Enter a job title or keyword

Senior Vulnerability Engineer

Anduril


Job Location:

Boston, NH - USA

Yearly Salary: USD 191000 - 253000
Posted: 27 September 2026 (12 hours ago)
Application Deadline: 25 December 2026
Vacancies: 1 Vacancy

Job Summary

ABOUT THE TEAM

Anduril Cyber is hiring a Vulnerability Engineer to discover novel vulnerabilities in hardware and software systems and turn that research into rigorous technical artifacts. The role is focused on original vulnerability discovery across embedded systems firmware applications protocols hardware/software boundaries and system integrations.

ABOUT THE JOB
  • Find novel vulnerabilities in software firmware embedded systems protocols update paths device interfaces and hardware/software integration boundaries.
  • Design and execute vulnerability research plans that combine code review reverse engineering fuzzing emulation dynamic instrumentation hardware analysis and adversarial testing.
  • Build custom fuzzers harnesses emulators instrumentation triage workflows and proof-of-concept tooling to turn research hypotheses into reproducible findings.
  • Analyze root cause exploitability operational impact and mitigation options for discovered vulnerabilities.
  • Partner with reverse engineers product security engineers embedded software engineers hardware engineers and systems teams to validate findings and drive practical remediation.
  • Write clear technical reports that include evidence reproduction steps exploitability assessment impact mitigations and follow-on research opportunities.
  • Design hardware-in-the-loop vulnerability experiments that combine software exploitation protocol analysis physical interfaces and lab instrumentation.
  • Develop tooling to automate experiment orchestration device interaction data collection crash triage and vulnerability reproduction.
REQUIRED QUALIFICATIONS
  • Strong experience discovering vulnerabilities in firmware applications network services embedded Linux systems drivers protocols IoT devices or hardware-adjacent systems.
  • Proficiency with one or more programming languages used for vulnerability research and tooling such as Python C C Rust or Go.
  • Experience with fuzzing harness development crash triage exploitability analysis source-code review binary analysis or dynamic instrumentation.
  • Ability to reason about memory corruption logic flaws authentication and authorization failures unsafe parsing concurrency issues insecure update flows and trust-boundary failures.
  • Hands-on familiarity with Linux embedded systems networking debugging and common security research tooling.
  • Ability to communicate vulnerability impact reproduction steps and mitigation options clearly to both research and engineering audiences.
  • Demonstrated bias toward practical mission-enabling security outcomes rather than purely theoretical findings.
  • Must be eligible to obtain and maintain a U.S. security clearance.
  • Experience evaluating vulnerabilities across embedded protection mechanisms such as secure boot firmware update paths key storage memory protection and debug interface controls.
  • Comfort working with lab-based vulnerability validation using hardware interfaces protocol analyzers debuggers or instrumented test setups.
PREFERRED QUALIFICATIONS
  • Experience finding vulnerabilities in boot chains firmware update mechanisms device identity systems cryptographic integrations anti-tamper mechanisms or programmable-logic-backed systems.
  • Experience with advanced vulnerability research techniques such as coverage-guided fuzzing symbolic execution differential testing fault injection protocol state modeling or hardware-in-the-loop testing.
  • Familiarity with reverse-engineering tools such as Ghidra IDA Pro Binary Ninja QEMU Frida gdb/lldb or comparable frameworks.
  • Background in embedded aerospace robotic RF or cyber-physical systems and the ways their threat models differ from conventional enterprise software.
  • Track record of producing high-quality vulnerability research artifacts internal tooling conference-quality writeups CVEs or comparable technical outputs.
  • Experience applying side-channel analysis fault injection black-box testing or hardware-assisted fuzzing to embedded systems.
  • Experience with RF protocols cryptographic protocol analysis FPGA/SoC security signal processing or board-level vulnerability assessment.
  • Demonstrated technical leadership mentorship or ownership of complex vulnerability research efforts from hypothesis through reproducible technical artifact.

US Salary Range

$191000 - $253000 USD

The salary range for this role is an estimate based on a wide range of compensation factors inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience education and/or training critical skills and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Andurils total compensation package. Additionally Anduril offers top-tier benefits for full-time employees including:

Benefits

At Anduril we invest in our people. Our comprehensive competitive benefits package (available at little to no cost to employees) ensures youre supported in health recovery and whatever comes next.For more information Explore Our Benefits.

Protecting Yourself from Recruitment Scams

Anduril is committed to maintaining the integrity of our Talent acquisition process and the security of our candidates. Weve observed a rise in sophisticated phishing and fraudulent schemes where individuals impersonate Anduril representatives luring job seekers with false interviews or job offers. These scammers often attempt to extract payment or sensitive personal information.

To ensure your safety and help you navigate your job search with confidence please keep the following critical points in mind:

  • No Financial Requests:Anduril will never solicit payment or demand personal financial details (such as banking information credit card numbers or social security numbers) at any stage of our hiring process. Our legitimate recruitment is entirely free for candidates.

  • Please always verify communications:
    • Direct from Anduril: If you receive an email from one of our recruiters it will only come from an @ address.
    • Via Agency Partner: If contacted by a recruiting agency for an Anduril role their email will clearly identify their agency. If you suspect any suspicious activity please verify the agencys authenticity by reaching out to .
  • Exercise Caution with Unsolicited Outreach:If you receive any communication that appears suspicious contains grammatical errors or makes unusual requests do not engage. Always confirm the senders email domain is @ before providing any personal information or clicking on links.

  • What to Do If You Suspect Fraud:Should you encounter any questionable or fraudulent outreach claiming to be from Anduril please report it immediately to. Your proactive caution is invaluable in protecting your personal information and upholding the security and trustworthiness of our recruitment efforts.

Data Privacy

To view Andurils candidate data privacy policy please visit submitting your application you consent to Anduril Industries using a third-party service provider to conduct pre-employment risk integrity and due diligence screening and assessing potential risks as part of your application process. This third-party service provider provides risk-intelligence services that may include analysis of sanctions and watchlists adverse media public-record information and other lawful open-source or commercial data sources. This third-party service provider does not act as a consumer reporting agency. Use of this provider helps to ensure compliance with applicable laws and protect technology intellectual property and organizational security.


Required Experience:

Senior IC