures
  • Exploit mitigation bypasses for ASLR, DEP (info leak, ROP chains)
  • Creative, persistent approach to obtaining and configuring vulnerable hardware and software including: Enterprise applications (VMware, Oracle)
  • Perimeter appliances (VPNs, firewalls)
  • Robust programming abilities in Python, Go, and C

Responsibilities

  • Research N-day (and if sensible, 0-day) vulnerabilities via reverse engineering and static/dynamic analysis
  • Keep up with public vulnerability research and proof-of-concept exploits
  • Prototype novel fingerprinting capabilities for enterprise applications and appliances
  • Develop highly reliable exploits, and provide rapid tactical support to analysts and operators
  • Publish cutting-edge research in the form of blog posts, presentations, etc

Benefits

  • Bishop Fox has always allowed its employees to work remotely, and this role could work anywhere in the United States
  • Our comprehensive benefits program is tailored to meet your needs at an affordable price

Share this job:

Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.